Online training - Call us on 1300 009 924
Online training - access your course anytime, anywhere! Call us on 1300 009 924
Technology

Certified Cyber Security Analyst

T-CSA
Next Intake
14 Sep 2026
200 Hours of Learning
100% Online, Self-Paced
6 Modules
2 TechDX certifications
10 Months Access
Mentor Support Available
TechDX Certification
No Experience Required
In partnership with

Course Overview

From foundations to analyst-level cyber security work

The Certified Cyber Security Analyst Course stacks two TechDX certifications, taken in order. Stage 1, the Certified Cybersecurity Associate, sets up everything that Stage 2 assumes: reading traffic and logs, running and securing machines, and determining which alerts deserve a closer look. Stage 2, the Certified Cybersecurity Analyst, is what most people enrol for, taking you into threat detection, incident escalation and evidence-based investigation. Together that is 200 hours and six units, split 60% hands-on labs and 40% lessons. Study is fully online and self-paced inside the browser-based TDX Arena platform, and entry asks only for basic computer literacy, so no prior cyber security or IT experience is needed.

Analyst work is judgement work. Deciding whether an alert is real means knowing what normal traffic, normal logins and a normal process list look like, and you cannot spot a deviation from a baseline you have never seen. Jump straight to detection and you end up memorising playbooks you cannot reason your way past. Stage 1 puts 100 hours of command line, networking, systems and alert-handling practice underneath you first, so Stage 2 spends its 100 hours on investigation rather than backfilling gaps.

Who is this course for?

  • Career changers who want to reach a first analyst role, not just sample the field and stop.
  • Help desk and IT support staff stepping across into threat detection, escalation and live incident work.
  • Beginners with no security or IT background who want to finish at analyst level rather than stop at foundations.
  • Network and systems administrators who already field security incidents but have no structured training in analysis.
  • Job seekers who need hands-on evidence for interviews, not a certificate listing the topics they covered.
  • Full-time workers and parents who need self-paced study and ten months of access to fit 200 hours in.



Is this cyber security course accredited?

No. The Certified Cyber Security Analyst Course is non-accredited training. You finish with two TechDX certifications, Certified Cybersecurity Associate and Certified Cybersecurity Analyst, awarded by TechDX and recognised by industry. What you do not get is a nationally recognised qualification under the Australian Qualifications Framework. It is not a Statement of Attainment, it is not delivered under Upskilled's RTO scope, and it does not licence you to perform a regulated role.

Plenty of employers hire analysts on demonstrated capability, which is what an applied, lab-assessed program is built to show. But if a nationally recognised credential is what you actually need, for an employer requirement, a visa, a government role or credit towards further study, Upskilled delivers accredited IT qualifications as well. Start with the ICT40120 Certificate IV in Information Technology (Focus on Cyber Security), or compare the whole range of cyber security qualifications.

Which cyber security program is right for you?


Upskilled runs three versions of the same TechDX pathway, and this page is the middle one: 200 hours, two certifications, Associate then Analyst. The other two are the first stage on its own, and the full four-stage pathway. Each one contains the one before it, so the only question is how far you want to go now.

Program Hours Certifications Best for
Certified Cybersecurity Associate 100 hours 1 TechDX certification, 3 units Best if you want to test whether security work suits you before committing further. It is the same first stage this course opens with, at the smallest commitment.
Certified Cyber Security Analyst Course (this page) 200 hours 2 TechDX certifications, 6 units Best if you already know you want analyst work. Two stages take you from foundations through threat detection, incident escalation and investigation, in one enrolment.
Cyber Security Online Bootcamp 400 hours 4 TechDX certifications, 12 units Best if you are set on a full security career and want the specialist stages that follow this one, escalation-level operations work and threat intelligence, in the same enrolment.

Cyber security skills you will walk away with

  • Work a command line comfortably and follow a request across a network from one machine to another.
  • Lock down a build, then justify every account, service and firewall change you made.
  • Judge whether an alert or suspicious email warrants escalation, and document that decision.
  • Take an alert from first look to a defensible verdict, and show how you got there.
  • Pull together records from several systems to establish what actually happened on a network.
  • Hand work upward with the sequence of events, the machines involved and the proof behind it.
  • Reduce alert noise by tuning detections and ranking weaknesses by CVSS before recommending patch order.
  • Hold both TechDX certifications and all six units after passing the second applied exam.

The kind of work you will do in the labs

  • Log search and correlation across multiple data sources
  • Alert queue triage, with tuning to cut false positives
  • Timeline reconstruction from endpoint, network and identity events
  • Sandbox detonation of suspicious attachments and links
  • Traffic capture review to confirm what a host did
  • Vulnerability severity ranking to decide escalation order
  • Open source research to validate indicators you find
  • Written incident handover: scope, impact and next steps

Frameworks you will be introduced to

  • MITRE ATT&CK: A shared catalogue of attacker techniques, so you can name what you are seeing.
  • The cyber kill chain: Breaks an attack into stages, which helps you work out how far one got.
  • NIST Cybersecurity Framework: The common language for how organisations identify, protect, detect, respond and recover.
  • CVE and CVSS How software flaws are identified and scored, so you know which ones to fix first.
  • ASD Essential Eight: The Australian baseline controls you will be asked about in local security roles.

Course Modules: What you will study across six units

Stage 1: Certified Cybersecurity Associate

Stage 1 is the Certified Cybersecurity Associate, and it runs first so that nothing in Stage 2 arrives unexplained. Over 100 hours and three units you learn how machines and networks behave, how they are locked down, and how odd activity gets checked. Basic computer literacy is the only starting point.

Foundations

Lab work starts at the terminal: moving through directories, checking permissions and watching processes run. You then map addressing, ports and name resolution, open a saved traffic capture to follow protocols in sequence, and weigh small scenarios against confidentiality, integrity and availability.

Systems

You run the machines. Labs cover building accounts on least privilege, switching off services nobody needs, limiting remote access and setting host firewall rules. You read logs to rebuild what someone did, rank flaws by CVSS severity and check a build against Essential Eight controls.

Operations

Now you defend. You work a queue of alerts from log data, decide which deserve attention and write the escalation. You pull a phishing email apart header by header, check cloud identity and storage exposure, and name behaviour using MITRE ATT&CK and the kill chain.


Stage 1 is also sold on its own as the Certified Cybersecurity Associate if you would rather start there and decide about analyst work later.

Stage 2: Certified Cybersecurity Analyst

The Certified Cybersecurity Analyst takes the groundwork laid in Stage 1 and moves you onto the detection side, learning the workflows a security operations centre depends on by doing them: reading a queue, separating noise from genuine intrusion, handing over findings that hold up. It runs 100 hours across three units, weighted towards labs, and closes with an applied exam.

Fundamentals

Fundamentals sets you up before you are trusted with a live queue. In the labs you work out where evidence actually lives: authentication records, endpoint telemetry, name resolution and web proxy history, and what each source can and cannot tell you. You build a picture of a host, its services, its users and its normal traffic, then query a log platform to pull one session back out of millions of lines. You also align events recorded across different time zones, and learn where first-line responsibility ends.

Essentials

Essentials is the working day itself. The labs hand you a queue that keeps filling: signature hits, unusual sign-ins, blocked downloads, staff reports. You take each item, gather what surrounds it, and reach a decision, closing what is benign, raising what is not, and recording your reasoning in words a colleague can follow. You pull apart reported emails and detonate their attachments in a sandbox. You rank weaknesses by CVSS so patching goes where it matters, and you tune detections that fire constantly and are never right.

Analysis

Analysis is where alerts become a case. Given an environment already compromised, you work backwards: which account was used first, what it touched, what was installed to keep access, and how the attacker spread. You stitch endpoint, network and identity records into one ordered account of events, open captured traffic when the logs stop short, and check addresses and hashes against open sources. You name the behaviour using MITRE ATT&CK and the cyber kill chain, then set out what was reached, what it cost, and what needs cutting off.


How you will learn on the TDX Arena

Both certifications sit inside one training environment. Stage 1 and Stage 2 share the same account, so all six units, every lab and both applied exams are tracked in the one place, with nothing new to set up when Stage 2 opens. Access runs for 10 months from the enrolment date.

Progress across all 200 hours

Completion is measured over the whole enrolment rather than per certification, so you can see how far through the six units you have come without holding two separate records in your head.
Two applied exams, one format

Each stage closes with a practical exam set inside the platform you trained in. There is no change of format between them, so the second exam holds no surprises beyond harder material and a wider scenario.
Labs stay at 60 per cent

The split holds steady across both certifications: 120 of your 200 hours go toward lab work and 80 toward lessons, so the balance does not shift as the material gets harder in Stage 2.
Help that does not reset at Stage 2

Ember, the AI teaching assistant, is available day or night, and a single support team fields everything from a lab that has you stuck to an enrolment question, Foundations through to Analysis.
One place to ask, one view of your progress

Whatever the question, technical or administrative, there is a single form, a single email address and a single phone number to use. Your completion tracks unit by unit, so you always know how much is left.

Career and Industry Outlook

Two hundred hours of lab work and two TechDX certifications give you something specific to show: tasks you have performed rather than subjects you have read about. These are industry certifications, not a qualification, so how much weight they carry depends on the employer. What they reliably give you is the vocabulary of detection and escalation work, and your own examples to talk through at interview.

Roles this course can support

  • Cyber Analyst: You sit with the alert queue, checking what the monitoring tools flag against endpoint, authentication and network logs, discarding what turns out to be routine, then writing up the rest in enough detail for a senior analyst to act on.
  • Cybersecurity Operations Technician: You keep the detection side of a security team running: confirming log sources are still reporting, scheduled scans have finished, patches and access changes are recorded, and flagging it early when a control has quietly stopped doing its job.
  • Incident Response Support Specialist: When something real is underway, you handle the evidence: collecting it before it ages out, building the timeline of what happened and when, listing affected accounts and machines, and keeping case notes clean so the responders leading the work are not guessing.

Related roles these skills support

  • IT Security Administrator
  • Junior Vulnerability Analyst
  • Information Security Support Officer
  • Systems Administrator with security responsibilities


The roles above are the ones TechDX aligns the Certified Cybersecurity Analyst certification to. The related roles are positions where these skills are useful, not roles this course qualifies you for on its own.

Career support that goes the distance

Your cyber security analyst course is just the start. Our internship program can help you turn study into real work, real contacts and real outcomes.

Upskilled Internships

Turn your qualification into real Australian work experience. Complete 80% of your course and apply for a 12-week internship with a top host company, delivered with Career Success Australia. Past placements include NAB, BHP, PwC, Telstra and IBM.

Get in touch to know more.*

*Terms and conditions apply.

Payment Options

Pay Upfront & Save
You pay $2310
RRP $3150
Spread the Cost - Payment Plans

Upskilled Payment Plans
We can arrange an interest-free, flexible and easy-to-manage monthly payment plan for you. Speak to our friendly Education Consultants at 1300 009 024 to learn more

What is included

  • Both certifications in one enrolment. Certified Cybersecurity Associate and Certified Cybersecurity Analyst, six named units between them, covered by a single fee with nothing further to pay.
  • 200 hours weighted towards practice. Of your 200 hours, 120 are spent working in labs and 80 in lessons, so practice takes up most of the program.
  • Two applied exams, one per stage. Each stage closes with a hands-on, scenario-based certification exam. You are given a security situation to work through rather than questions to answer.
  • Help while you study. Ember, the AI teaching assistant, replies by avatar, by voice or in writing whenever you are studying, and one Upskilled team covers access, billing and content queries.
  • Everything runs in a browser. TDX Arena opens in the browser you already have. Nothing is installed, no virtual machines are configured, and an ordinary laptop is enough to start.
  • Two evidence packs for employers. Each certification comes with its own Skills List, Case Studies and Achievement Report, so you finish with two sets of documented, lab-tested evidence for employers.

Your Certified Cyber Security Analyst certification

Pass the final applied exam, and you receive the Certified Cybersecurity Analyst certification from TechDX, along with credentials for all six units, a Skills List setting out what you can do, the case studies from the work you completed, and an Achievement Report. Together these give an employer something more specific than a course title on a resume: evidence of tasks you have actually performed in a lab environment.

Cyber-Analyst-TechDX-Cert.png

This certification is issued by TechDX and recognises completion of applied assessment. It is not AQF or ASQA accreditation.

Certified Cyber Security Analyst Course FAQs

It is a single enrolment covering two stacked TechDX certifications: the Certified Cybersecurity Associate first, then the Certified Cybersecurity Analyst. Together, that is 200 hours and six units, weighted 60% to hands-on labs, run by Upskilled with TechDX inside the TDX Arena. Stage 1 teaches the networking, systems and operations groundwork; Stage 2 puts you into threat detection, incident escalation and analyst-level investigation. You begin with no experience and finish able to work an alert queue and document what you found.

No. This is non-accredited training that delivers two TechDX certifications and six units. There is no AQF level attached; it is not a Statement of Attainment; it sits outside Upskilled's RTO scope; and it is not a licence to perform regulated work. What you get instead is industry certification backed by applied assessment, which many employers accept as evidence of practical skill. If a nationally recognised credential is what your situation requires, Upskilled also delivers nationally recognised IT qualifications, so check what your target roles actually ask for before enrolling.

Yes. Entry asks for everyday computer skills and a connection that stays up, nothing more. Stage 1 is the Certified Cybersecurity Associate, which opens at computing fundamentals and networking, so nothing is used before it has been defined. That matters here, because Stage 2 assumes you can already read logs and traffic with confidence, and Stage 1 is where you build that. Career changers, help desk staff and complete beginners all start in the same place.

Around 200 hours in total, which is about 20 weeks at the suggested pace of 10 hours a week. Study is online and self-paced, and the timetable is yours: evenings, weekends, or a heavier week when work allows. Your platform access lasts 10 months from the day you enrol, roughly double the suggested schedule, so a busy stretch at work does not put the course at risk. There are no intake dates and no scheduled classes to attend.

They are the Certified Cybersecurity Associate and the Certified Cybersecurity Analyst, and yes, they run in order. Stage 1 covers Foundations, Systems and Operations: computing and networking basics, system administration and hardening, then alert triage and threat defence. Stage 2 covers Fundamentals, Essentials, and Analysis: log collection and normalisation, monitoring and escalation, and then full investigation across endpoint, network, and identity evidence. Stage 2 is written on the assumption that Stage 1 has been completed, so the sequence is not optional.

Sixty per cent of your hours are labs. Across the two certifications, that is about 120 hours spent doing security work and 80 hours in lessons, and each lesson is followed by a task that asks you to apply it. The labs adapt to how you perform, so time goes where your skills are weakest. Assessment matches the format: both stages finish with a hands-on, scenario-based exam where you are marked on the decisions you make inside a live-style situation, not on recall.

This is the focused analyst route: 200 hours, two certifications, six units, taking you from no experience to threat detection and incident escalation work, then stopping there. The Cyber Security Online Bootcamp is the full 400 hour pathway. It contains everything on this page and then adds two further TechDX certifications, Certified SOC Analyst and Certified CTI Analyst, which move into escalation-level investigation and threat intelligence specialisations. Choose this route if analyst-level capability is your goal; choose the full pathway if the specialist end of security is where you are headed.