A micro-credential is a short, focused unit of learning that certifies you can do specific things well — and that can later count toward a larger qualification. TESDA launched a national micro-credentialing system in 2025 for exactly this purpose.
The eight-week programme
Eight weeks, each pairing concepts with hands-on labs run inside Kanraul IT Solutions' isolated cyber range. Aligned to the TESDA Cyber Threat Mitigation NC II qualification and built on NIST CSF 2.0 and the Data Privacy Act (RA 10173).
1 · Threat Landscapes & Social Engineering
Foundations of cybersecurity (the CIA Triad), how attacks exploit human emotion rather than software, and business email compromise. Labs: phishing detection challenge, phishing indicator scans.
2 · Identity & Access Security
The three pillars of identity, and why password entropy beats complexity. Labs: password manager audit, desktop MFA setup, authenticator app rollout.
3 · Network Safety & Encryption
How packets are actually built, and the difference between passive and active sniffing. Labs: HTTPS padlock check, WPA2 vs WPA3 audit, VPN client tunnelling.
4 · Data Protection & the Privacy Act
RA 10173 in practice and the four-tier data classification standard. Labs: file permissions audit, OneDrive and SharePoint sharing rules, full-disk encryption.
5 · Incident Response & Drills
The first-responder flow, containment, and the “unplug rule”. Labs: ransomware tabletop drill, 3-2-1 backup strategy audit.
6 · Access Governance & Server-Side Security
Role-based access control, why validation must happen server-side, and how passwords are salted and hashed rather than stored. Labs: account life-cycle setup, hashing verification.
▶ Watch the film · 🎧 56-min explainer
7 · OWASP Top 10 Web Exploits
SQL injection, cross-site scripting and insecure direct object references — run in the isolated range, never against live systems. Labs: broken authentication, SQLi detection, live SIEM console monitoring.
8 · AI in Cyber Defence (Capstone)
Signature rules versus machine-learning intrusion detection, using CyberFlow IDS — a real system built by your own instructor. Lab: fool the model (adversarial ML), then the final capstone.
📋 The full syllabus
Enrolled trainees can download the complete 8-week calendar — every concept, every lab, and which video or podcast covers each week.
Download the syllabus (PDF) →⚠️ Cyber range ground rules
Every practical lab runs under three non-negotiable rules:
- Dummy data only — never real employee records, personal files or company data.
- Dedicated test accounts — never your own personal, banking or workplace logins.
- Isolated sandboxes — all exploitation and AI-evasion work stays inside the designated cyber range. Testing production networks is forbidden.
What you walk away with
Not just knowledge — four working tools, built on your own accounts and devices during the course.
- 📋 Phishing Email Analyzer Checklist — a 10-point test for any suspicious message
- 🔐 Password & MFA Setup Audit Guide — your top accounts, hardened
- 📄 Digital Workplace Cyber Hygiene Policy Sheet — a personal standard you sign
- 🚨 Incident Reporting & Escalation Matrix — real contacts, filled in before you need them
Watch: Cyber Threat Mitigation
A short film from Kanraul Media on how everyday threats reach Filipino workplaces — free for everyone, no sign-up.
Learn your way — module by module
Every module comes three ways: watch it, listen to it, or read it. Same content, whichever suits your day — the podcast episodes download for offline listening on the road.
▶ Watch the whole course in order — this player runs every module video back to back, newest included. Or open the playlist on YouTube to save it to your account.
Cyber Hygiene & Threat Vectors
Phishing, passwords and entropy, multi-factor authentication, physical security.
Network Safety & Remote Work
Wi-Fi encryption, public networks and evil twins, VPNs, safe browsing.
Data Protection & Privacy
Data classification, PII and the Data Privacy Act (RA 10173), endpoint governance.
Incident Response & Recovery
Indicators of compromise, ransomware, 3-2-1 backups, escalation triage.
New here? Start with the Cyber Threat Mitigation video above and podcast Episode 1 for the overview, then work through the modules in order.
Course materials
Everything for this course in one place — watch it, listen to it, read it, or work through the slides. The same content, whichever suits your day.
Browsing everything we publish? The Library lists every material across all our courses, filterable by course or type.
How you're assessed
Assessment is competency-based. Knowledge checks confirm understanding, but the artifacts and a final scenario assessment are where competence is demonstrated. Each artifact criterion is rated Competent or Not Yet Competent, and learners may revise and resubmit.
To earn the credential: ≥75% total score and all four artifacts rated Competent on every criterion.
Where it leads
This micro-credential is a deliberate on-ramp to TESDA's full national qualification, Cyber Threat Mitigation NC II (ICTCTM224) — 305 hours of in-center training plus 160 hours of supervised industry learning, preparing people for roles such as Cyber Threat Analyst, Security Support Specialist, and IT Security Support (Level 1).
Who wrote this program
Main author: Dr. Raul C. Gacusan
Trainer-contributors: Raul P. Gacusan, Jr., Nikko Unay Caray, Artemis Nueve Tico, and Cherry Mae Cardenas
Kanraul Builders Development Corporation and East Pacific Computer College, Inc.
Interested in the next batch?
This micro-credential runs inside our Digital Workplace Readiness Program. Email us to be told when the next cohort opens.