Eristotle CYBER Security Competency Model

From foundational concepts that anchor secure system design to the advanced practices that defend complex, interconnected infrastructures, this framework offers a structured path for developing and applying cybersecurity expertise. It spans the full spectrum of capabilities required to understand, anticipate, and mitigate cyber risk, including human factors, legal and regulatory dimensions, technical attack and defense mechanisms, and the protection of modern software, platforms, and physical–digital systems. It emphasises rigorous thinking about threats and vulnerabilities, disciplined engineering of secure systems, and the ability to respond effectively to evolving adversarial behaviours across diverse environments.

Eristotle’s Cybersecurity Competency Model is specifically tailored to organise and grow the knowledge and skills required for general cybersecurity practice and aligns competencies to key knowledge areas across the Cyber Security Body of Knowledge (CyBOK).

Foundations and Governance

CompetencyDescriptionProficiency
Cybersecurity Concepts & TerminologyUses core security concepts (CIA, threat, vulnerability, risk, assurance, trust) correctly across contexts.Foundational → Applied
Security Architecture MindsetUnderstands how people, process, and technology interact to create a security posture, and where to place controls.Applied → Adaptive
Body of Knowledge NavigationMaps problems and curricula to CyBOK knowledge areas and explains their scope and relationships.Applied → Adaptive
Risk Definitions & ConceptsDistinguishes risk, threat, vulnerability, likelihood, impact from technical and business perspectives.Foundational → Advanced
Risk Assessment & AnalysisPerforms structured risk assessments and prioritises treatments for key assets.Applied → Adaptive
Risk Governance & PolicyAligns policies, risk appetite, and controls with organisational objectives and constraints.Expert
Business Continuity & PreparednessConnects risk scenarios to incident response, continuity, and recovery planning.Applied → Adaptive
CompetencyDescriptionProficiency
User Behaviour & Usable SecurityRecognises how cognitive biases and usability issues drive insecure behaviour; identifies design frictions.Applied → Adaptive
Social Engineering & AwarenessIdentifies social-engineering tactics and supports awareness interventions to mitigate them.Applied → Adaptive
Organisational Culture & Security ClimateUnderstands how structures, incentives, and norms shape security behaviour and culture.Applied → Adaptive
Cyber Law & Regulatory LandscapeDescribes main cyber-related legal domains and where security duties arise.Foundational → Advanced
Jurisdiction & Enforcement ChallengesExplains cross-border, attribution, and enforcement challenges in cyberspace.Applied → Adaptive
Legal Compliance in PracticeTranslates legal/regulatory requirements into security and privacy controls.Applied → Adaptive
Privacy Concepts & RightsExplains privacy principles, user rights, and expectations in digital environments.Foundational → Advanced
Data Protection ControlsRelates privacy requirements to technical and organisational measures.Applied → Adaptive
Online Tracking & ProfilingDescribes tracking/profiling mechanisms and associated risks.Applied → Adaptive

Attacks, Adversaries, and Operations

CompetencyDescriptionProficiency
Threat Actor ModellingProfiles threat actors, motivations, capabilities, and targeting patterns.Expert
Attack Campaigns & Kill ChainsMaps intrusions across stages and uses kill chain/ATT&CK-style reasoning.Expert
Deception & Counter‑IntelligenceRecognises attacker deception and defensive deception opportunities.Applied → Adaptive
Digital Evidence PrinciplesApplies integrity, chain of custody, and admissibility principles to digital evidence.Foundational → Advanced
Forensic Acquisition & AnalysisUnderstands core acquisition and artefact analysis concepts for common platforms.Expert
Incident ReconstructionReconstructs probable attack paths from forensic artefacts and logs.Applied → Adaptive
Monitoring & Detection ConceptsUnderstands SOC goals, logging, correlation, and alert triage concepts.Applied → Adaptive
Incident Response LifecycleFollows and supports the full incident response process.Applied → Adaptive
Playbooks & CoordinationAppreciates playbooks, escalation paths, and cross-team coordination.Applied → Adaptive
Malware Families & CapabilitiesDescribes major malware categories and their capabilities.Expert
Exploit & Payload ConceptsUnderstands exploit, payload delivery, and post-exploitation concepts.Applied → Adaptive
Evasion & Anti‑AnalysisRecognises common anti-analysis and evasion tactics used by malware.Applied → Adaptive

Systems, Software, and Infrastructure Security

CompetencyDescriptionProficiency
Identity & Authentication FundamentalsUnderstands identifiers, credentials, MFA, and core protocols.Applied → Adaptive
Access Control ModelsExplains DAC, MAC, RBAC, ABAC and their practical trade-offs.Applied → Adaptive
Accountability & AuditUnderstands logs, non‑repudiation, and audit trails as accountability tools.Applied → Adaptive
OS Security FoundationsUnderstands processes, memory, isolation, and privilege concepts in OSs.Applied → Adaptive
Virtualisation & Container RisksDescribes hypervisor/container threats and isolation mechanisms.Applied → Adaptive
Hardening & Patch ManagementUnderstands OS hardening and patch/update management concepts.Applied → Adaptive
Secure Design PrinciplesApplies secure design principles in software/system architectures.Expert
Secure SDLC IntegrationIntegrates security activities into requirements, design, build, and test.Applied → Adaptive
Common Software VulnerabilitiesRecognises common classes of vulnerabilities in web/mobile/enterprise apps.Applied → Adaptive
Security Testing & VerificationUnderstands static/dynamic analysis, fuzzing, and review concepts.Applied → Adaptive
Distributed Systems ThreatsDescribes security challenges in distributed systems and services.Applied → Adaptive
Network Security ConceptsUnderstands segmentation, firewalls, IDS/IPS, and zero‑trust ideas.Expert
Physical & Link‑Layer RisksRecognises threats and mitigations at physical/link network layers.Applied → Adaptive
CPS SecurityUnderstands risk characteristics of ICS/SCADA and other CPS.Applied → Adaptive
Embedded & Hardware ThreatsRecognises side‑channels, Trojans, supply‑chain and tamper threats.Expert
CPS Risk & Safety IntegrationRelates cyber risk to reliability and physical safety in CPS.Applied → Adaptive

Cryptography and Trust Foundations

CompetencyDescriptionProficiency
Crypto Primitives UnderstandingUnderstands basic primitives and the properties they provide.Foundational → Applied
Protocols & Key Management ConceptsRecognises the role of protocols and key lifecycle management.Applied → Adaptive
Crypto Misuse & LimitationsIdentifies common misuse patterns and the need for standards.Applied → Adaptive
Practical Crypto EngineeringAppreciates how crypto is embedded into real systems and APIs.Applied → Adaptive
Protocol Analysis MindsetReasons about protocol goals, assumptions, and attack surfaces.Applied → Adaptive
Usability & Deployability in CryptoUnderstands trade-offs between theoretical security and deployability.Applied → Adaptive
Specification & Modelling ConceptsUnderstands that formal methods model systems and desired properties.Foundational → Applied
Verification & Analysis TechniquesAppreciates how formal verification uncovers subtle security flaws.Applied → Adaptive
Limits & Practical UseKnows where formal methods are most impactful and their constraints.Applied → Adaptive

Cross-Cutting Core Competencies

CompetencyDescriptionProficiency
Analytical & Critical ThinkingAnalyses complex, ambiguous security information and forms reasoned judgements.Expert
Communication & Stakeholder EngagementCommunicates security issues effectively to technical and non‑technical audiences.Expert
Ethical & Professional ConductActs in line with legal, regulatory, and ethical expectations, including privacy and rights.Expert
Lifelong Learning & AdaptationMaintains currency with evolving threats, technologies, and practices.Foundational → Expert