Enrols as Cyber Security in the academy's catalogue.
Security is mostly not an entry-level field. Most people arrive through IT support or networking first, and this course is aimed squarely at that route. Anyone selling a three-month path straight into a security job is not being straight with you.
Duration
3 Months
Contact hours
96 hours
Level
Intermediate
Modules
6
Topics
24 (16 practical)
Fee
PKR 60,000
What the programme includes
Live classes with a named trainer, on a published schedule
Recordings of every session, so a missed class is not a lost one
Marked assignments with written feedback
Project work reviewed and verified by your trainer
A final assessment
A completion letter stating your attendance, results and verified work —
independently verifiable by any employer
Syllabus
1. How attacks actually work
12 hours
Replacing the film version with the commercial reality.
What attackers want, and why you are a target
Money, resellable accounts, your contact list, a route into your employer, ransom. None of it requires you to be important.
Untargeted attacks and credential stuffing
hands on
Why being ordinary is not protection, and what password reuse actually costs.
The human is the weakest point
Why it is cheaper to convince someone to hand over a code than to defeat encryption.
The Pakistani threat picture
SIM swap, EasyPaisa and JazzCash fraud, WhatsApp account theft, fake job offers. Local and specific.
2. Networking for defenders
20 hours
Enough network knowledge to reason about traffic.
TCP/IP, ports and what is listening
hands on
Reading a connection and knowing what should not be there.
DNS, HTTP and TLS
hands on
How a certificate actually proves anything, and what a browser warning means.
Scanning and enumeration with nmap
hands on
In a lab you own. Scope and written authorisation covered before the first scan.
Reading traffic with Wireshark
hands on
Seeing credentials cross a network in plain text — once seen, never forgotten.
3. Systems and hardening
16 hours
Making a machine harder to take.
Linux fundamentals for security work
hands on
Users, permissions, processes, logs and services.
Patching, and why it is the highest-value control
Unglamorous, unpopular, and the thing that would have stopped most real incidents.
Least privilege in practice
hands on
Shared admin logins, and why every named person needs their own account.
Backups you have actually restored
hands on
An untested backup is a hope. Restoring one is the exercise.
4. Web application security
20 hours
Where most real vulnerabilities are found.
The OWASP Top Ten, demonstrated not recited
hands on
Each one shown working in a lab application.
Injection and broken access control
hands on
The two that cause the most real damage — including changing an id in a URL to read another user's record.
Using Burp Suite
hands on
Intercepting, modifying and replaying requests.
Writing the finding, not just finding it
hands on
A vulnerability nobody can understand or reproduce does not get fixed. Severity, reproduction steps, and the remediation.
5. Detection and response
16 hours
Assuming something will get through.
Logs, and what to keep
hands on
The evidence you will wish you had.
Recognising an incident in progress
Indicators, and the cost of a false alarm versus a missed one.
The first hour
hands on
Contain, preserve, communicate. In that order, and why improvising the third one damages an organisation most.
Phishing analysis
hands on
Headers, links and attachments — taking a real reported message apart.
6. Law, ethics and career reality
12 hours
The part that keeps you employable and out of trouble.
PECA and the legal boundary in Pakistan
What unauthorised access means in law. Testing a system you were not asked to test is a crime, whatever your intent.
Scope, authorisation and the engagement letter
hands on
Never touching anything without it in writing.
Disclosure done responsibly
What to do when you find something in a system that is not yours.
How people really enter this field
Usually through IT support or networking first. Anyone selling a three-month route straight into a security job is not being straight with you.
Before, and after
Before you start
Comfortable with computers and networks
Not a first computing course. CCNA or equivalent networking is an advantage.
Free: Cybersecurity Fundamentals
Recommended before enrolling.
Where it leads
CCNA
The networking depth most security roles expect.
CCNP
For those going down the network engineering route.
Roles this prepares you for
IT Support with security responsibility
The most common genuine first step, and this programme is aimed squarely at it.
SOC Analyst (Tier 1)
Monitoring and triage. Usually requires networking depth as well.
Junior Security Analyst
Typically reached after one to two years in IT or networking, not directly from a course.
These are the roles the programme is aimed at. BvLogic Academy does not guarantee employment,
an income, or a timeframe — and you should be careful with any institute that does.