From foundational concepts that anchor secure system design to the advanced practices that defend complex, interconnected infrastructures, this framework offers a structured path for developing and applying cybersecurity expertise. It spans the full spectrum of capabilities required to understand, anticipate, and mitigate cyber risk, including human factors, legal and regulatory dimensions, technical attack and defense mechanisms, and the protection of modern software, platforms, and physical–digital systems. It emphasises rigorous thinking about threats and vulnerabilities, disciplined engineering of secure systems, and the ability to respond effectively to evolving adversarial behaviours across diverse environments.
Eristotle’s Cybersecurity Competency Model is specifically tailored to organise and grow the knowledge and skills required for general cybersecurity practice and aligns competencies to key knowledge areas across the Cyber Security Body of Knowledge (CyBOK).
Understands how people, process, and technology interact to create a security posture, and where to place controls.
Applied → Adaptive
Body of Knowledge Navigation
Maps problems and curricula to CyBOK knowledge areas and explains their scope and relationships.
Applied → Adaptive
Risk Definitions & Concepts
Distinguishes risk, threat, vulnerability, likelihood, impact from technical and business perspectives.
Foundational → Advanced
Risk Assessment & Analysis
Performs structured risk assessments and prioritises treatments for key assets.
Applied → Adaptive
Risk Governance & Policy
Aligns policies, risk appetite, and controls with organisational objectives and constraints.
Expert
Business Continuity & Preparedness
Connects risk scenarios to incident response, continuity, and recovery planning.
Applied → Adaptive
Human, Legal, and Organisational Factors
Competency
Description
Proficiency
User Behaviour & Usable Security
Recognises how cognitive biases and usability issues drive insecure behaviour; identifies design frictions.
Applied → Adaptive
Social Engineering & Awareness
Identifies social-engineering tactics and supports awareness interventions to mitigate them.
Applied → Adaptive
Organisational Culture & Security Climate
Understands how structures, incentives, and norms shape security behaviour and culture.
Applied → Adaptive
Cyber Law & Regulatory Landscape
Describes main cyber-related legal domains and where security duties arise.
Foundational → Advanced
Jurisdiction & Enforcement Challenges
Explains cross-border, attribution, and enforcement challenges in cyberspace.
Applied → Adaptive
Legal Compliance in Practice
Translates legal/regulatory requirements into security and privacy controls.
Applied → Adaptive
Privacy Concepts & Rights
Explains privacy principles, user rights, and expectations in digital environments.
Foundational → Advanced
Data Protection Controls
Relates privacy requirements to technical and organisational measures.
Applied → Adaptive
Online Tracking & Profiling
Describes tracking/profiling mechanisms and associated risks.
Applied → Adaptive
Attacks, Adversaries, and Operations
Competency
Description
Proficiency
Threat Actor Modelling
Profiles threat actors, motivations, capabilities, and targeting patterns.
Expert
Attack Campaigns & Kill Chains
Maps intrusions across stages and uses kill chain/ATT&CK-style reasoning.
Expert
Deception & Counter‑Intelligence
Recognises attacker deception and defensive deception opportunities.
Applied → Adaptive
Digital Evidence Principles
Applies integrity, chain of custody, and admissibility principles to digital evidence.
Foundational → Advanced
Forensic Acquisition & Analysis
Understands core acquisition and artefact analysis concepts for common platforms.
Expert
Incident Reconstruction
Reconstructs probable attack paths from forensic artefacts and logs.
Applied → Adaptive
Monitoring & Detection Concepts
Understands SOC goals, logging, correlation, and alert triage concepts.
Applied → Adaptive
Incident Response Lifecycle
Follows and supports the full incident response process.
Applied → Adaptive
Playbooks & Coordination
Appreciates playbooks, escalation paths, and cross-team coordination.
Applied → Adaptive
Malware Families & Capabilities
Describes major malware categories and their capabilities.
Expert
Exploit & Payload Concepts
Understands exploit, payload delivery, and post-exploitation concepts.
Applied → Adaptive
Evasion & Anti‑Analysis
Recognises common anti-analysis and evasion tactics used by malware.
Applied → Adaptive
Systems, Software, and Infrastructure Security
Competency
Description
Proficiency
Identity & Authentication Fundamentals
Understands identifiers, credentials, MFA, and core protocols.
Applied → Adaptive
Access Control Models
Explains DAC, MAC, RBAC, ABAC and their practical trade-offs.
Applied → Adaptive
Accountability & Audit
Understands logs, non‑repudiation, and audit trails as accountability tools.
Applied → Adaptive
OS Security Foundations
Understands processes, memory, isolation, and privilege concepts in OSs.
Applied → Adaptive
Virtualisation & Container Risks
Describes hypervisor/container threats and isolation mechanisms.
Applied → Adaptive
Hardening & Patch Management
Understands OS hardening and patch/update management concepts.
Applied → Adaptive
Secure Design Principles
Applies secure design principles in software/system architectures.
Expert
Secure SDLC Integration
Integrates security activities into requirements, design, build, and test.
Applied → Adaptive
Common Software Vulnerabilities
Recognises common classes of vulnerabilities in web/mobile/enterprise apps.
Applied → Adaptive
Security Testing & Verification
Understands static/dynamic analysis, fuzzing, and review concepts.
Applied → Adaptive
Distributed Systems Threats
Describes security challenges in distributed systems and services.
Applied → Adaptive
Network Security Concepts
Understands segmentation, firewalls, IDS/IPS, and zero‑trust ideas.
Expert
Physical & Link‑Layer Risks
Recognises threats and mitigations at physical/link network layers.
Applied → Adaptive
CPS Security
Understands risk characteristics of ICS/SCADA and other CPS.
Applied → Adaptive
Embedded & Hardware Threats
Recognises side‑channels, Trojans, supply‑chain and tamper threats.
Expert
CPS Risk & Safety Integration
Relates cyber risk to reliability and physical safety in CPS.
Applied → Adaptive
Cryptography and Trust Foundations
Competency
Description
Proficiency
Crypto Primitives Understanding
Understands basic primitives and the properties they provide.
Foundational → Applied
Protocols & Key Management Concepts
Recognises the role of protocols and key lifecycle management.
Applied → Adaptive
Crypto Misuse & Limitations
Identifies common misuse patterns and the need for standards.
Applied → Adaptive
Practical Crypto Engineering
Appreciates how crypto is embedded into real systems and APIs.
Applied → Adaptive
Protocol Analysis Mindset
Reasons about protocol goals, assumptions, and attack surfaces.
Applied → Adaptive
Usability & Deployability in Crypto
Understands trade-offs between theoretical security and deployability.
Applied → Adaptive
Specification & Modelling Concepts
Understands that formal methods model systems and desired properties.
Foundational → Applied
Verification & Analysis Techniques
Appreciates how formal verification uncovers subtle security flaws.
Applied → Adaptive
Limits & Practical Use
Knows where formal methods are most impactful and their constraints.
Applied → Adaptive
Cross-Cutting Core Competencies
Competency
Description
Proficiency
Analytical & Critical Thinking
Analyses complex, ambiguous security information and forms reasoned judgements.
Expert
Communication & Stakeholder Engagement
Communicates security issues effectively to technical and non‑technical audiences.
Expert
Ethical & Professional Conduct
Acts in line with legal, regulatory, and ethical expectations, including privacy and rights.
Expert
Lifelong Learning & Adaptation
Maintains currency with evolving threats, technologies, and practices.
Foundational → Expert
Report
There was a problem reporting this post.
Block Member?
Please confirm you want to block this member.
You will no longer be able to:
See blocked member's posts
Mention this member in posts
Invite this member to groups
Message this member
Add this member as a connection
Please note:
This action will also remove this member from your connections and send a report to the site admin.
Please allow a few minutes for this process to complete.