
Loading…

Loading…
Defend organisations in an age of persistent threats
Online or on campus

Cyber attacks cost the global economy trillions annually. This MSc develops practitioners who can protect networks, respond to breaches, and embed security culture across organisations. You will study penetration testing methodology, digital forensics, secure software development, and security governance frameworks including ISO 27001 and NIST CSF. Labs run in isolated virtual environments with realistic attack scenarios. MSc Cybersecurity is taught as one award, not a list of unrelated modules. The published length is 24 months, and the credit total is 36. Students move from Network Security & Protocols through Network Security & Protocols; Cryptography & PKI; Operating System & Application Security; Security Governance & Risk Management; Penetration Testing Methodology; Digital Forensics & Incident Response, and finish on MSc Cybersecurity Capstone. Each course has a question, a method, and a submission. In this field, students map one named system, write a threat model, and specify the controls that would stop the most likely path. Reading is control catalogues, incident write-ups, and a short technical standard. The artefact a marker expects is a defensive design with a test plan and a statement of residual risk. The award is built so that a graduate can do the following in practice: Conduct vulnerability assessments and penetration tests ethically and legally Lead incident response from detection through recovery and post-mortem Design zero-trust architectures for cloud and hybrid environments Teaching assumes the student can read a source, attempt a problem before the seminar, and revise after feedback. Attendance at live seminars is part of the design. The capstone or final course must use the methods of the earlier courses; a project that ignores them does not pass. The pages for each course name the topics that are examined. Those topics are the syllabus. A brochure line is not a substitute for them.
Labs run in isolated virtual environments — legal and ethical scope is taught before any offensive technique. You will complete a full breach-response capstone from detection through board reporting. Content aligns with CompTIA Security+ and CEH knowledge domains.
Faculty spotlight
Professor Marcus Chen, ex-CISO in financial services, leads Security Governance; Dr. Yuki Tanaka runs red-team/blue-team intensives.
Study online
Online tuition is free. Online examinations are free. There is no exam fee for online study.

On-campus study
Prefer to learn at our Edinburgh campus? Campus tuition and campus examinations are charged. The published campus price is on each programme page.
| Code | Course | Credits · hours |
|---|---|---|
| CY501 | Network Security & Protocols Network Security & Protocols (CY501) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Network Security & Protocols as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY502 | Cryptography & PKI Cryptography & PKI (CY502) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Cryptography & PKI as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY503 | Operating System & Application Security Operating System & Application Security (CY503) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Operating System & Application Security as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY504 | Security Governance & Risk Management Security Governance & Risk Management (CY504) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Security Governance & Risk Management as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| Code | Course | Credits · hours |
|---|---|---|
| CY505 | Penetration Testing Methodology Penetration Testing Methodology (CY505) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Penetration Testing Methodology as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY506 | Digital Forensics & Incident Response Digital Forensics & Incident Response (CY506) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Digital Forensics & Incident Response as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY507 | Cloud Security Architecture Cloud Security Architecture (CY507) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Cloud Security Architecture as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY508 | Secure Software Development (DevSecOps) Secure Software Development (DevSecOps) (CY508) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Secure Software Development (DevSecOps) as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| Code | Course | Credits · hours |
|---|---|---|
| CY601 | Advanced Threat Intelligence Advanced Threat Intelligence (CY601) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Advanced Threat Intelligence as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY602 | Security Leadership & Compliance Security Leadership & Compliance (CY602) is a 3-credit course on MSc Cybersecurity, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Security Leadership & Compliance as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| CY603 | MSc Cybersecurity Capstone MSc Cybersecurity Capstone (CY603) is a 6-credit course on MSc Cybersecurity, with 60 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using MSc Cybersecurity Capstone as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 6 · 60 h |
Modules are assessed through a published mix of coursework, applied projects, and examinations. Exam windows are announced in advance so students in other time zones are not forced into overnight sittings. Alternative arrangements are available where documented.
The published duration is 24 months. Teaching language: English. Actual time-to-complete depends on mode and any recognised prior learning.
You may study this award fully online from your country, or — where published — on campus at Brigant. Online study does not require a student visa. Campus study may.
Degree tuition for this award is published as £0 / tuition-free on the online pathway. Examination or administrative fees may apply at checkout — never an annual tuition invoice. Check the Fees page for any extras.
Requirements are grouped on this page (academic, English, documents). Equivalent qualifications are considered. English may be waived after prior English-medium study.
Assessment is typically a mix of coursework, projects, and examinations. Doctoral awards include a thesis or dissertation and an oral examination. Details sit in the programme specification and module outlines.
Recognition of the award for local employment, professional licence, or ministry attestation is decided by your employer or regulator. University of Brigant publishes verification pages for certificates. We do not claim automatic equivalence in every country.
Start an application on this website. Progress is saved from the first step. Admissions: admissions@brigant.uk.
Recognised & Accredited