
Loading…

Loading…
Defend systems, networks, and data from modern threats
Online or on campus

Cybersecurity at Brigant trains defenders and ethical hackers in a controlled campus lab environment. You will configure firewalls, analyse malware samples, and conduct penetration tests under faculty supervision. Modules span cryptography, secure software development, digital forensics, and security governance. Capture-the-flag competitions and industry certifications (CompTIA Security+) are integrated into the curriculum. BSc (Hons) Cybersecurity is taught as one award, not a list of unrelated modules. The published length is 3 years full-time, and the credit total is 360. Students move from Computing & Networking Foundations through Computing & Networking Foundations; Programming for Cybersecurity (Python & C); Information Security Fundamentals; Discrete Mathematics & Logic for Cyber; Linux Administration & Shell Scripting; Web Technologies & Application Security, and finish on Honours Cybersecurity Project & Dissertation. Each course has a question, a method, and a submission. In this field, students map one named system, write a threat model, and specify the controls that would stop the most likely path. Reading is control catalogues, incident write-ups, and a short technical standard. The artefact a marker expects is a defensive design with a test plan and a statement of residual risk. The award is built so that a graduate can do the following in practice: Harden systems and networks against common attack vectors Conduct authorised penetration tests with documented findings Analyse security incidents using forensic procedures Teaching assumes the student can read a source, attempt a problem before the seminar, and revise after feedback. Attendance at live seminars is part of the design. The capstone or final course must use the methods of the earlier courses; a project that ignores them does not pass. The pages for each course name the topics that are examined. Those topics are the syllabus. A brochure line is not a substitute for them.
The Cyber Range lab simulates enterprise networks for red-team/blue-team exercises each semester.
Faculty spotlight
Dr. Fiona McAllister leads Network Security; Professor James Okello supervises malware analysis research.
Study online
Online tuition is free. Online examinations are free. There is no exam fee for online study.

On-campus study
Prefer to learn at our Edinburgh campus? Campus tuition and campus examinations are charged. The published campus price is on each programme page.
| Code | Course | Credits · hours |
|---|---|---|
| CYB101 | Computing & Networking Foundations Computing & Networking Foundations (CYB101) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Computing & Networking Foundations as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB102 | Programming for Cybersecurity (Python & C) Programming for Cybersecurity (Python & C) (CYB102) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Programming for Cybersecurity (Python & C) as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB103 | Information Security Fundamentals Information Security Fundamentals (CYB103) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Information Security Fundamentals as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB104 | Discrete Mathematics & Logic for Cyber Discrete Mathematics & Logic for Cyber (CYB104) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Discrete Mathematics & Logic for Cyber as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB105 | Linux Administration & Shell Scripting Linux Administration & Shell Scripting (CYB105) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Linux Administration & Shell Scripting as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB106 | Web Technologies & Application Security Web Technologies & Application Security (CYB106) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Web Technologies & Application Security as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| Code | Course | Credits · hours |
|---|---|---|
| CYB201 | Applied Cryptography & PKI Applied Cryptography & PKI (CYB201) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Applied Cryptography & PKI as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB202 | Network Defence & Firewall Engineering Network Defence & Firewall Engineering (CYB202) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Network Defence & Firewall Engineering as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB203 | Ethical Hacking & Penetration Testing Ethical Hacking & Penetration Testing (CYB203) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Ethical Hacking & Penetration Testing as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB204 | Digital Forensics & Incident Response Digital Forensics & Incident Response (CYB204) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Digital Forensics & Incident Response as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB205 | Secure Software Development & DevSecOps Secure Software Development & DevSecOps (CYB205) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Secure Software Development & DevSecOps as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB206 | Identity, Access Management & Directory Services Identity, Access Management & Directory Services (CYB206) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Identity, Access Management & Directory Services as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| Code | Course | Credits · hours |
|---|---|---|
| CYB301 | Security Operations & Threat Intelligence Security Operations & Threat Intelligence (CYB301) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Security Operations & Threat Intelligence as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB302 | Cloud Security Architecture & Virtualisation Cloud Security Architecture & Virtualisation (CYB302) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Cloud Security Architecture & Virtualisation as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB303 | Governance, Risk, Compliance & ISO 27001 Governance, Risk, Compliance & ISO 27001 (CYB303) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Governance, Risk, Compliance & ISO 27001 as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB304 | Malware Analysis & Reverse Engineering Malware Analysis & Reverse Engineering (CYB304) is a 20-credit course on BSc (Hons) Cybersecurity, with 200 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Malware Analysis & Reverse Engineering as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 20 · 200 h |
| CYB305 | Honours Cybersecurity Project & Dissertation Honours Cybersecurity Project & Dissertation (CYB305) is a 40-credit course on BSc (Hons) Cybersecurity, with 400 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Honours Cybersecurity Project & Dissertation as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 40 · 400 h |
Modules are assessed through a published mix of coursework, applied projects, and examinations. Exam windows are announced in advance so students in other time zones are not forced into overnight sittings. Alternative arrangements are available where documented.
The published duration is 3 years full-time. Teaching language: English. Actual time-to-complete depends on mode and any recognised prior learning.
You may study this award fully online from your country, or — where published — on campus at Brigant. Online study does not require a student visa. Campus study may.
Degree tuition for this award is published as £0 / tuition-free on the online pathway. Examination or administrative fees may apply at checkout — never an annual tuition invoice. Check the Fees page for any extras.
Requirements are grouped on this page (academic, English, documents). Equivalent qualifications are considered. English may be waived after prior English-medium study.
Assessment is typically a mix of coursework, projects, and examinations. Doctoral awards include a thesis or dissertation and an oral examination. Details sit in the programme specification and module outlines.
Recognition of the award for local employment, professional licence, or ministry attestation is decided by your employer or regulator. University of Brigant publishes verification pages for certificates. We do not claim automatic equivalence in every country.
Start an application on this website. Progress is saved from the first step. Admissions: admissions@brigant.uk.
Recognised & Accredited