
ICO ITSec Penetration Testing Professional
Practical cybersecurity training in ethical hacking, penetration testing, vulnerability assessment, and security testing techniques.

ICO ITSec FND
Three days of hands-on cybersecurity fundamentals. You learn how attacks are actually carried out, how information is gathered before one, and the cryptography and forensics behind the defence. Prepares you for the ICO ITSec Penetration Testing FND exam.
About this course
You cannot defend a system you do not know how to attack. Most security training explains policies; this one starts from the attacker's side, because that is where the useful understanding comes from. By the end of it you know how a target is mapped, how the common attacks work, and why the countermeasures you have heard about exist.
This foundation course runs over three instructor led days, online, with practical work throughout. You cover the terminology and method of a penetration test, spend the largest block on information gathering and attack techniques, then close with the cryptography and the forensic principles that sit underneath every serious security discussion. You leave able to follow a security conversation as a participant rather than an observer.
Who this course is for
- IT staff and administrators who want to understand the attacks they are defending against
- Developers who keep meeting security requirements and want to know what is behind them
- Security newcomers preparing for a first role in the field
- Anyone heading for the ICO ITSec Penetration Testing Professional certification, for whom this is the first step
What you will learn
- Use the vocabulary of offensive security precisely, and describe how a penetration test is structured from scoping to reporting
- Tell a penetration test and an ISMS audit apart, and know when each is the right instrument
- Gather information about a target the way an attacker does, and see how much is available before anything is touched
- Recognise the common attack classes, including denial of service, and understand the mechanism rather than the label
- Explain symmetric, asymmetric and hybrid encryption, hash functions and where each belongs
- Apply the principles of IT forensics: what evidence is, how it is preserved and what destroys it
Course outline
Day one, method and attack
- Prerequisites and the ground the course assumes
- Procedure and important terms, how a penetration test is run
- Information gathering and attack, the largest block of the course, worked hands on
Day two, cryptology
- Cryptography and cryptanalysis, and why the distinction matters
- Kerckhoffs's principle, symmetric, asymmetric and hybrid encryption
- Cryptographic hash functions and their practical use
Day three, forensics
- Principles of IT forensics and the handling of evidence
- Exam preparation and sample questions
Prerequisites
None that are formally required. General IT knowledge, in particular a working understanding of networks and operating systems, will let you get considerably more out of the practical parts.
Exam and certification
The course prepares you for the ICO ITSec Penetration Testing FND examination, awarded by ICO International Certification Organization GmbH. It is an accredited certification exam, not a certificate of attendance.
- 30 multiple choice questions, where one, several or all options may be correct
- 45 minutes, closed book
- Pass mark of 60 percent
- Taken online, at a time and place you choose
The exam is available as an optional add on to the course. Full details are published by the awarding body at ico-cert.org.
What is included
- Three days, 24 hours, of live instructor led online training in English
- Small groups, never more than 22 participants
- Complete course materials, exercises and sample exam questions
- Hands on work in every block, against prepared targets in a safe environment
- Certificate of attendance, with the ICO ITSec Penetration Testing FND exam as an optional add on

ICO ITSec PRO
Five days of ethical hacking and penetration testing, on site and hands on. You work through network, operating system and application level testing, social engineering and cryptography, inside the legal framework that makes it lawful. Prepares you for the ICO ITSec Penetration Testing PRO exam.
About this course
A penetration test is a controlled attack carried out with permission. Everything that makes it useful, and everything that keeps it legal, comes from doing it methodically: a defined scope, a written mandate, a reproducible procedure and a report someone can act on. Improvised hacking is neither a service nor, in most jurisdictions, lawful.
This professional course runs over five instructor led days on site, and it is the practical half of the ITSec pathway. You test at network level, at operating system level and at application level, you work the human factor, and you close with the cryptography a tester meets in the field. The legal and organisational groundwork comes first, because it is what separates a penetration tester from an intruder.
Who this course is for
- IT security specialists moving into offensive testing
- System and network administrators who want to test their own infrastructure properly
- Consultants who will deliver penetration tests as a service
- Security engineers who need to reproduce and verify findings rather than take them on trust
- Holders of the ITSec foundation certificate continuing towards the Professional role
What you will learn
- Scope, mandate and document a penetration test so that it is lawful, repeatable and useful to the client
- Test at network level, from the OSI and TCP/IP model through data link layer and VLAN weaknesses to switching
- Test at operating system level and understand where privilege boundaries actually fail
- Test at application level, the layer where most real findings live
- Work the human factor, from pretexting to phishing, and report it without damaging the people involved
- Apply cryptography in the field: what to attack, what not to bother attacking, and how to recognise the difference
Course outline
Day one, ground rules and the network
- Requirements and the knowledge the course builds on
- Legal and organisational basics of penetration testing, mandate, scope and reporting duties
- Penetration testing at network level
Day two, operating systems
- Penetration testing at operating system level, hands on
Day three, applications
- Penetration testing at application level, hands on
Day four, the human factor
- Attack through the human factor, method, boundaries and reporting
Day five, cryptology and close
- Cryptology in practice
- Exam preparation and sample questions
Prerequisites
None that are formally required. We recommend the ICO ITSec Penetration Testing FND certificate or equivalent knowledge, together with solid networking and operating system experience, because the course works at that level from the first day.
Exam and certification
The course prepares you for the ICO ITSec Penetration Testing PRO examination, awarded by ICO International Certification Organization GmbH. Passing both the foundation and the professional exam leads to the ICO ITSec Penetration Testing Professional role certificate, issued without a further exam.
- 50 multiple choice questions, where one, several or all options may be correct
- 100 minutes, closed book
- Pass mark of 60 percent
- Taken online, at a time and place you choose
The exam is available as an optional add on to the course. Full details are published by the awarding body at ico-cert.org.
What is included
- Five days, 40 hours, of instructor led classroom training in English
- Small groups, never more than 28 participants
- Complete course materials, exercises and sample exam questions
- A prepared lab environment, with hands on testing every day
- Certificate of attendance, with the ICO ITSec Penetration Testing PRO exam as an optional add on