
Loading…

Loading…
ICO complaints, ransomware, and SME controls—not CISSP and not a hacking course.
Online or on campus

SMEs do not fail cyber because they lack a Silicon Valley SOC; they fail because backups were a myth, MFA was optional, and nobody owned the ICO clock. This MSc starts there. You will map a ransomware weekend for a ten-person firm, write a personal-data inventory that is not a lie, and brief a director without claiming a hacking qualification. Scottish and rUK SMEs sit in the cases: professional services in Edinburgh, manufacturers in the Central Belt, care and education suppliers who hold children’s data. Dual-pathway students sit the same assessments. Faculty mark whether you can separate UK GDPR, PECR, and NIS-adjacent duties without dumping a US NIST poster as the whole answer. The degree is not CISSP, not a penetration-testing licence, not ICO employment. Offensive techniques are not taught as a curriculum outcome. Capstones must improve a control environment, not demonstrate intrusion. ICO-facing clocks, children’s data in small education suppliers, and invoice-fraud on a Friday afternoon are the Scottish and UK cases, not a Silicon Valley breach memoir. University of Brigant will not display NCSC, ICO, or CISSP marks. You will still be expected to brief a director in plain English about residual risk after MFA and backups are real rather than slideware. MSc UK SME Cyber and ICO-Facing Practice is taught as one award, not a list of unrelated modules. The published length is 18 months, and the credit total is 36. Students move from UK GDPR and PECR for SME Operators through UK GDPR and PECR for SME Operators; ICO Processes, SARs, and Complaint Clocks; NIS-Adjacent Duties without Operator Theatre; Identity, MFA, and Backup Reality; Phishing, Invoice Fraud, and Staff Culture; Cloud, Laptops, and Home Working in SMEs, and finish on Tabletop Exercises that Are Not LARP Hacking. Each course has a question, a method, and a submission. In this field, students map one named system, write a threat model, and specify the controls that would stop the most likely path. Reading is control catalogues, incident write-ups, and a short technical standard. The artefact a marker expects is a defensive design with a test plan and a statement of residual risk. The award is built so that a graduate can do the following in practice: Design proportionate SME controls and backup reality tests Run an ICO-facing complaint or SAR timeline as operations Write an incident log a director and an insurer can read Teaching assumes the student can read a source, attempt a problem before the seminar, and revise after feedback. Attendance at live seminars is part of the design. The capstone or final course must use the methods of the earlier courses; a project that ignores them does not pass. The pages for each course name the topics that are examined. Those topics are the syllabus. A brochure line is not a substitute for them.
Thirty-six credits: UK legal-operational cyber for SMEs, ICO-facing processes, incident and supplier risk, and a supervised controls capstone. Dual pathway. Explicit non-CISSP, non-offensive marketing.
Study online
Online tuition is free. Online examinations are free. There is no exam fee for online study.

On-campus study
Prefer to learn at our Edinburgh campus? Campus tuition and campus examinations are charged. The published campus price is on each programme page.
| Code | Course | Credits · hours |
|---|---|---|
| UOB701 | UK GDPR and PECR for SME Operators UK GDPR and PECR for SME Operators (UOB701) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using UK GDPR and PECR for SME Operators as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB702 | ICO Processes, SARs, and Complaint Clocks ICO Processes, SARs, and Complaint Clocks (UOB702) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using ICO Processes, SARs, and Complaint Clocks as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB703 | NIS-Adjacent Duties without Operator Theatre NIS-Adjacent Duties without Operator Theatre (UOB703) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using NIS-Adjacent Duties without Operator Theatre as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| Code | Course | Credits · hours |
|---|---|---|
| UOB705 | Identity, MFA, and Backup Reality Identity, MFA, and Backup Reality (UOB705) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Identity, MFA, and Backup Reality as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB706 | Phishing, Invoice Fraud, and Staff Culture Phishing, Invoice Fraud, and Staff Culture (UOB706) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Phishing, Invoice Fraud, and Staff Culture as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB707 | Cloud, Laptops, and Home Working in SMEs Cloud, Laptops, and Home Working in SMEs (UOB707) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Cloud, Laptops, and Home Working in SMEs as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| Code | Course | Credits · hours |
|---|---|---|
| UOB709 | Ransomware Weekends and Honest Downtime Ransomware Weekends and Honest Downtime (UOB709) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Ransomware Weekends and Honest Downtime as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB710 | Insurers, Solicitors, and Notification Decisions Insurers, Solicitors, and Notification Decisions (UOB710) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Insurers, Solicitors, and Notification Decisions as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB711 | Processor Contracts and Supply-Chain Weakest Links Processor Contracts and Supply-Chain Weakest Links (UOB711) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Processor Contracts and Supply-Chain Weakest Links as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| Code | Course | Credits · hours |
|---|---|---|
| UOB713 | Scottish SME and Professional-Services Cases Scottish SME and Professional-Services Cases (UOB713) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Scottish SME and Professional-Services Cases as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB714 | Research Methods for Socio-Technical Controls Research Methods for Socio-Technical Controls (UOB714) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Research Methods for Socio-Technical Controls as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
| UOB715 | Tabletop Exercises that Are Not LARP Hacking Tabletop Exercises that Are Not LARP Hacking (UOB715) is a 3-credit course on MSc UK SME Cyber and ICO-Facing Practice, with 30 notional learning hours. By the end, students can map one named system, write a threat model, and specify the controls that would stop the most likely path, using Tabletop Exercises that Are Not LARP Hacking as the working context rather than a generic management example. The course is taught in three movements. First, students establish the terms and the decision the course is about. Second, they apply the method to a case, dataset, text, or design and compare it with a weaker alternative. Third, they revise the work after feedback and state what the conclusion cannot support. Preparation uses control catalogues, incident write-ups, and a short technical standard. Seminar time is for the decision, not for reading the materials aloud. Assessment is a defensive design with a test plan and a statement of residual risk. A pass requires a clear method, evidence a marker can check, and an explicit limit. Credit is not awarded for summary alone.
| 3 · 30 h |
Modules are assessed through a published mix of coursework, applied projects, and examinations. Exam windows are announced in advance so students in other time zones are not forced into overnight sittings. Alternative arrangements are available where documented.
The published duration is 18 months. Teaching language: English (dual pathway: Edinburgh campus or tuition-free online; one academic standard). Actual time-to-complete depends on mode and any recognised prior learning.
You may study this award fully online from your country, or — where published — on campus at Brigant. Online study does not require a student visa. Campus study may.
Degree tuition for this award is published as £0 / tuition-free on the online pathway. Examination or administrative fees may apply at checkout — never an annual tuition invoice. Check the Fees page for any extras.
Requirements are grouped on this page (academic, English, documents). Equivalent qualifications are considered. English may be waived after prior English-medium study.
Assessment is typically a mix of coursework, projects, and examinations. Doctoral awards include a thesis or dissertation and an oral examination. Details sit in the programme specification and module outlines.
Recognition of the award for local employment, professional licence, or ministry attestation is decided by your employer or regulator. University of Brigant publishes verification pages for certificates. We do not claim automatic equivalence in every country.
Start an application on this website. Progress is saved from the first step. Admissions: admissions@brigant.uk.
Recognised & Accredited