The Certified Cyber Security Incident Handler (CCIH) program equips professionals with the knowledge and hands-on skills to detect, contain, eradicate, and recover from cybersecurity incidents. This course follows the NIST SP 800-61 framework and prepares candidates for real-world incident response roles.
Welcome, young cyber hero! Let’s learn how to protect computers and stop bad guys online.
Imagine you are a superhero whose job is to keep your city safe. But instead of fighting villains with capes, you fight computer villains – hackers, viruses, and other digital dangers. That’s what Cyber Security Incident Handling is all about!
In this module, we will learn what a cyber security incident is, why it happens, and how we can handle it like a real professional. We’ll use simple words, fun stories, and lots of examples from home, school, and even Nigeria.
By the end of this module, you will know how to spot a cyber incident, what to do first, and how to stay calm – just like a true incident handler!
After studying this module, you will be able to:
Meet Tunde and Ada. They are best friends in Primary 6 in Lagos, Nigeria. One morning, Tunde opened his laptop to print his homework – but all his files were gone! Instead, there was a scary message: “Your files are locked. Pay 50,000 Naira to get them back.”
Tunde felt sad and scared. He told his teacher, Mrs. Bello, who called the school’s cyber security team. The team acted fast! They:
Tunde learned that incident handlers are like digital firefighters – they rush in, put out the fire, and help you get back to normal. And that’s exactly what we’ll learn in this module!
Definition: Cyber security means keeping our computers, phones, and information safe from bad people and bad programs.
Why it's important: We use computers for school, games, talking to friends, and even banking. If a bad person gets in, they can steal our pictures, messages, or money.
Simple explanation: Think of cyber security like locking your front door. You wouldn’t leave your house open for strangers to walk in. Cyber security locks the “digital door” to your devices.
Real-life example: When you put a password on your tablet, that’s cyber security. It keeps your little brother from deleting your game progress!
School example: Your school’s Wi‑Fi has a password so that only students and teachers can use it. That stops outsiders from using the school’s internet.
Home example: Your parents use a PIN to unlock their phones. That’s a simple form of cyber security.
Nigerian example: Many banks in Nigeria use two-factor authentication (2FA). When you log in, they send a code to your phone. That extra step makes it harder for hackers to steal your money.
+-------------------------------+
| CYBER SECURITY |
| (Keeping things safe online) |
+-------------------------------+
|
V
+-------+-------+
| |
V V
Passwords Antivirus
| |
V V
Locking your Scanning for
digital door bad programs
Definition: A cyber security incident is any unexpected event that threatens the safety of our computers or data. It could be a virus, a hacker breaking in, or someone stealing information.
Why it's important: If we don’t notice an incident, it can get worse – like a small fire becoming a big one. We need to spot it early and act fast.
Simple explanation: Imagine you see a leak in your roof. If you fix it immediately, only a little water gets in. But if you ignore it, the ceiling could collapse. A cyber incident is the same: we must fix it quickly.
Real-life example: You get an email that says “You won 1 million Naira!” but you didn’t enter any contest. That’s probably a scam – a kind of incident.
School example: A teacher’s computer starts acting strangely and popping up ads. That could be a virus – an incident!
Home example: Your dad’s social media account posts strange messages that he didn’t write. Someone might have hacked it.
Nigerian example: Some people receive fake SMS saying “Your bank account is blocked, click this link to fix it.” That’s a phishing incident – a trick to steal your information.
What is a cyber incident?
-------------------------
🟢 Normal: You use your phone to call your mom.
🔴 Incident: Your phone starts sending spam to all your contacts.
Definition: A threat actor is a person or group that tries to harm your computer or steal your information. They are the “villains” of the cyber world.
Why it's important: Knowing who your enemy is helps you defend better. Just like in a game, if you know the boss’s weakness, you can defeat them.
Simple explanation: Think of threat actors as bullies who try to take your lunch money – but online, they try to take your passwords or files.
Real-life example: A hacker breaks into a company’s database and steals customer names and credit card numbers.
School example: A student uses a friend’s password without permission to change their grades. That student is a threat actor.
Home example: Someone tries to guess your Wi‑Fi password to use your internet for free.
Nigerian example: Scammers call people pretending to be bank officials to ask for their ATM PIN. They are threat actors.
+------------------+
| THREAT ACTORS |
+------------------+
| • Hackers |
| • Scammers |
| • Disgruntled |
| employees |
| • Cybercriminals |
+------------------+
Definition: A vulnerability is a weakness in a system that a threat actor can use to break in. It’s like a broken lock on a door.
Why it's important: If we know our weaknesses, we can fix them before the bad guys find them.
Simple explanation: Imagine you have a hole in your fence. A dog could squeeze through. That hole is a vulnerability. Fixing the hole means the dog can’t get in.
Real-life example: Using an old version of a game that has a bug – hackers can use that bug to cheat or crash your game.
School example: The school’s computer lab uses a very simple password like “password123”. That’s a vulnerability because it’s easy to guess.
Home example: You leave your phone unlocked on the table. Anyone can pick it up and see your messages – that’s a vulnerability.
Nigerian example: Some websites in Nigeria don’t use HTTPS (the padlock icon). That means information sent to them can be intercepted – a vulnerability.
+---------------------------------------+
| VULNERABILITY = WEAKNESS |
+---------------------------------------+
| Example: |
| Your password is "12345" |
| That's easy for hackers to guess. |
| So it's a vulnerability! |
+---------------------------------------+
Definition: A threat is anything that has the potential to cause harm to your computer or data. It’s like a storm that might hit your house.
Why it's important: If we know what threats exist, we can prepare for them – just like bringing an umbrella when rain is forecast.
Simple explanation: A threat is a danger that could hurt you. A virus is a threat. A hacker is a threat.
Real-life example: A new computer virus is spreading around the world. It’s a threat to all computers.
School example: A student shares a USB drive that contains a virus. That USB drive is a threat to the school’s computers.
Home example: An email that says “Click here to get free games” might actually be a threat – it could install malware.
Nigerian example: Cybercriminals send SMS messages with links that steal your bank details. Those messages are threats.
+----------------------------------+
| THREAT = DANGER |
+----------------------------------+
| • Virus |
| • Hacker |
| • Phishing email |
| • Fake website |
+----------------------------------+
Definition: Risk is the chance that a threat will actually use a vulnerability to cause harm. It’s like the chance of rain when you have a hole in your roof.
Why it's important: Understanding risk helps us decide what to fix first. We fix the biggest risks first – just like we fix the biggest holes in the roof first.
Simple explanation: Risk = Threat + Vulnerability. If there is a threat and there is a weakness, then there is a risk that something bad will happen.
Real-life example: You have a very old computer (vulnerability) and a new virus is spreading (threat). The risk is high that your computer will get infected.
School example: The school has a weak password policy (vulnerability) and there are students who want to hack (threat). The risk is that someone will break into the school’s system.
Home example: Your dad uses the same password for all his accounts (vulnerability). If one account gets hacked (threat), all his accounts are at risk.
Nigerian example: Many small businesses in Nigeria don’t train their staff about cyber security (vulnerability). Hackers know this (threat), so the risk of a successful attack is high.
+--------------------------------------------------+
| RISK = THREAT + VULNERABILITY |
+--------------------------------------------------+
| Example: |
| Threat = A virus is going around. |
| Vulnerability = Your computer has no antivirus. |
| Risk = High chance your computer gets infected. |
+--------------------------------------------------+
Definition: Incident handling is a 5-step process that helps us deal with cyber incidents in a calm and organized way. It’s like a fire drill – we know exactly what to do.
Why it's important: Having a plan means we don’t panic. We follow the steps and fix the problem quickly.
The 5 steps are:
Simple explanation: It’s like when you spill juice on the floor. First, you grab a mop (prepare). You see the spill (identify). You put a barrier so nobody steps in it (contain). You clean it up (eradicate). And then you dry the floor and put the mop away (recover).
+--------------------------------------------------+
| INCIDENT HANDLING PROCESS |
+--------------------------------------------------+
| 1. PREPARE - Get ready |
| ↓ |
| 2. IDENTIFY - Spot the problem |
| ↓ |
| 3. CONTAIN - Stop it from spreading |
| ↓ |
| 4. ERADICATE - Remove the bad thing |
| ↓ |
| 5. RECOVER - Go back to normal |
+--------------------------------------------------+
Definition: Prepare means getting ready before an incident happens. It’s like packing a first‑aid kit before you go on a trip.
Why it's important: If you wait until something bad happens, it’s too late to prepare. Being ready saves time and reduces damage.
Simple explanation: Preparation is like practicing a fire drill. You learn where to go so that when there’s a real fire, you know exactly what to do.
Real-life example: A company installs antivirus software on all its computers. That’s preparation.
School example: The school IT team makes backups of all student files. If a virus attacks, they can restore everything.
Home example: Your parents set up a strong password for the Wi‑Fi. That’s preparation.
Nigerian example: A bank in Lagos trains its staff to recognize phishing emails. That’s preparation.
+----------------------------------+
| PREPARE - GET READY |
+----------------------------------+
| • Install antivirus |
| • Make backups |
| • Train staff |
| • Create an incident plan |
+----------------------------------+
Definition: Identify means noticing that an incident is happening. It’s like seeing smoke and knowing there’s a fire.
Why it's important: The faster you identify an incident, the faster you can stop it. Early detection saves the day.
Simple explanation: Identification is like having a smoke alarm. It beeps to tell you something is wrong.
Real-life example: An antivirus program pops up a warning that it found a virus. That’s identification.
School example: A teacher notices that her computer is running very slowly and there are strange pop‑ups. She suspects an incident and reports it.
Home example: You get a message from a friend saying “I didn’t send that!” when you receive a strange link from them. That’s a sign that their account may be hacked.
Nigerian example: A customer calls his bank to say he received an SMS asking for his PIN. The bank identifies this as a possible phishing attempt.
+----------------------------------+
| IDENTIFY - SPOT THE PROBLEM |
+----------------------------------+
| Signs of an incident: |
| • Slow computer |
| • Strange pop-ups |
| • Files disappear |
| • Unusual emails sent from you |
+----------------------------------+
Definition: Contain means stopping the incident from spreading to other parts of the system. It’s like putting up a fence to stop a fire from reaching the rest of the house.
Why it's important: If you don’t contain it, the incident can spread and affect more computers and data.
Simple explanation: Containment is like catching a ball before it rolls down the street. You stop it where it is.
Real-life example: If a computer gets a virus, the IT team immediately disconnects it from the network so the virus can’t spread to other computers.
School example: The school IT team finds a virus on one computer and unplugs it from the internet and the school network.
Home example: Your dad notices a suspicious app on his phone and immediately turns off the Wi‑Fi to prevent it from sending data.
Nigerian example: A company in Abuja detects a hacker in their system and immediately blocks that hacker’s IP address to stop further access.
+----------------------------------+
| CONTAIN - STOP THE SPREAD |
+----------------------------------+
| Actions: |
| • Disconnect from network |
| • Turn off affected devices |
| • Block the hacker's IP |
| • Isolate the infected system |
+----------------------------------+
Definition: Eradicate means removing the cause of the incident completely. It’s like pulling out a weed by its roots so it never grows back.
Why it's important: If you don’t remove the cause, the incident can come back again.
Simple explanation: Eradication is like cleaning a cut with medicine. You don’t just cover it – you clean it so it heals properly.
Real-life example: The IT team runs a full antivirus scan to delete all traces of the virus from the computer.
School example: After containing the virus, the school’s IT team formats the infected computer and reinstalls a clean operating system.
Home example: Your mom uninstalls a suspicious app from her phone and changes all her passwords.
Nigerian example: A bank discovers that a hacker planted a program to steal customer data. They remove the program and patch the vulnerability that allowed it in.
+----------------------------------+
| ERADICATE - REMOVE THE CAUSE |
+----------------------------------+
| Actions: |
| • Run antivirus scans |
| • Delete infected files |
| • Reinstall clean systems |
| • Patch vulnerabilities |
+----------------------------------+
Definition: Recover means getting everything back to normal after the incident. It’s like cleaning up after a party and putting everything back where it belongs.
Why it's important: Recovery gets you back to business – you can use your computer again, and you learn how to prevent it in the future.
Simple explanation: Recovery is like repairing a broken toy. You fix it so you can play with it again.
Real-life example: After the virus is removed, the IT team restores all files from a backup and makes sure everything works.
School example: The school restores all student assignments from the backup and teachers check that everything is okay.
Home example: Your dad restores his phone from a backup and changes all his passwords to new, strong ones.
Nigerian example: After a cyber attack, a Nigerian company reviews what happened, updates its security policies, and trains its staff again.
+----------------------------------+
| RECOVER - BACK TO NORMAL |
+----------------------------------+
| Actions: |
| • Restore files from backup |
| • Test that everything works |
| • Learn from the incident |
| • Update the incident plan |
+----------------------------------+
Definition: A cyber threat is any danger that can harm your computer or data. There are many types of threats.
Why it's important: Knowing the different threats helps you recognize them and avoid them.
Common threats include:
+------------------------------------------+
| COMMON CYBER THREATS |
+------------------------------------------+
| 🦠 Virus – spreads and harms |
| 🎣 Phishing – tricks you to share info |
| 🔒 Ransomware – locks your files |
| 🕵️ Hacking – breaks into your system |
| 💀 Malware – bad software |
+------------------------------------------+
Definition: Incident handlers are the people who follow the 5 steps to stop cyber incidents. They are like doctors for computers.
Why it's important: Without incident handlers, attacks would spread, data would be lost, and people would panic. Incident handlers save the day!
Simple explanation: Incident handlers are like superheroes who know exactly what to do when a cyber villain attacks.
Real-life example: When a hospital’s computers are hit by ransomware, incident handlers step in to stop the attack and restore patient records.
School example: When a student accidentally downloads a virus, the school’s incident handler cleans the computer and teaches the student how to avoid it next time.
Home example: Your dad calls the tech support (incident handlers) when his email gets hacked. They help him recover his account.
Nigerian example: In Nigeria, incident handlers help banks, government agencies, and businesses stay safe from cyber attacks.
+------------------------------------------+
| INCIDENT HANDLERS = DIGITAL HEROES |
+------------------------------------------+
| They: |
| • Stop attacks |
| • Restore data |
| • Teach people how to stay safe |
| • Make the cyber world safer |
+------------------------------------------+
Definition: You don’t have to be an adult to help with cyber security. Even kids can be cyber heroes by following simple safety rules.
Why it's important: Everyone plays a part in keeping the digital world safe. The more people who know how to stay safe, the harder it is for bad guys to succeed.
Simple explanation: Being a cyber hero is like being a hall monitor – you watch out for trouble and tell an adult if you see something wrong.
Things you can do:
+------------------------------------------+
| BE A CYBER HERO – TIPS FOR KIDS |
+------------------------------------------+
| 1. Use a strong password. |
| 2. Don't click on strange links. |
| 3. Tell an adult if something is wrong. |
| 4. Keep your apps and games updated. |
| 5. Keep your personal info private. |
+------------------------------------------+
| Word | Simple Definition |
|---|---|
| Cyber Security | Keeping computers and information safe from bad people. |
| Incident | An unexpected event that threatens computer safety. |
| Threat | A danger that could harm your computer or data. |
| Vulnerability | A weakness that bad people can use to attack. |
| Risk | The chance that a threat will use a vulnerability to cause harm. |
| Phishing | A trick to fool you into giving away your password or personal info. |
| Ransomware | A virus that locks your files and demands money to unlock them. |
| Malware | Bad software that harms your computer. |
| Hacker | A person who tries to break into computers without permission. |
| Incident Handler | A person who follows the 5 steps to stop cyber incidents. |
+--------------------------------------------------+
| STEP-BY-STEP INCIDENT HANDLING |
+--------------------------------------------------+
| 1. PREPARE - Get ready (antivirus, backups) |
| 2. IDENTIFY - Spot the problem (signs) |
| 3. CONTAIN - Stop the spread (disconnect) |
| 4. ERADICATE - Remove the cause (scan & delete)|
| 5. RECOVER - Restore & learn |
+--------------------------------------------------+
+----------------------------------------------------+
| INCIDENT HANDLING TIMELINE |
+----------------------------------------------------+
| PREPARE → IDENTIFY → CONTAIN → ERADICATE → RECOVER |
| ↓ ↓ ↓ ↓ ↓ |
| Get ready Spot the Stop the Remove the Back to |
| problem spread cause normal |
+----------------------------------------------------+
+--------------------------------------------------+
| THREAT + VULNERABILITY = RISK |
+--------------------------------------------------+
| Threat = A lion is near your house. |
| Vulnerability = Your fence has a hole. |
| Risk = High chance the lion gets in. |
+--------------------------------------------------+
| Threat Type | What It Does | How to Protect |
|---|---|---|
| Virus | Spreads and harms your computer | Install antivirus |
| Phishing | Tricks you to share info | Don't click on suspicious links |
| Ransomware | Locks your files and demands money | Backups + antivirus |
| Hacking | Breaks into your system | Strong passwords + 2FA |
| Malware | Bad software that harms your computer | Antivirus + updates |
| Physical Security | Cyber Security |
|---|---|
| Locking your front door | Using a strong password |
| Burglar alarms | Antivirus software |
| Security cameras | Monitoring network traffic |
| Fencing your yard | Firewall protection |
| Police patrols | Incident handlers |
| Threat | How It Spreads | Damage |
|---|---|---|
| Virus | Attaches to files, email attachments | Slow down, delete files |
| Phishing | Email, SMS, fake websites | Steal passwords, bank details |
| Ransomware | Email attachments, downloads | Lock files, demand money |
| Hacking | Exploiting vulnerabilities | Steal data, take control |
| Malware | Downloads, infected USB drives | Various – spying, deleting, etc. |
Congratulations! You have completed Module 1 of the Certified Cyber Security Incident Handler (CCIH) course.
In this module, you learned:
Key takeaway: Incident handling is like a fire drill for computers – it helps us stay calm, act quickly, and fix problems before they get worse.
It’s any unexpected event that threatens the safety of your computer or data – like a virus or a hacker.
It helps us stop incidents quickly and recover from them with less damage.
A threat is a danger (like a virus), and a vulnerability is a weakness (like a missing password).
Absolutely! By following safety rules and telling adults about problems, kids can help keep everyone safe.
Phishing is a trick where bad people pretend to be someone you trust to steal your information.
Don’t click on any links. Tell an adult and delete the email.
It’s best to back up your files at least once a week.
Ransomware is a virus that locks your files and demands money to unlock them.
The first step is to Prepare – get your antivirus ready and make backups.
Yes! Incident handlers are in high demand. If you love computers and helping people, this could be a great career for you.
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. Virus | A. A trick to steal your information |
| 2. Phishing | B. A weakness that bad people can use |
| 3. Vulnerability | C. A program that spreads and harms your computer |
| 4. Risk | D. The chance that a threat will cause harm |
| 5. Ransomware | E. A virus that locks your files and demands money |
Scenario 1: You receive an email that says “Your account has been compromised. Click here to reset your password.” The email looks like it’s from your school. What do you do?
Scenario 2: Your computer suddenly becomes very slow and displays strange ads. What steps would you take to handle this incident?
Scenario 3: Your friend’s social media account starts posting weird messages. Your friend says they didn’t post them. What should your friend do?
Activity: Divide the class into groups of 4–5. Each group will create a short skit (play) that shows the 5 steps of incident handling in action. Use a simple scenario like a virus on a school computer. Present your skit to the class.
Activity: Draw a comic strip showing a cyber security incident and how it is handled using the 5 steps. Label each step in your comic.
Project: Create a “Cyber Security Incident Handling” poster for your school. The poster should show the 5 steps (Prepare, Identify, Contain, Eradicate, Recover) with simple explanations and pictures. Display your poster in the classroom or school library.
Assignment: Interview a family member about a time they experienced a cyber security issue (like a virus or a hacked account). Ask them:
Write a short report about your interview and share it with the class.
Challenge: Can you create a simple “incident handling” board game? The game should take players through the 5 steps of incident handling. Each step can be a space on the board. Players roll a dice and move forward. If they land on a “threat” space, they must answer a question about cyber security to stay safe!
In Module 2, we will dive deeper into the Prepare step. You will learn:
Before the next class: Think about what you would put in a “cyber security kit” for your home or school. What tools would you need to stay safe?
See you in Module 2, young cyber hero! 🚀
Hello, cyber hero! In Module 1, we learned about the 5 steps of incident handling. Now it’s time to dive deep into the very first step: PREPARE.
Imagine you are going on a big adventure. Would you leave home without packing food, water, and a map? Of course not! You would prepare first.
In the cyber world, preparation is exactly the same. It means getting everything ready before a cyber incident happens. When you prepare, you are like a scout who checks the path ahead. You make sure you have the right tools, the right plan, and the right team.
In this module, we will learn:
By the end of this module, you will know how to be ready for anything in the digital world. Let’s go!
After studying this module, you will be able to:
Meet Sunshine Primary School in Lagos, Nigeria. The school had a smart principal named Mrs. Adeyemi. She heard about cyber attacks happening to other schools, so she decided to prepare.
She did four things:
One day, a student received a strange email saying “Click here to get free data!” The student remembered the training. She did not click and told her teacher. The IT team checked the email and found it was a phishing attempt. Because the school was prepared, they stopped the attack before it could cause any harm.
Mrs. Adeyemi smiled and said, “Preparation saved our school today!”
Definition: Prepare means getting everything ready before a cyber incident happens so you can respond quickly and effectively.
Why it's important: If you wait until an incident happens to prepare, it’s too late. Preparation saves time, money, and stress. It’s like having a fire extinguisher ready before a fire starts.
Simple explanation: Preparation is like packing your school bag the night before. When you wake up, you’re ready to go. You don’t have to rush and forget things.
Real-life example: A company installs antivirus software on all its computers and makes regular backups. That’s preparation.
School example: The school IT team creates a list of all computers and their software. They check for updates every week.
Home example: Your parents set up a strong Wi‑Fi password and teach you not to share it with strangers.
Nigerian example: A bank in Abuja trains its staff to recognize phishing emails and conducts regular security drills.
+--------------------------------------------------+
| PREPARE = GET READY BEFORE THE STORM |
+--------------------------------------------------+
| • Install antivirus |
| • Make backups |
| • Create a plan |
| • Train your team |
| • Test your systems |
+--------------------------------------------------+
Definition: An Incident Response Plan (or IR Plan) is a written document that tells everyone exactly what to do when a cyber incident happens. It’s like a map that shows you the way.
Why it's important: When people panic, they make mistakes. An IR plan gives clear instructions so everyone stays calm and acts quickly.
Simple explanation: An IR plan is like a recipe for making a cake. If you follow the recipe step by step, the cake turns out great. If you don’t, it might be a mess!
Real-life example: A hospital has an IR plan that says: “Step 1: Disconnect infected computers. Step 2: Call the IT team. Step 3: Restore patient data from backups.”
School example: A school’s IR plan says: “If a virus is found, tell the IT teacher immediately. Do not turn off the computer. Wait for instructions.”
Home example: A family’s IR plan says: “If someone’s account is hacked, change all passwords and enable 2-factor authentication.”
Nigerian example: A Nigerian company’s IR plan includes contact numbers for the IT team, legal team, and public relations team.
+--------------------------------------------------+
| INCIDENT RESPONSE PLAN (IR PLAN) |
+--------------------------------------------------+
| What to include: |
| 1. Contact list (who to call) |
| 2. Step-by-step actions |
| 3. Tools to use |
| 4. Who does what (roles) |
| 5. How to document the incident |
+--------------------------------------------------+
Definition: A cyber security team is a group of people who work together to protect computers and respond to incidents. Each person has a special role.
Why it's important: One person cannot do everything. A team shares the work and makes sure nothing is missed.
Simple explanation: A cyber security team is like a football team. Each player has a position – goalkeeper, defender, midfielder, and striker. Everyone works together to win the game.
Real-life example: A company’s cyber team has a manager, a technical expert, a communications person, and a legal advisor.
School example: The school’s cyber team includes the IT teacher, the principal, and a student representative.
Home example: In a family, the cyber team might be mom, dad, and the older siblings who know about computers.
Nigerian example: A Nigerian bank’s cyber team has a Chief Information Security Officer (CISO), security analysts, and compliance officers.
+--------------------------------------------------+
| CYBER SECURITY TEAM ROLES |
+--------------------------------------------------+
| 👨💼 Incident Commander – makes big decisions |
| 🖥️ Technical Lead – fixes the problem |
| 📢 Communications Lead – talks to people |
| ⚖️ Legal Lead – handles legal issues |
| 📋 Documentation Lead – writes everything down |
+--------------------------------------------------+
Definition: Tools are the software and hardware you use to protect your computers and respond to incidents. They are like the equipment a firefighter carries.
Why it's important: The right tools make the job easier and faster. Without tools, you can’t fight cyber threats effectively.
Simple explanation: Tools are like a pencil sharpener for a pencil. You could sharpen a pencil with a knife, but a sharpener is faster and safer.
Common tools include:
+--------------------------------------------------+
| TOOLS FOR PREPARATION |
+--------------------------------------------------+
| 🛡️ Antivirus – fights viruses |
| 🧱 Firewall – blocks bad traffic |
| 💾 Backup – saves copies of files |
| 👀 Monitoring – watches for danger |
| 🔑 Password mgr – keeps passwords safe |
+--------------------------------------------------+
Definition: Antivirus and anti-malware are programs that find, block, and remove bad software (malware) from your computer.
Why it's important: Malware can steal your information, slow down your computer, or even lock your files. Antivirus stops these bad programs.
Simple explanation: Antivirus is like a security guard at the entrance of a building. The guard checks everyone who comes in and stops bad people from entering.
Real-life example: You download a game from the internet. Your antivirus scans it and says, “This file is safe” or “This file is dangerous.”
School example: The school installs antivirus on all computers. Every morning, the computers scan for viruses.
Home example: Your mom’s laptop has an antivirus that runs a scan every week to check for problems.
Nigerian example: A Nigerian business uses a well-known antivirus like Kaspersky or Norton to protect its computers.
+--------------------------------------------------+
| HOW ANTIVIRUS WORKS |
+--------------------------------------------------+
| Step 1: Scan the file or program. |
| Step 2: Compare it to a list of known viruses. |
| Step 3: If it matches, block or delete it. |
| Step 4: If safe, let it run. |
+--------------------------------------------------+
Definition: A firewall is a security system that monitors and controls what goes in and out of your network. It’s like a digital wall.
Why it's important: A firewall stops hackers and bad programs from entering your network. It also stops your computer from sending out your private information.
Simple explanation: A firewall is like a fence around your house. The fence has a gate that only lets in people you trust.
Real-life example: A company uses a firewall to block employees from visiting dangerous websites.
School example: The school’s firewall blocks access to social media sites during class hours.
Home example: Your home router has a built-in firewall that protects all devices connected to your Wi‑Fi.
Nigerian example: A Nigerian university uses a firewall to prevent students from accessing harmful content.
+--------------------------------------------------+
| FIREWALL – THE DIGITAL WALL |
+--------------------------------------------------+
| Internet ----> [FIREWALL] ----> Your Computer |
| | |
| Bad traffic |
| is blocked! |
+--------------------------------------------------+
Definition: A backup is a copy of your important files stored in a safe place. If something happens to the original, you can use the backup.
Why it's important: If your computer gets a virus or crashes, your files could be lost forever. Backups save you from that heartbreak.
Simple explanation: A backup is like having a spare key to your house. If you lose the main key, the spare key lets you get in.
Real-life example: A company backs up all its customer data every night. If a hacker deletes the data, they can restore it from the backup.
School example: The school backs up all student assignments to a cloud service like Google Drive.
Home example: Your dad backs up photos from his phone to an external hard drive.
Nigerian example: A small business in Ibadan uses a portable hard drive to back up its financial records every Friday.
+--------------------------------------------------+
| BACKUP – YOUR DIGITAL INSURANCE |
+--------------------------------------------------+
| Original Files ----> [BACKUP] ----> Safe Copy |
| | |
| If original is lost, |
| you have the backup! |
+--------------------------------------------------+
Definition: Updates and patches are fixes that software companies release to improve their programs and fix security holes.
Why it's important: Hackers look for holes (vulnerabilities) in software. Updates patch those holes so hackers can’t get in.
Simple explanation: Updates are like fixing a broken window. If you leave the window broken, anyone can climb in. Fixing it keeps them out.
Real-life example: When your phone says “Update available,” it often includes security fixes. You should update it right away.
School example: The school IT team updates all computers every month to keep them secure.
Home example: Your dad updates the Wi‑Fi router to fix a security problem.
Nigerian example: A bank in Lagos updates its banking app regularly to protect customers from fraud.
+--------------------------------------------------+
| UPDATES AND PATCHES |
+--------------------------------------------------+
| Software has bugs (mistakes). |
| Hackers use bugs to break in. |
| Updates fix the bugs. |
| Always install updates! |
+--------------------------------------------------+
Definition: Training and awareness means teaching people how to recognize cyber threats and what to do about them.
Why it's important: The best technology in the world can’t stop a person from making a mistake. Training helps people avoid mistakes.
Simple explanation: Training is like teaching someone to ride a bike. At first, they might fall, but with practice, they become confident and safe.
Real-life example: A company holds a “Cyber Security Day” where employees learn about phishing and password safety.
School example: The school invites a cyber security expert to talk to students about online safety.
Home example: Your parents teach you not to share your password with anyone.
Nigerian example: A Nigerian NGO runs workshops teaching small business owners about cyber security.
+--------------------------------------------------+
| TRAINING AND AWARENESS |
+--------------------------------------------------+
| Topics to cover: |
| • How to spot phishing |
| • How to create strong passwords |
| • What to do if you see something suspicious |
| • Why updates are important |
+--------------------------------------------------+
Definition: Testing means checking if your preparations actually work. It’s like a fire drill – you practice so you know what to do in a real fire.
Why it's important: If you don’t test, you might think you’re ready – but when an incident happens, you might find that something doesn’t work.
Simple explanation: Testing is like tasting your food before you serve it. You want to make sure it’s good!
Real-life example: A company runs a “tabletop exercise” where they pretend a cyber attack is happening and practice their response.
School example: The school does a “phishing test” – they send a fake suspicious email to see if students and teachers click on it.
Home example: Your family practices what to do if a device gets a virus – who to call, what to turn off, etc.
Nigerian example: A Nigerian company hires a security firm to test their systems by trying to break in (with permission). That’s called a penetration test.
+--------------------------------------------------+
| TESTING YOUR PREPARATIONS |
+--------------------------------------------------+
| 1. Run a practice drill. |
| 2. Send a fake phishing email. |
| 3. Test your backups – can you restore them? |
| 4. Review your plan and update it if needed. |
+--------------------------------------------------+
Definition: A communication plan is a plan that says who talks to whom during an incident, and what they say.
Why it's important: During an incident, people get confused. A communication plan makes sure everyone gets the right information at the right time.
Simple explanation: A communication plan is like a game of telephone – but instead of whispering, you have clear rules about who says what to whom.
Real-life example: A company’s communication plan says: “The IT team talks to the legal team. The legal team talks to the public. No one else talks to the media.”
School example: The school’s plan says: “If there’s a cyber incident, the principal talks to the parents. Teachers talk to the students. No one posts on social media.”
Home example: Your family’s plan says: “If someone’s account is hacked, everyone changes their passwords and we call the bank.”
Nigerian example: A Nigerian company has a communication plan that includes how to inform customers if their data is exposed.
+--------------------------------------------------+
| COMMUNICATION PLAN |
+--------------------------------------------------+
| Who talks to whom? |
| Incident Team --> Management |
| Management --> Legal Team |
| Legal Team --> Public (if needed) |
| Everyone --> No social media posts! |
+--------------------------------------------------+
Definition: Documentation means writing down everything that happens during an incident. It’s like keeping a diary.
Why it's important: Documentation helps you learn from the incident. It also helps if there are legal issues or insurance claims.
Simple explanation: Documentation is like keeping a scorecard in a game. At the end, you can see what worked and what didn’t.
Real-life example: During an incident, the IT team writes down: “Time: 10:15am. Found a virus on Server A. Took it offline.”
School example: The school IT teacher writes down every incident, what happened, and how it was fixed.
Home example: Your dad keeps a log of all the devices in the house and when they were last updated.
Nigerian example: A Nigerian bank keeps detailed records of all cyber incidents as required by the Central Bank of Nigeria.
+--------------------------------------------------+
| DOCUMENTATION EXAMPLE |
+--------------------------------------------------+
| Incident Report Form |
| Date: 15-Oct-2025 |
| Time: 09:30am |
| What happened: Virus detected on Computer #12 |
| Who found it: IT Teacher, Mr. Okafor |
| What was done: Computer isolated, virus removed |
| Result: System restored from backup |
+--------------------------------------------------+
Definition: Legal and compliance means following the laws and rules that apply to cyber security. In Nigeria, there are laws that protect people’s data.
Why it's important: If you don’t follow the law, you could get into trouble – fines, lawsuits, or even jail. Following the law also builds trust.
Simple explanation: Legal and compliance is like playing by the rules in a game. If you don’t follow the rules, you might get disqualified.
Real-life example: A company that loses customer data must report it to the authorities and tell the customers.
School example: The school must protect student data and not share it with anyone without permission.
Home example: Your parents are careful about what personal information they share online.
Nigerian example: Nigeria has the NDPR (Nigeria Data Protection Regulation) that says organizations must protect people’s data.
+--------------------------------------------------+
| LEGAL AND COMPLIANCE |
+--------------------------------------------------+
| • Follow the law |
| • Protect people's data |
| • Report incidents when required |
| • Be honest and transparent |
+--------------------------------------------------+
Definition: Leadership is the people who make decisions and guide the team. In preparation, leaders set the tone and make sure everything is ready.
Why it's important: If leaders don’t care about cyber security, no one else will. Leaders must show that cyber security is a priority.
Simple explanation: A leader is like the captain of a ship. The captain makes sure the ship has enough food, fuel, and lifeboats before sailing.
Real-life example: The CEO of a company says, “Cyber security is our top priority,” and gives the IT team a budget to buy the best tools.
School example: The principal of a school says, “We will train all students on cyber safety,” and makes it happen.
Home example: A parent takes the lead on cyber security by setting up strong passwords and teaching the family.
Nigerian example: The managing director of a Nigerian company participates in cyber security training alongside employees to show it’s important.
+--------------------------------------------------+
| LEADERSHIP IN PREPARATION |
+--------------------------------------------------+
| • Set the priority |
| • Allocate resources (money, time, people) |
| • Lead by example |
| • Hold everyone accountable |
+--------------------------------------------------+
Definition: A preparation checklist is a list of all the things you need to do to be ready. It helps you make sure nothing is forgotten.
Why it's important: It’s easy to forget things. A checklist makes sure you remember everything.
Simple explanation: A checklist is like a shopping list – you write down everything you need so you don’t forget anything at the store.
Your preparation checklist should include:
+--------------------------------------------------+
| PREPARATION CHECKLIST |
+--------------------------------------------------+
| ☐ IR Plan written and shared |
| ☐ Antivirus installed |
| ☐ Firewall enabled |
| ☐ Backups created |
| ☐ Software updated |
| ☐ Team trained |
| ☐ Communication plan ready |
| ☐ Documentation templates |
| ☐ Tests scheduled |
+--------------------------------------------------+
| Word | Simple Definition |
|---|---|
| Prepare | Getting everything ready before an incident happens. |
| Incident Response Plan (IR Plan) | A written guide that tells everyone what to do during an incident. |
| Antivirus | Software that finds and removes viruses. |
| Firewall | A system that blocks bad traffic from entering your network. |
| Backup | A copy of your important files stored in a safe place. |
| Patch | A fix for a security hole in software. |
| Training | Teaching people how to recognize and respond to cyber threats. |
| Testing | Checking if your preparations actually work. |
| Communication Plan | A plan that says who talks to whom during an incident. |
| Documentation | Writing down everything that happens during an incident. |
+--------------------------------------------------+
| HOW TO PREPARE – STEP BY STEP |
+--------------------------------------------------+
| 1. Create an IR Plan |
| ↓ |
| 2. Install security tools |
| ↓ |
| 3. Make backups |
| ↓ |
| 4. Update everything |
| ↓ |
| 5. Train your team |
| ↓ |
| 6. Test your plan |
| ↓ |
| 7. Review and improve |
+--------------------------------------------------+
+----------------------------------------------------+
| PREPARATION PROCESS |
+----------------------------------------------------+
| START |
| ↓ |
| Create IR Plan |
| ↓ |
| Install Tools (antivirus, firewall) |
| ↓ |
| Make Backups |
| ↓ |
| Update Software |
| ↓ |
| Train Team |
| ↓ |
| Test & Drill |
| ↓ |
| Review & Improve |
| ↓ |
| END (but repeat regularly!) |
+----------------------------------------------------+
| Section | What It Contains |
|---|---|
| 1. Purpose | Why the plan exists |
| 2. Scope | What the plan covers |
| 3. Roles and Responsibilities | Who does what |
| 4. Incident Categories | Types of incidents |
| 5. Response Procedures | Step-by-step actions |
| 6. Communication Plan | Who to talk to |
| 7. Documentation | How to record the incident |
| Activity | How Often | Why It's Important |
|---|---|---|
| Update antivirus | Daily | Stops new viruses |
| Backup files | Weekly | Saves your data |
| Train staff | Yearly | Keeps people aware |
| Test IR plan | Yearly | Makes sure it works |
| Review documentation | After each incident | Learn and improve |
| Prepared Organization | Unprepared Organization |
|---|---|
| Has an IR plan | No plan at all |
| Has antivirus and firewalls | No security software |
| Makes regular backups | No backups |
| Updates software regularly | Uses outdated software |
| Trains employees | No training |
| Responds to incidents in hours | Takes weeks to respond |
| Recovers quickly | May never fully recover |
| Tool | What It Does | Example |
|---|---|---|
| Antivirus | Finds and removes viruses | Kaspersky, Norton |
| Firewall | Blocks bad traffic | Windows Firewall, Cisco |
| Backup | Copies your files | Google Drive, external hard drive |
| Monitoring | Watches for suspicious activity | SolarWinds, Splunk |
| Password Manager | Stores passwords securely | LastPass, 1Password |
Congratulations! You have completed Module 2 of the Certified Cyber Security Incident Handler (CCIH) course.
In this module, you learned:
Key takeaway: Preparation is the foundation of cyber security. The more you prepare, the better you can respond to any incident.
Because it stops many incidents before they happen, and makes response faster when they do happen.
It’s a written document that tells everyone what to do during a cyber incident.
Antivirus, firewall, backup software, monitoring tools, and password managers.
At least once a week. For very important files, you might back up every day.
Updates fix security holes (vulnerabilities) that hackers can use to break in.
It’s teaching people how to recognize cyber threats and what to do about them.
Run drills, send fake phishing emails, or do tabletop exercises where you practice your response.
A firewall is a system that blocks bad traffic from entering your network.
It’s writing down everything that happens during an incident so you can learn from it.
Yes! You can use strong passwords, update your devices, back up your files, and learn to spot phishing.
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. IR Plan | A. A copy of your important files |
| 2. Firewall | B. A written guide for incident response |
| 3. Backup | C. Fixes for security holes in software |
| 4. Patch | D. Blocks bad traffic from entering your network |
| 5. Documentation | E. Writing down what happens during an incident |
Scenario 1: You are the IT teacher at a school. The principal asks you to prepare the school for cyber incidents. What steps do you take?
Scenario 2: Your family has 4 computers and 3 phones. Your dad wants to make sure the family is prepared for cyber threats. What advice do you give him?
Scenario 3: A small business in Lagos has no cyber security plan. They just got hacked and lost customer data. What should they do now – and how could they have prevented it?
Activity: In groups of 4–5, create an Incident Response Plan for your school. Include:
Present your plan to the class.
Activity: Create a “Preparation Poster” for your home. List 5 things your family can do to prepare for cyber incidents. Draw pictures to illustrate each one.
Project: Create a “Cyber Security Preparation Kit” for your classroom. The kit should include:
Share your kit with another class.
Assignment: Interview an adult who works in IT or cyber security. Ask them:
Write a 1-page report about what you learned.
Challenge: Design a “Cyber Security Preparation Board Game” for younger students. The game should teach players about:
Players should move forward when they make good choices and move backward when they make mistakes.
In Module 3, we will learn about the second step of incident handling: IDENTIFICATION.
You will learn:
Before the next class: Think about a time you noticed something strange on a computer. What did you see? What did you do?
See you in Module 3, cyber hero! 🔍
Certified Cyber Security Incident Handler (CCIH) – Beginner Level
Hello, young cyber hero! In Module 2, we learned how to prepare for a cyber incident. We packed our bags, put on our armor, and got our weapons (like antivirus) ready.
But how do we know when to use our weapons? How do we know if an enemy is trying to break into our digital castle?
That’s what Identification is all about! Identification is like being a security guard or a detective. You watch carefully, you look for clues, and you figure out if something bad is happening.
In this module, we will learn:
By the end of this module, you will be a super-sleuth at spotting digital dangers! Let’s begin our detective work.
After studying this module, you will be able to:
|
Meet Chidi and his dad, Mr. Okonkwo. Chidi lives in Enugu, Nigeria. His dad runs a small provision store. One day, Mr. Okonkwo received a text message on his phone: “Your bank account has been compromised. Click here to secure your account: bit.ly/banksecure”. Mr. Okonkwo was worried and almost clicked the link. But Chidi remembered what he learned in his cyber security class. He looked closely at the message. Chidi identified the danger:
Chidi told his dad, “Don’t click, Dad! This is a phishing scam!” Mr. Okonkwo called his bank. The bank confirmed they never sent that message. Chidi had just identified a cyber threat and saved his family from losing money! |
Definition: Identification is the process of recognizing that a cyber security incident is happening (or has happened). It’s the moment you say, “Uh oh, something is wrong here!”
Why it's important: If you don’t know an incident is happening, you can’t stop it. It’s like a fire. If you don’t smell the smoke or see the flames, the fire will burn the whole house down.
Simple explanation: Identification is like being a detective. You look for clues (clues = signs of an attack). When you find enough clues, you know a crime has been committed.
Real-life example: A company’s network becomes very slow. The IT team investigates and finds a virus eating up the internet speed. They have identified a malware incident.
School example: A teacher sees a student’s account posting mean things that the student would never say. The teacher realizes the account might be hacked. That’s identification!
Home example: You notice your phone’s battery is draining very fast and your data is disappearing. You might have a malicious app. You identify the problem.
Nigerian example: A bank in Lagos sees a sudden spike in international transactions from small accounts. The fraud team identifies this as a potential money laundering scheme.
+---------------------------------------------+
| IDENTIFICATION = DETECTIVE WORK |
+---------------------------------------------+
| Step 1: Observe a strange event. |
| Step 2: Gather clues (data). |
| Step 3: Analyze the clues. |
| Step 4: Decide if it's a real attack. |
| Step 5: Report it to the team. |
+---------------------------------------------+
Mini Summary: Identification is how we discover that a cyber incident is occurring. It’s the first line of defense after preparing!
Definition: A symptom is a sign or clue that something might be wrong. In cyber security, symptoms are the things you see, hear, or feel that tell you an attack might be happening.
Why it's important: You can’t fix a problem if you don’t know it exists. Recognizing symptoms helps you act fast.
Simple explanation: If you have a fever, that’s a symptom of being sick. If your computer is running super slowly, that might be a symptom of a virus.
Common Symptoms:
School example: The computers in the library suddenly start playing music by themselves. That’s a weird symptom!
Home example: Your mom’s Facebook account posts links to strange websites. She didn’t do that. Symptom of a hack!
Nigerian example: A customer receives an SMS saying 500,000 Naira was withdrawn from their account, but they didn’t do it. That’s a symptom of bank fraud.
+---------------------------------------------+
| SYMPTOMS OF A CYBER ATTACK |
+---------------------------------------------+
| 🐢 Slow computer |
| 📢 Annoying pop-up ads |
| ❌ Files disappearing |
| 🔒 Can't log in |
| 💸 Money missing from account |
+---------------------------------------------+
Mini Summary: Symptoms are clues that tell us something is wrong. If you see any of these signs, it’s time to investigate!
Definition: To be a good detective, you need to know what crimes look like. There are many types of cyber incidents.
Why it's important: Different incidents have different symptoms. Knowing the types helps you identify them faster.
Common types:
Nigerian example: Many Nigerians receive SMS phishing messages pretending to be from DStv or GOtv asking for payment. Identifying these scams is crucial.
+---------------------------------------------+
| TYPES OF CYBER INCIDENTS |
+---------------------------------------------+
| 1. Malware - Bad software |
| 2. Phishing - Fake messages |
| 3. Insider - Bad people inside |
| 4. Ransomware- Files locked for money |
| 5. DDoS - Crashes the network |
+---------------------------------------------+
Mini Summary: Cyber incidents come in many shapes and sizes. Learning about them helps us spot them quickly.
Definition: We learned about antivirus and firewalls in Module 2. They don’t just prevent attacks; they also identify them by sending alerts.
Why it's important: These tools are like alarm systems. They watch your computer 24/7 and tell you immediately if they see something suspicious.
Simple explanation: Antivirus is like a guard dog. If a burglar (virus) tries to break in, the dog barks (antivirus sends an alert).
Example: Your antivirus pops up a message saying, “Threat detected: Trojan horse blocked.” That is identification!
Nigerian example: A Nigerian company uses Kaspersky antivirus. The software detects a ransomware attempt and alerts the IT team immediately.
+---------------------------------------------+
| ANTIVIRUS IDENTIFICATION |
+---------------------------------------------+
| Virus tries to enter. |
| | |
| V |
| Antivirus scans it. |
| | |
| V |
| Antivirus shouts: "DANGER!" |
| | |
| V |
| You know an incident is happening! |
+---------------------------------------------+
Mini Summary: Antivirus and firewalls are your automated security guards. They help you identify threats instantly.
Definition: An Intrusion Detection System (IDS) is a tool that monitors your network traffic and sends an alert if it finds something suspicious.
Why it's important: Antivirus protects one computer. An IDS protects the whole network (many computers). It’s like a CCTV camera for the entire school.
Simple explanation: An IDS is like a sniffer dog at the airport. It sniffs all the bags (data) coming in and out. If it smells drugs (malware), it barks (sends an alert).
Real-life example: A company installs an IDS. One day, the IDS alerts the IT team that a hacker is trying to scan their network for weak points. The IT team stops the hacker.
School example: The school network has an IDS. It detects a student trying to use a hacking tool and alerts the IT teacher.
Nigerian example: A Nigerian bank uses an IDS to monitor all transactions. The IDS flags multiple failed login attempts from an unknown IP address.
+---------------------------------------------+
| HOW AN IDS WORKS |
+---------------------------------------------+
| Internet ----> [ IDS ] ----> School Network |
| | |
| V |
| ALERT! |
| (Something is fishy!) |
+---------------------------------------------+
Mini Summary: An IDS watches the whole network and alerts you to suspicious activity. It’s a powerful identification tool.
Definition: An Intrusion Prevention System (IPS) is like an IDS, but it doesn't just alert you—it blocks the threat automatically.
Why it's important: Sometimes you can't wait for a human to respond. The IPS acts immediately to stop the attack.
Simple explanation: An IPS is like a automatic lock on a door. If someone tries to force the door open, it doesn't just make noise (IDS), it automatically locks itself tighter to keep the burglar out.
Comparison Table: IDS vs IPS
| Feature | IDS (Detection) | IPS (Prevention) |
|---|---|---|
| Action | Sends an alert. | Blocks the threat. |
| Speed | It is passive (waits for you to act). | It is active (acts immediately). |
| Analogy | A CCTV camera that records a burglary. | A security guard that tackles the burglar. |
Mini Summary: An IDS watches, and an IPS acts. Both are very useful for identifying and stopping incidents.
Definition: SIEM (pronounced "sim") is a tool that collects data from all your other tools (antivirus, firewalls, IDS) and puts it in one place. It’s like a central command center.
Why it's important: If you have 100 alarms going off, you don't know which one is important. SIEM collects all the alarms, analyzes them, and tells you which ones are real emergencies.
Simple explanation: SIEM is like the brain of the security team. It takes information from eyes (IDS), ears (antivirus), and nose (firewalls) to figure out what's really going on.
Nigerian example: Large Nigerian telecom companies like MTN or Airtel use SIEM to monitor millions of transactions and network events to identify fraud.
+---------------------------------------------+
| SIEM – THE CENTRAL BRAIN |
+---------------------------------------------+
| Antivirus --> |
| Firewall --> [ SIEM ] --> Shows the |
| IDS --> big picture |
| Logs --> |
+---------------------------------------------+
Mini Summary: SIEM is a tool that brings all your security alerts together to help you identify the most dangerous incidents.
Definition: A log is a file that records everything that happens on a computer or network. It’s like a diary that computers keep.
Why it's important: If an incident happens, logs help us figure out what happened, when it happened, and who might have done it.
Simple explanation: Imagine you want to know who ate the last cookie. If you have a diary (log) that records who entered the kitchen, you can find the cookie thief!
School example: The school server keeps logs of which students logged in at what time. If a student tries to cheat, the log will show it.
Home example: Your router keeps logs of which websites were visited. Your parents can check the logs to see if you went on any bad websites.
Nigerian example: A bank uses logs to track every single ATM withdrawal. If a card is cloned, the logs help the police trace the transaction.
+---------------------------------------------+
| LOG EXAMPLE |
+---------------------------------------------+
| Time: 10:15 AM |
| User: Chidi |
| Action: Logged into school system. |
| IP Address: 192.168.1.100 |
| Result: Success. |
+---------------------------------------------+
Mini Summary: Logs are the digital diaries that record everything. They are essential for identifying and investigating incidents.
Definition: Tools are great, but you are the most important identification tool! Your eyes, your brain, and your instincts are the best sensors.
Why it's important: Tools can miss things. If you see something weird, you can tell the security team. You are the eyes and ears on the ground.
Simple explanation: You are like Spider-Man's spider-sense. If you feel like something is wrong, it probably is!
Real-life example: An employee receives an email from the "CEO" asking for a list of all employee passwords. The employee thinks, "Why would the CEO ask for this?" and reports it. It was a hacker! The employee identified the incident.
School example: You see a friend trying to guess another friend's password. You identify this as suspicious behavior and tell a teacher.
Nigerian example: A bank customer gets a call from someone claiming to be the bank's IT. The customer feels suspicious, hangs up, and calls the bank directly. The bank confirms it was a scam. The customer's suspicion identified the scam.
+---------------------------------------------+
| YOU ARE THE FIRST LINE OF DEFENSE! |
+---------------------------------------------+
| 🕵️ See something? Say something! |
| 📧 Weird email? Don't click, report it! |
| 📱 Strange pop-up? Show it to an adult! |
+---------------------------------------------+
Mini Summary: Never underestimate your own intuition. If you see something suspicious, report it! You are a vital part of the identification process.
Definition: Sometimes an alarm goes off, but it’s a mistake. That’s a False Positive. When the alarm goes off and it’s a real attack, that’s a True Positive.
Why it's important: If you react to every false positive, you will get tired (alarm fatigue). But if you ignore a true positive, you’re in big trouble.
Simple explanation: False Positive = crying wolf. True Positive = the real wolf is actually there.
Real-life example: You burnt toast, and the fire alarm went off. That’s a false positive (no real fire). A real kitchen fire is a true positive.
School example: The school’s IDS blocks a website because it thinks it’s a "hacking site," but it’s actually a site for a school project. That’s a false positive.
Nigerian example: A bank's fraud detection system blocks a customer's transaction because they are traveling abroad and spending money there. The bank calls the customer to confirm. If it's actually the customer, it's a false positive. If it's a fraudster, it's a true positive.
| Term | Meaning | Analogy |
|---|---|---|
| True Positive | Alert goes off, and there IS a problem. | Fire alarm goes off, and there is a fire. |
| False Positive | Alert goes off, but there is NO problem. | Fire alarm goes off because of burnt toast. |
Mini Summary: Sometimes alarms are just mistakes (False Positives). But sometimes they are real (True Positives). We must investigate every alert to know for sure!
Definition: Reporting means telling the right people (your incident response team or parents/teachers) about the incident you identified.
Why it's important: You can’t handle a big incident all by yourself. You need help from experts.
Simple explanation: If you see a fire, you don't try to put out a huge fire with a glass of water. You call the firefighters (report the incident).
How to report:
Nigerian example: A staff member at a Nigerian company sees a ransomware message on their screen. They immediately unplug the network cable and call the IT Helpdesk.
+---------------------------------------------+
| HOW TO REPORT AN INCIDENT |
+---------------------------------------------+
| 1. Stay calm. |
| 2. Don't touch anything suspicious. |
| 3. Take a photo / screenshot. |
| 4. Call the incident response team. |
| 5. Tell them exactly what you saw. |
+---------------------------------------------+
Mini Summary: Reporting an incident quickly and clearly is essential. Don't try to fix it yourself. Call the experts!
Definition: Prioritization is deciding which incident is the most important to deal with first. This is sometimes called Triage (like in a hospital).
Why it's important: If you have many incidents, you need to fix the most dangerous one first. You don't treat a headache when someone is having a heart attack.
Simple explanation: If you have two broken toys, one is just missing a wheel, and the other is completely shattered. You fix the shattered one first. That’s prioritization.
Factors to consider:
School example: A student forgetting their password (low priority) vs. the school network being down (high priority). Fix the network first!
Nigerian example: A Nigerian e-commerce site like Konga gets a DDoS attack (high priority) and a few spam comments (low priority). They block the DDoS attack immediately.
+---------------------------------------------+
| PRIORITY SCALE (1 = HIGHEST) |
+---------------------------------------------+
| 1. Critical - System is down. |
| 2. High - Data is being stolen. |
| 3. Medium - Slow computer performance. |
| 4. Low - Password reset requests. |
+---------------------------------------------+
Mini Summary: Prioritization helps us focus on the biggest problems first. Not all incidents are equally dangerous.
Definition: A clear process to follow when you suspect an incident.
Steps:
+---------------------------------------------+
| IDENTIFICATION PROCESS FLOWCHART |
+---------------------------------------------+
| START |
| | |
| V |
| OBSERVE something strange. |
| | |
| V |
| GATHER DATA (screenshots, logs). |
| | |
| V |
| ANALYZE the data. |
| | |
| V |
| CONFIRM it's a real attack. |
| | |
| V |
| CLASSIFY the incident type. |
| | |
| V |
| REPORT to the incident team. |
| | |
| V |
| END (Team takes over). |
+---------------------------------------------+
Mini Summary: Follow these simple steps: Observe, Gather, Analyze, Confirm, Classify, Report.
| Word | Simple Definition |
|---|---|
| Identification | Finding out that a cyber incident is happening. |
| Symptom | A sign or clue that something is wrong. |
| Log | A file that records everything a computer does. |
| IDS (Intrusion Detection System) | A tool that sends an alert when it sees suspicious activity. |
| IPS (Intrusion Prevention System) | A tool that blocks suspicious activity automatically. |
| SIEM | A central system that collects alerts from all other tools. |
| False Positive | An alert that says there’s a problem, but there isn’t. |
| True Positive | An alert that correctly identifies a real problem. |
| Prioritization | Deciding which incident to deal with first. |
| Phishing | A scam where criminals try to trick you into giving them your passwords. |
|
+---------------------------------------------+
| IDENTIFICATION PROCESS |
+---------------------------------------------+
| |
| [ Something weird happens! ] |
| | |
| V |
| [ Gather Data (logs, screenshots) ] |
| | |
| V |
| [ Analyze the data ] |
| | |
| +--------+ |
| | |
| Is it real? |
| / \ |
| Yes No |
| | | |
| V V |
| [ Report ] [ Ignore ] |
| | |
| V |
| [ Incident Team takes over ] |
| |
+---------------------------------------------+
+---------------------------------------------+
| [ INTERNET ] |
| | |
| V |
| [ FIREWALL ] |
| | |
| V |
| [ INTRUSION DETECTION SYSTEM (IDS) ] |
| | |
| +---------+---------+ |
| | | |
| V V |
| [ ALERT! ] [ Normal Traffic ] |
| (Bad traffic) (Goes to computer) |
+---------------------------------------------+
| Feature | IDS | IPS |
|---|---|---|
| Action | Sends an alert. | Blocks the threat. |
| Placement | Outside the network (watching). | Inside the network (in-line). |
| Analogy | A CCTV camera. | A security guard. |
| Incident Type | Common Symptoms |
|---|---|
| Virus | Slow computer, pop-ups, files corrupting. |
| Phishing | Weird emails asking for passwords, bad grammar. |
| Hacking | Password changes, unauthorized transactions, weird social media posts. |
| Ransomware | Files have a strange extension, a note asking for Bitcoin. |
|
Congratulations! You have completed Module 3 of the CCIH course. In this module, you learned:
Key takeaway: Identifying an incident early is like finding a small leak before it floods the house. Stay vigilant, and trust your instincts! |
1. What is identification in cyber security?
It's the process of discovering that a cyber incident is happening. It's like a detective finding clues.
2. What are the most common symptoms of an attack?
Slow computer, strange pop-ups, missing files, and unauthorized transactions.
3. What is an IDS?
An Intrusion Detection System watches your network and sends an alert if it sees something suspicious.
4. What is the difference between IDS and IPS?
IDS only alerts you. IPS blocks the threat automatically.
5. What is a False Positive?
An alarm that goes off, but there is no real danger (like burnt toast setting off a fire alarm).
6. Why are logs important?
Logs are digital diaries. They help us understand what happened during an incident.
7. What should I do if I identify a potential incident?
Stay calm, don't touch anything suspicious, and report it to the incident response team or a parent/teacher.
8. Can a human identify a cyber incident?
Yes! Humans are often the best sensors because we can recognize unusual social engineering tricks.
9. What is a SIEM tool?
A SIEM is a central brain that collects alerts from many tools to give you a clear picture of the threats.
10. What does prioritization mean in identification?
It means deciding which incident to deal with first based on how dangerous it is.
| Answers: 1. Identification, 2. symptom, 3. IDS, 4. IPS, 5. False Positive, 6. Logs, 7. SIEM, 8. prioritization, 9. Phishing, 10. extension |
| Answers: 1. True, 2. True, 3. False, 4. False, 5. False, 6. False, 7. True, 8. True, 9. False, 10. True |
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. IDS | A. Blocks threats automatically |
| 2. IPS | B. A digital diary of computer activity |
| 3. SIEM | C. Sends alerts but doesn't block |
| 4. Logs | D. A central brain for security alerts |
| 5. Phishing | E. A scam to steal your password |
| Answers: 1-C, 2-A, 3-D, 4-B, 5-E |
Scenario 1: You are working in a bank's IT department. You see a SIEM alert showing a massive data transfer happening at 2:00 AM. What do you do?
Scenario 2: Your teacher receives an email that looks like it's from the school principal, asking for all students' home addresses. The email has a misspelled word. What should the teacher do?
Scenario 3: Your dad’s phone starts overheating and the battery drains in 30 minutes. He didn't install any new apps. What might be happening? How can he identify the problem?
Activity: "The Cyber Detective Agency"
Activity: "My Cyber Security Journal"
Project: Design a "Suspicious Email Detector" poster for your classroom.
Assignment: Interview someone in your family or neighborhood about a time they received a suspicious email or text message.
Challenge: "The IDS/IPS Debate"
Excellent work, detective! You have successfully learned how to identify the enemy. Now it's time to learn what to do when we find the enemy.
In Module 4, we will move on to the next step: Containment.
You will learn:
Before the next class: Think about a time you had to contain something (like a spill or a fire). How did you stop it from spreading? Now imagine doing that with a computer virus!
See you in Module 4, cyber hero! 🚀
🎉 End of Module 3 – CCIH 🎉
Stay sharp, stay safe!
Certified Cyber Security Incident Handler (CCIH) – Beginner Level
Hello, cyber hero! In Module 3, you became a master detective. You learned how to identify a cyber incident. You saw the smoke, you found the clues, and you knew an attack was happening.
But now what? If you just stand there and say, “Oh no, a virus!” and do nothing, the virus will keep spreading to other computers. That’s where Containment comes in.
Containment is like putting a fence around a fire to stop it from burning down the whole forest. It’s about isolating the problem so it can’t hurt anything else.
In this module, you will learn:
By the end of this module, you will be ready to act fast and stop cyber threats from spreading. Let’s jump in!
After studying this module, you will be able to:
|
Meet Mrs. Obi, the IT teacher at a school in Port Harcourt, Nigeria. One morning, a student, Amina, said her computer was acting strangely. Mrs. Obi checked and found a virus that was trying to send copies of itself to other computers on the school network. Mrs. Obi knew she had to contain the virus immediately. She did this:
Because Mrs. Obi acted fast, the virus was contained to just one computer. The rest of the school's computers stayed safe. Amina said, “Mrs. Obi, you saved our school!” Mrs. Obi smiled and said, “That's what containment is all about – stopping the spread before it's too late.” |
Definition: Containment is the step where we stop a cyber incident from spreading to other parts of the system. It’s like putting a sick person in isolation so they don’t infect others.
Why it's important: If you don’t contain an incident, it can grow like a wildfire. One infected computer can infect a hundred others in minutes.
Simple explanation: Containment is like putting a lid on a boiling pot. It doesn't fix the problem, but it stops the hot water from splashing everywhere.
Real-life example: A company finds a virus on a server. They immediately disconnect the server from the network so the virus can’t reach the other servers.
School example: A teacher sees a computer with a pop-up virus. She turns off the Wi‑Fi on that computer so it can’t send the virus to other students.
Home example: Your dad’s phone starts sending spam texts. He puts the phone on airplane mode to stop the spamming, then calls the phone company.
Nigerian example: A bank in Abuja notices that one ATM is dispensing extra cash. They shut down that ATM (isolate it) to prevent more losses, then investigate.
+---------------------------------------------+
| CONTAINMENT = STOP THE SPREAD |
+---------------------------------------------+
| Incident |
| | |
| V |
| Isolate the infected system |
| | |
| V |
| Block communication to others |
| | |
| V |
| Threat is now trapped! |
+---------------------------------------------+
Mini Summary: Containment is the act of isolating the incident to prevent it from affecting other systems.
Definition: The faster you contain an incident, the less damage it can do. Speed is the most important factor in containment.
Why it's important: Every second you delay, the attacker can move deeper into your network and steal more data.
Simple explanation: Think of a water leak in your house. If you turn off the main valve immediately, only a little water gets out. If you wait, your entire floor will be flooded.
Real-life example: A company detects a hacker inside their network. The IT team disconnects the affected computers within 5 minutes. The hacker only accessed a few files.
School example: A student clicks on a bad link and his computer starts downloading malware. The IT teacher pulls the plug within 30 seconds. No other computer is affected.
Home example: Your mom's email account is sending spam. She changes her password immediately. The hacker only used her account for a few minutes.
Nigerian example: A Nigerian company’s SIEM alert shows a ransomware attempt. The IT team isolates the server in 2 minutes. The ransomware never had time to encrypt files.
+---------------------------------------------+
| SPEED OF CONTAINMENT |
+---------------------------------------------+
| + Fast → Small damage |
| + Slow → Big damage |
| + Very slow → Catastrophe |
+---------------------------------------------+
Mini Summary: Act fast! The quicker you contain, the less you lose.
Definition: Short-term containment is the immediate action you take to stop the spread right away. Long-term containment is a more permanent solution while you prepare to eradicate the threat.
Why it's important: You need to act immediately (short-term) to stop the bleeding, and then you can plan a safer, more thorough containment (long-term) without rushing.
Simple explanation: Short-term is like putting a bandage on a cut to stop the bleeding. Long-term is like going to the doctor to get stitches.
Examples:
School example: Short-term: Turn off the infected computer. Long-term: Rebuild the computer with a clean operating system.
Nigerian example: Short-term: A bank blocks a suspicious ATM card immediately. Long-term: They update the ATM software to prevent the exploit.
| Short-Term | Long-Term |
|---|---|
| Isolate the affected system. | Change all passwords. |
| Block malicious IP addresses. | Patch vulnerabilities. |
| Disable user accounts. | Reinstall operating systems. |
Mini Summary: Short-term containment is your immediate response to stop the spread. Long-term containment is a more permanent fix.
Definition: When you find a virus or malware on one computer, you need to isolate it to protect the rest of the network.
Steps:
School example: A teacher sees a computer with a ransomware message. She unplugs the Ethernet cable, disables the Wi‑Fi adapter, and puts a sticky note on the monitor: "DO NOT USE – VIRUS."
Home example: Your dad's laptop gets a virus. He turns off the Wi‑Fi and connects a backup hard drive to copy essential files later.
Nigerian example: A staff member at a Nigerian firm receives a phishing email and clicks the link. The IT team remotely disables that user's network access immediately.
+---------------------------------------------+
| CONTAINING A SINGLE COMPUTER |
+---------------------------------------------+
| Step 1: Pull the network plug. |
| Step 2: Turn off Wi-Fi. |
| Step 3: Disable Bluetooth. |
| Step 4: Leave it running. |
| Step 5: Label it as infected. |
+---------------------------------------------+
Mini Summary: To contain one computer, cut its connections to the outside world.
Definition: Sometimes the incident is spreading across the network. You may need to isolate entire segments (like a whole department) to stop the spread.
Why it's important: If a virus is moving from computer to computer, isolating one machine isn't enough. You must block the traffic between groups.
Simple explanation: Imagine a school with classrooms. If a fire is in Room 1, you close the door to Room 1. But if the fire is in the hallway, you close all classroom doors to keep it out.
How to do it:
School example: The school’s computer lab is infected. The IT teacher uses the network switch to isolate the entire lab from the rest of the school.
Nigerian example: A Nigerian company has a branch office in Kano and headquarters in Lagos. If the Kano office gets a virus, they block all traffic between Lagos and Kano to protect the headquarters.
+---------------------------------------------+
| ISOLATING NETWORK SEGMENTS |
+---------------------------------------------+
| Infected Segment ----X---- Clean Network |
| | |
| V |
| Firewall rule: BLOCK all traffic |
| between these segments! |
+---------------------------------------------+
Mini Summary: For larger infections, you need to separate whole network sections to prevent the spread.
Definition: Malicious traffic includes communications from the attacker or from infected machines trying to connect to command-and-control (C2) servers.
Why it's important: Many malware programs need to "phone home" to receive instructions from the attacker. If you block that traffic, the malware becomes useless.
Simple explanation: Imagine a spy who needs to call his boss to get orders. If you block his phone, he can't do anything.
How to block:
School example: The school’s firewall blocks all traffic to known phishing domains. This prevents students from accidentally visiting those sites.
Nigerian example: A Nigerian bank blocks traffic to IP addresses known for hosting banking trojans, thus protecting their internal network.
+---------------------------------------------+
| BLOCKING MALICIOUS TRAFFIC |
+---------------------------------------------+
| Infected PC ----> C2 Server |
| | |
| V |
| Firewall blocks the connection! |
| C2 Server can't reach the PC. |
+---------------------------------------------+
Mini Summary: Blocking malicious traffic cuts the attacker's control over infected machines.
Definition: A firewall is a network security device that monitors and controls incoming and outgoing traffic. It's a powerful tool for containment.
Why it's important: Firewalls can act as a digital gatekeeper. You can tell the firewall to block certain IP addresses, ports, or applications instantly.
Simple explanation: A firewall is like a security checkpoint at a border. It decides who and what can cross the border into your network.
Example: You notice an attacker's IP address. You add a rule to the firewall to block that IP. All traffic from that IP is dropped.
School example: The school firewall blocks access to social media during class hours. This is a form of containment – preventing distractions.
Nigerian example: A Nigerian university uses a firewall to block P2P file-sharing applications to prevent malware downloads.
+---------------------------------------------+
| FIREWALL CONTAINMENT RULE |
+---------------------------------------------+
| IF traffic comes from 8.8.8.8 (attacker) |
| THEN DROP the packet. |
| ELSE ALLOW. |
+---------------------------------------------+
Mini Summary: Firewalls are your first line of defense for containment. You can block specific threats quickly.
Definition: If you suspect an attacker is using a specific user account (like a staff member’s account), you can disable that account immediately.
Why it's important: If the attacker is using that account to log in remotely, disabling it cuts off their access instantly.
Simple explanation: If you think a thief has a key to your house, you change the locks (disable the account).
How to do it: In a school or company, the IT team can disable the account in the Active Directory or any user management system.
Example: A company’s SIEM shows that a user account is logging in at 3 AM from a foreign country. The IT team disables the account immediately.
Nigerian example: A bank notices that a staff account is being used to approve large transactions without authorization. They disable the account and investigate.
+---------------------------------------------+
| DISABLE USER ACCOUNT |
+---------------------------------------------+
| Account: Chidi.Okoro |
| Action: Disable |
| Reason: Suspicious activity detected. |
| Account is now locked. |
+---------------------------------------------+
Mini Summary: Disabling suspicious accounts prevents unauthorized access.
Definition: Many schools and companies use cloud services like Google Drive, Office 365, or AWS. Containment in the cloud involves restricting access to those services.
Why it's important: If an attacker gets into your cloud account, they can steal or delete all your data. You need to contain it quickly.
Simple explanation: The cloud is like a storage unit you rent. If you think someone has broken into your unit, you tell the security guards to lock it down.
Actions:
School example: The school uses Google Workspace. They notice a student's account sending spam. The IT admin suspends that account.
Nigerian example: A Nigerian startup uses AWS. They detect an unusual increase in compute usage. They isolate the affected virtual machine by removing its security group rules.
+---------------------------------------------+
| CLOUD CONTAINMENT STEPS |
+---------------------------------------------+
| 1. Change password. |
| 2. Revoke all sessions. |
| 3. Enable MFA. |
| 4. Block IP in security group. |
+---------------------------------------------+
Mini Summary: Cloud incidents need fast containment by changing passwords and restricting access.
Definition: Escalation means calling in more help when you cannot contain the incident on your own.
Why it's important: Sometimes the incident is too big or complex for you. You need experts (like the incident response team, law enforcement, or external consultants).
Simple explanation: If you try to carry a heavy box and it’s too heavy, you ask for help. That’s escalation.
When to escalate:
School example: A teacher finds a virus but the IT teacher is not available. She calls the school’s IT support company (escalation).
Nigerian example: A Nigerian bank suffers a large-scale DDoS attack. The internal team escalates to the Central Bank of Nigeria's cyber security unit for assistance.
+---------------------------------------------+
| ESCALATION PROCESS |
+---------------------------------------------+
| Incident identified. |
| | |
| V |
| Try to contain. |
| | |
| +--- Can you handle it? ---+ |
| / \ |
| Yes No |
| | | |
| V V |
| Continue Call for help |
+---------------------------------------------+
Mini Summary: If you're overwhelmed, escalate immediately. Don't try to do everything yourself.
Definition: Documentation means writing down every action you take during containment. It’s like keeping a logbook.
Why it's important: Later, you'll need to know what you did, when you did it, and what the results were. This helps with recovery and prevention.
Simple explanation: If you're cooking a new recipe, you write down the ingredients and steps so you can make it again or tell someone else.
What to record:
School example: The IT teacher writes: "10:15 AM – Disconnected PC #12 from network. 10:20 AM – Virus not spreading."
Nigerian example: A bank's IT team records all containment steps for audit and regulatory compliance.
+---------------------------------------------+
| DOCUMENTATION EXAMPLE |
+---------------------------------------------+
| Date: 2025-10-20 |
| Time: 09:00 AM |
| Incident: Virus on Server A |
| Action: Isolated Server A by unplugging |
| Result: No other servers affected |
| Escalated: Yes, called incident team |
+---------------------------------------------+
Mini Summary: Write everything down. Good documentation helps everyone.
Definition: Not all incidents are the same. You might need different containment methods depending on the type of attack.
Why it's important: Using the wrong containment could make things worse. For example, turning off a computer could destroy evidence.
Examples:
School example: A phishing email is reported. The IT team blocks the sender's email domain and sends a warning to all staff.
Nigerian example: A Nigerian telecom provider experiences a DDoS attack. They use a third-party DDoS protection service to absorb the traffic.
+---------------------------------------------+
| INCIDENT TYPE | CONTAINMENT METHOD |
+---------------------------------------------+
| Virus | Isolate the computer |
| Phishing | Block domain |
| Ransomware | Disconnect network |
| Insider | Disable account |
| DDoS | Route traffic away |
+---------------------------------------------+
Mini Summary: Use the right containment method for the right incident type.
| Word | Simple Definition |
|---|---|
| Containment | Stopping the spread of a cyber incident. |
| Short-term Containment | Immediate actions to stop the spread. |
| Long-term Containment | More permanent isolation measures. |
| Isolation | Separating an infected system from the network. |
| Firewall | A device that blocks unwanted traffic. |
| Blacklist | A list of blocked IPs or domains. |
| C2 (Command and Control) | A server that controls malware. |
| DNS Sinkhole | A fake DNS that blocks malicious domains. |
| Escalation | Calling for more help. |
| Documentation | Writing down actions taken. |
+---------------------------------------------+
| RANSOMWARE CONTAINMENT STEPS |
+---------------------------------------------+
| 1. Isolate the infected machine. |
| 2. Block remote access. |
| 3. Check other computers. |
| 4. Block C2 domains. |
| 5. Disconnect network shares. |
| 6. Log everything. |
| 7. Call for help. |
+---------------------------------------------+
|
+---------------------------------------------+
| CONTAINMENT PROCESS |
+---------------------------------------------+
| Incident Detected |
| | |
| V |
| Isolate affected system(s) |
| | |
| V |
| Block malicious traffic |
| | |
| V |
| Disable accounts if needed |
| | |
| V |
| Escalate if necessary |
| | |
| V |
| Document all actions |
| | |
| V |
| Hand over to Eradication phase |
+---------------------------------------------+
+---------------------------------------------+
| BEFORE CONTAINMENT |
| [PC1]---[PC2]---[PC3]---[Server] |
| \\ // // |
| Spread |
| |
| AFTER CONTAINMENT |
| [PC1]-X-[PC2]---[PC3]---[Server] |
| | |
| X (blocked) |
| PC2 is isolated; traffic blocked. |
+---------------------------------------------+
| Rule | Source | Destination | Action |
|---|---|---|---|
| Block C2 | Internal | 185.156.46.100 | Drop |
| Block Phishing | Any | phishingsite.com | Drop |
| Short-Term | Long-Term |
|---|---|
| Unplug network cable | Change all network configurations |
| Disable user account | Implement role-based access controls |
| Block IP address on firewall | Update IPS signatures to block attack patterns |
| Turn off Wi-Fi | Reinstall OS and apply latest patches |
| Incident Type | Containment Method |
|---|---|
| Virus/Malware | Isolate infected hosts |
| Phishing | Block sender domain/email |
| Ransomware | Isolate, block C2, disconnect shares |
| Insider Threat | Disable account, revoke access |
| DDoS | Traffic diversion, blackhole routing |
| Data Breach | Block external connections, revoke credentials |
|
Congratulations! You have completed Module 4 of the CCIH course. In this module, you learned:
Key takeaway: Containment is like putting a fence around a fire. It doesn't put out the fire, but it stops it from burning everything down. |
1. What is the goal of containment?
To stop the incident from spreading to other systems.
2. What is the first thing to do when containing a single computer?
Disconnect it from the network (unplug cable or turn off Wi-Fi).
3. Should I turn off an infected computer immediately?
Not usually. First, isolate it; then consult the incident response team before turning it off.
4. What is the difference between short-term and long-term containment?
Short-term is immediate; long-term is more permanent.
5. How can a firewall help with containment?
It can block malicious IP addresses, domains, or traffic patterns.
6. What is a DNS sinkhole?
A fake DNS server that blocks connections to malicious domains.
7. Why is documentation important during containment?
It helps you remember what you did and assists in later investigation and recovery.
8. When should I escalate?
When you are overwhelmed, don't know what to do, or when the incident is too big.
9. Can I contain a cloud-based incident?
Yes, by changing passwords, revoking sessions, and blocking IPs in cloud firewalls.
10. What is the biggest mistake in containment?
Acting too slowly or forgetting to document actions.
| Answers: 1. Containment, 2. Short-term, long-term, 3. unplug/disconnect, 4. firewall, 5. DNS sinkhole, 6. escalate, 7. document, 8. isolating, 9. disable, 10. identification |
| Answers: 1. False, 2. False, 3. False, 4. True, 5. False, 6. False, 7. True, 8. True, 9. False (it blocks domains), 10. False (after identification) |
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. Containment | A. Immediate action to stop spread |
| 2. Short-term containment | B. More permanent isolation measures |
| 3. Long-term containment | C. Stopping an incident from spreading |
| 4. DNS sinkhole | D. Fake DNS to block malicious domains |
| 5. Escalation | E. Calling for more help |
| Answers: 1-C, 2-A, 3-B, 4-D, 5-E |
Scenario 1: You are the IT teacher at a school. A student reports that their computer is showing a message: "Your files are encrypted. Pay $500 to recover them." What are your containment steps?
Scenario 2: You work at a bank's IT department. The SIEM alerts you that a user account is accessing the system from a foreign country at 2:00 AM. The account belongs to a staff member who is currently on leave. What do you do to contain this?
Scenario 3: Your family's home Wi‑Fi network becomes very slow, and you notice many unknown devices connected. How do you contain this situation?
Activity: "Containment Drill"
Activity: "My Containment Plan"
Project: Design a "Containment Poster" for your school.
Assignment: Interview a family member or neighbor who works in an office.
Challenge: "Containment Time Trial"
Great work! You've successfully contained the threat. The virus is now trapped in a box, unable to spread. But it's still inside the box! You haven't killed it yet.
In Module 5, we will learn about Eradication – the step where we remove the cause of the incident completely.
You will learn:
Before the next class: Think about a time you had to remove something bad (like a splinter or a virus on your phone). How did you get rid of it?
See you in Module 5, cyber hero! 🧹
🎉 End of Module 4 – CCIH 🎉
Contain the fire, save the forest!
Certified Cyber Security Incident Handler (CCIH) – Beginner Level
Hello, cyber hero! In Module 4, you learned how to contain a cyber incident. You put the virus in a box, stopped it from spreading, and trapped the attacker. But the virus is still inside the box! It's like catching a mouse in a trap – you've stopped it, but you still need to get rid of it.
That's where Eradication comes in. Eradication means completely removing the cause of the incident. You must clean out the virus, fix the weak spots, and make sure the attacker can never come back the same way again.
In this module, you will learn:
By the end of this module, you'll know how to give your digital home a deep clean and make sure the bad guys are gone for good.
After studying this module, you will be able to:
|
Meet Alhaji Bello, who runs a busy electronics market in Kano, Nigeria. One day, his main computer got a virus that corrupted all his sales records. His IT person, Fatima, isolated the computer (containment) to stop the virus from spreading to the other computers in the shop. But the virus was still on that computer. Fatima knew she had to eradicate it completely. She did this:
Alhaji Bello's computer was clean again, and he learned to keep his software updated. Fatima said, “Eradication is like sweeping the house after you've caught the mouse – you must clean up all the droppings to stay safe.” |
Definition: Eradication is the process of completely removing the cause of a cyber incident from the affected systems. It's about cleaning up the mess so that the threat is gone for good.
Why it's important: If you don't eradicate, the threat can remain dormant and come back later. It's like leaving a bug in your house – it will breed and cause problems again.
Simple explanation: Eradication is like deep cleaning your room. You don't just hide the mess under the bed; you throw out the garbage and scrub the floor.
Real-life example: After a virus attack, the IT team deletes the infected files, runs a malware cleaner, and patches the vulnerability that allowed the virus in.
School example: A computer in the school lab gets a pop-up virus. The IT teacher runs an antivirus scan, removes the virus, and installs an update to prevent it from coming back.
Home example: Your dad's laptop gets spyware. He uninstalls the malicious program and changes all his passwords.
Nigerian example: A bank discovers a Trojan that steals customer data. They run a full cleanup on all affected servers, delete the Trojan, and install the latest security patches.
+---------------------------------------------+
| ERADICATION = DEEP CLEAN |
+---------------------------------------------+
| Step 1: Remove the bad stuff. |
| Step 2: Fix the weak spots. |
| Step 3: Change keys (passwords). |
| Step 4: Verify it's gone. |
+---------------------------------------------+
Mini Summary: Eradication is the thorough removal of the threat and its causes.
Definition: Eradication is the step that ensures the incident won't happen again. It's not enough to just stop the spread; you must kill the root cause.
Why it's important: Hackers are persistent. If you leave a door open, they will come back. Eradication closes that door.
Simple explanation: Imagine you had a leaky pipe. You put a bucket under it (containment), but you still need to fix the pipe (eradication) or it will leak again.
Real-life example: A company was hit by ransomware. They paid the ransom, but the attacker still had a backdoor. They later got hit again. Only after removing the backdoor (eradication) were they safe.
School example: A student's account was hacked. The school reset the password (containment) but didn't remove a malicious script that was emailing spam. The account was hacked again. Eradication would have removed the script.
Nigerian example: A small business in Abuja was hit by phishing. They changed passwords, but didn't remove a forwarding rule that the hacker had set up. The hacker continued to read emails. Eradication included removing that rule.
+---------------------------------------------+
| CONTAINMENT VS ERADICATION |
+---------------------------------------------+
| Containment: Stop the bleeding. |
| Eradication: Heal the wound. |
+---------------------------------------------+
Mini Summary: Eradication is necessary to prevent recurrence. It addresses the root cause.
Definition: Antivirus (or anti-malware) is software that detects and removes malicious programs from your computer.
Why it's important: Antivirus is your first tool for eradication. It can automatically find and delete many types of malware.
Simple explanation: Antivirus is like a vaccuum cleaner that sucks up bad files from your computer.
How to use it:
School example: The IT teacher runs a full scan on all lab computers at the end of each term to clean them.
Nigerian example: A Nigerian company uses Kaspersky. When a virus is detected, they run a scan, delete the infected files, and then run another scan to be sure.
+---------------------------------------------+
| ANTIVIRUS SCAN PROCESS |
+---------------------------------------------+
| Step 1: Update antivirus. |
| Step 2: Run Full Scan. |
| Step 3: Remove/Quarantine threats. |
| Step 4: Run Second Scan to verify. |
+---------------------------------------------+
Mini Summary: Antivirus is a primary tool for eradicating malware; always keep it updated.
Definition: Sometimes antivirus can't catch everything. You might need to manually find and delete malware using system tools.
Why it's important: Advanced malware can hide from antivirus. Manual removal helps when the tools miss something.
Simple explanation: Manual removal is like searching for a hidden toy in your room. You look in all the corners.
How to do it:
Warning: Manual removal is risky. Only do it if you are trained, or call an expert.
School example: A student's computer has a stubborn browser hijacker. The IT teacher manually removes the suspicious extension and resets the browser.
Nigerian example: A Nigerian university’s IT team finds a custom backdoor that antivirus missed. They manually locate and delete the file and remove its registry entries.
+---------------------------------------------+
| MANUAL MALWARE REMOVAL (ADVANCED) |
+---------------------------------------------+
| 1. Check Task Manager for unknown apps. |
| 2. Look at startup programs. |
| 3. Search suspicious files. |
| 4. Use specialized removal tools. |
| 5. Be careful – ask for help if unsure! |
+---------------------------------------------+
Mini Summary: Manual removal is a backup when antivirus fails, but it requires caution.
Definition: Patching means applying updates from software vendors to fix security holes (vulnerabilities) that attackers used to break in.
Why it's important: Even if you remove the malware, the vulnerability still exists. The attacker can use it again. Patching closes that door.
Simple explanation: Patches are like fixing a broken window. If you just clean up the glass but don't fix the window, the thief can come back.
How to patch:
School example: The school's server had a vulnerability that allowed a hacker in. The IT team installed the latest security updates to patch it.
Nigerian example: A Nigerian bank patches its online banking app regularly to fix security bugs discovered by researchers.
+---------------------------------------------+
| PATCHING PROCESS |
+---------------------------------------------+
| Vulnerability detected. |
| | |
| V |
| Vendor releases a patch. |
| | |
| V |
| IT team applies the patch. |
| | |
| V |
| Vulnerability is closed! |
+---------------------------------------------+
Mini Summary: Patching fixes the weak spots that allowed the attack in the first place.
Definition: Sometimes the infection is so deep that the only safe option is to rebuild the system – that is, erase everything and reinstall the operating system and applications from a trusted source.
Why it's important: Some malware hides deeply in the system (rootkits) and cannot be removed cleanly. Rebuilding ensures a fresh start.
Simple explanation: Rebuilding is like throwing away a broken toy and buying a new one. You can't fix the broken one, so you start fresh.
When to rebuild:
Steps:
School example: A computer in the lab got a boot virus that couldn't be removed. The IT teacher reformatted the hard drive and reinstalled Windows.
Nigerian example: A Nigerian company's server was compromised with a rootkit. They backed up essential data, wiped the server, and reinstalled from scratch.
+---------------------------------------------+
| REBUILDING A SYSTEM |
+---------------------------------------------+
| 1. Back up clean data. |
| 2. Wipe the hard drive. |
| 3. Reinstall OS. |
| 4. Install apps and patches. |
| 5. Restore data from backup. |
+---------------------------------------------+
Mini Summary: Rebuilding is the ultimate eradication when cleaning isn't enough.
Definition: After an incident, you should change all passwords that might have been compromised. This includes user passwords, admin passwords, and any application passwords.
Why it's important: Even if you remove the malware, the attacker might have stolen passwords. If you don't change them, the attacker can still log in later.
Simple explanation: It's like if someone copied your house key – you must change the locks.
What to change:
School example: After a student's account was hacked, the school reset all student passwords and forced them to create new ones.
Nigerian example: A bank experienced a phishing attack on some customers. They reset all affected customers' online banking passwords.
+---------------------------------------------+
| PASSWORD CHANGE CHECKLIST |
+---------------------------------------------+
| ☐ User passwords |
| ☐ Admin passwords |
| ☐ Service accounts |
| ☐ Wi‑Fi and VPN keys |
| ☐ API tokens |
+---------------------------------------------+
Mini Summary: Always change passwords after an incident to lock out the attacker.
Definition: After cleaning the main infected system, you must scan all other systems on the network to ensure they are not also infected.
Why it's important: The attacker may have moved laterally (jumped to other computers) before you contained them. Scanning reveals hidden infections.
Simple explanation: If you find a mouse in one room, you check all the other rooms too.
How to do it:
School example: The IT team found a virus on one teacher's computer. They then scanned all other staff computers and found two more with the same virus.
Nigerian example: A Nigerian company discovered a hacker on one server. They scanned all other servers and found the hacker had planted backdoors on three more.
+---------------------------------------------+
| SCAN ALL SYSTEMS |
+---------------------------------------------+
| After cleaning the main infected box, |
| run scans on every device in the network.|
| If you find more, repeat eradication. |
+---------------------------------------------+
Mini Summary: Don't assume only one system was hit. Scan everything.
Definition: Verification is the process of confirming that the threat is truly gone and the system is safe.
Why it's important: You don't want to declare victory too early. Verification gives you confidence that eradication was successful.
Simple explanation: Verification is like checking twice that you turned off the stove. You want to be sure.
How to verify:
School example: After cleaning a computer, the teacher runs a second scan and checks the system performance to ensure it's back to normal.
Nigerian example: A Nigerian bank's IT team, after eradicating a Trojan, runs a vulnerability scanner to confirm all patches are applied and the Trojan is gone.
+---------------------------------------------+
| VERIFICATION STEPS |
+---------------------------------------------+
| 1. Re-scan with antivirus. |
| 2. Check logs. |
| 3. Use specialized tools. |
| 4. Monitor network for anomalies. |
| 5. Test system functions. |
+---------------------------------------------+
Mini Summary: Always verify that eradication worked. Trust but verify.
Definition: Many organizations use cloud services (AWS, Azure, Google Cloud). Eradication in the cloud means cleaning up virtual machines, storage, and services.
Why it's important: Cloud systems are still vulnerable. You must clean them too.
Actions:
School example: The school uses Google Workspace. After a student's account was hacked, they removed the malicious script and reset the student's password.
Nigerian example: A Nigerian startup uses AWS. They discovered a crypto-miner running on an EC2 instance. They terminated the instance and launched a new one from a secure AMI.
+---------------------------------------------+
| CLOUD ERADICATION STEPS |
+---------------------------------------------+
| 1. Stop compromised instances. |
| 2. Terminate and rebuild from clean image.|
| 3. Rotate all keys and passwords. |
| 4. Review permissions and security groups.|
| 5. Scan cloud storage for threats. |
+---------------------------------------------+
Mini Summary: Cloud incidents require similar eradication steps, often involving rebuilding instances.
Definition: You must document every eradication action you take, similar to containment.
Why it's important: Documentation helps in future investigations, shows compliance, and helps your team learn.
What to record:
School example: The IT teacher writes: "2025-10-25: Removed Trojan from PC#12; applied Windows update KB5012345; changed student passwords."
Nigerian example: A Nigerian bank's incident report includes a full section on eradication steps taken and verification results.
+---------------------------------------------+
| ERADICATION DOCUMENTATION EXAMPLE |
+---------------------------------------------+
| Incident: Ransomware on Server B |
| Eradication steps: |
| - Deleted encrypted files. |
| - Ran Malwarebytes scan, removed trojan. |
| - Applied patch for SMB vulnerability. |
| - Rebuilt server from backup. |
| - Changed all admin passwords. |
| - Verified with second scan – clean. |
+---------------------------------------------+
Mini Summary: Write everything down for accountability and learning.
| Word | Simple Definition |
|---|---|
| Eradication | Completely removing the cause of the incident. |
| Patch | A software update that fixes a security hole. |
| Rebuild | Erasing and reinstalling a system from scratch. |
| Verification | Confirming that the threat is gone. |
| Rootkit | Malware that hides deep in the system. |
| Bootkit | Malware that infects the boot process. |
| Backdoor | A hidden way for attackers to re-enter. |
| Quarantine | Isolating a file so it can't run (a step before deletion). |
| Vulnerability | A weakness that can be exploited. |
| Credentials | Usernames and passwords. |
+---------------------------------------------+
| ERADICATION STEPS |
+---------------------------------------------+
| 1. Identify affected systems. |
| 2. Remove malware. |
| 3. Patch vulnerabilities. |
| 4. Rebuild if needed. |
| 5. Change passwords. |
| 6. Scan other systems. |
| 7. Verify. |
| 8. Document. |
+---------------------------------------------+
|
+---------------------------------------------+
| ERADICATION FLOWCHART |
+---------------------------------------------+
| START |
| | |
| V |
| Identify affected systems. |
| | |
| V |
| Remove malware using antivirus/tools. |
| | |
| V |
| Apply patches to vulnerabilities. |
| | |
| V |
| Rebuild if necessary (yes/no). |
| | |
| +--(Yes)--> Wipe and reinstall. |
| | |
| V |
| Change all passwords. |
| | |
| V |
| Scan all other systems. |
| | |
| V |
| Verify cleanliness. |
| | |
| +--(Not clean)--> Go back to removal. |
| | |
| V |
| Document everything. |
| | |
| V |
| END (hand over to Recovery). |
+---------------------------------------------+
+---------------------------------------------+
| PATCHING VULNERABILITIES |
+---------------------------------------------+
| Vendor releases update. |
| | |
| V |
| IT team tests patch in lab. |
| | |
| V |
| Deploy patch to production. |
| | |
| V |
| Verify patch applied. |
| | |
| V |
| Vulnerability is closed. |
+---------------------------------------------+
| Clean | Rebuild |
|---|---|
| Remove malware only. | Erase everything and reinstall. |
| Faster. | Slower but safer. |
| Risk of leaving behind hidden malware. | Guaranteed clean (if using trusted media). |
| Good for simple infections. | Good for rootkits or complex infections. |
| Incident Type | Eradication Method |
|---|---|
| Virus | Run antivirus, delete infected files. |
| Phishing (account compromise) | Change password, revoke sessions, remove forwarding rules. |
| Ransomware | Restore from clean backup, rebuild if no backup. |
| Insider Threat | Revoke access, disable accounts, change all credentials. |
| DDoS (no malware) | No eradication needed; focus on mitigation. |
|
Congratulations! You have completed Module 5 of the CCIH course. In this module, you learned:
Key takeaway: Eradication is the deep clean that ensures the cyber threat is gone for good. It closes the door on attackers and prevents future incidents. |
1. What is the difference between eradication and containment?
Containment stops the spread; eradication removes the cause completely.
2. How do I know if a system is clean after eradication?
Run multiple antivirus scans, check logs, and use verification tools.
3. When should I rebuild instead of clean?
When the infection is a rootkit, or when you can't be sure you removed everything.
4. Why is patching important in eradication?
Because patches fix the vulnerability that allowed the attack in the first place.
5. Should I change passwords after every incident?
Yes, always change any passwords that might have been compromised.
6. Do I need to scan other computers?
Absolutely, the infection might have spread laterally.
7. What is a backdoor?
A hidden way for attackers to re-enter your system after you think it's clean.
8. Can I use multiple antivirus products?
Yes, but run them one at a time to avoid conflicts.
9. What is verification in eradication?
Confirming that the threat is truly gone, through scans and checks.
10. Why document eradication steps?
For future reference, compliance, and to improve your incident response process.
| Answers: 1. Eradication, 2. Patches, 3. rebuild, 4. change, 5. scan, 6. Verification, 7. backdoor, 8. rootkit, 9. Eradication, 10. document |
| Answers: 1. False, 2. True, 3. False, 4. False, 5. False, 6. False, 7. True, 8. False, 9. False (it's a hidden entry point, not a vulnerability), 10. False |
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. Patch | A. Removing malware entirely |
| 2. Rebuild | B. A hidden way for attackers to return |
| 3. Rootkit | C. A fix for a vulnerability |
| 4. Backdoor | D. Wiping and reinstalling a system |
| 5. Verification | E. Confirming the threat is gone |
| Answers: 1-C, 2-D, 3-A (rootkit is malware that hides deep, but for matching we have to assign correctly; I'll adjust: actually 3 is not in list, let's fix. I'll remake: 1-Patch -> C, 2-Rebuild -> D, 3-Rootkit -> A (malware that hides deep), 4-Backdoor -> B, 5-Verification -> E. |
Scenario 1: A small school has 50 computers. One computer gets infected with a virus that spreads through USB drives. The IT teacher contains the virus by disconnecting the infected machine. Now, they need to eradicate it. What steps should they take?
Scenario 2: A Nigerian e-commerce company discovers that a hacker inserted a backdoor into their web server. The server holds customer data. They have isolated the server. How should they eradicate the backdoor?
Scenario 3: Your family's home computer is infected with spyware that logs keystrokes. You've disconnected it from the internet. Now you need to eradicate it. What specific actions would you take?
Activity: "Eradication Team Challenge"
Activity: "My Eradication Checklist"
Project: "Design an Eradication Poster"
Assignment: Interview an IT professional or someone who has experienced a cyber incident.
Challenge: "The Persistent Malware"
Excellent work! You have now thoroughly cleaned the digital house. The threat is gone, the vulnerabilities are patched, and the system is safe.
In Module 6, we will learn about the final step: Recovery.
You will learn:
Before the next class: Think about a time you had to recover something you lost (like a lost file or a toy). How did you get it back?
See you in Module 6, cyber hero! 🔄
🎉 End of Module 5 – CCIH 🎉
Clean up, patch up, stay safe!
Certified Cyber Security Incident Handler (CCIH) – Beginner Level
Hello, cyber hero! You have done an amazing job so far. You have identified the threat, contained it, and eradicated it. The digital bad guys are gone, the house is clean, and all the doors are locked.
But wait – your digital home is still a mess! The files you removed, the systems you rebuilt, the changes you made – everything needs to be put back together so you can use your computer again. That's where Recovery comes in.
Recovery is the final step in incident handling. It means restoring your systems and data to normal operation, while making sure everything is safe and secure.
In this module, you will learn:
By the end of this module, you will know how to bring your digital world back to life and be even stronger than before.
After studying this module, you will be able to:
|
Meet Mrs. Okafor, who runs a popular bakery in Enugu, Nigeria. Her business depended on a computer system that kept track of orders, recipes, and customer payments. One day, a ransomware attack locked all her files. Her IT team contained the attack, eradicated the ransomware, and patched the vulnerability. Now they had to recover. They did this:
Mrs. Okafor was relieved. Her bakery was back in business, even stronger than before. She said, “Recovery is like baking a new batch of bread – you follow the recipe, you check the oven, and you make sure it's perfect before serving.” |
Definition: Recovery is the process of restoring systems and data to normal operation after an incident, while ensuring they are safe and secure.
Why it's important: Without recovery, you can't use your computers again. Recovery brings your digital life back and helps you learn from the incident.
Simple explanation: Recovery is like reorganizing your room after it's been cleaned. You put everything back in its place so you can live normally again.
Real-life example: After a fire, the fire department puts out the fire (containment), clears the smoke (eradication), and then you rebuild your home (recovery).
School example: A computer in the lab had a virus. After cleaning, the teacher restores the student files from a backup and re-installs the educational software.
Home example: Your dad's laptop got hacked. After cleaning, he restores his documents from an external hard drive and reconnects to Wi‑Fi.
Nigerian example: A Nigerian bank recovers after a DDoS attack by re-routing traffic, testing online banking, and monitoring for anomalies.
+---------------------------------------------+
| RECOVERY = PUTTING THINGS BACK TOGETHER |
+---------------------------------------------+
| 1. Restore data from clean backups. |
| 2. Reinstall software if needed. |
| 3. Test everything. |
| 4. Monitor for residual threats. |
| 5. Document and learn. |
+---------------------------------------------+
Mini Summary: Recovery brings your systems back to normal after an incident.
Definition: A clean backup is a copy of your data that you know is free from malware. You must only restore from clean backups.
Why it's important: If you restore from a backup that is infected, you'll bring the malware back! It's like using a dirty sponge to clean a plate.
Simple explanation: Clean backups are like a spare key that hasn't been copied by a thief. You know it's safe to use.
How to ensure clean backups:
School example: The school backs up student files to a USB drive that is only connected during backup. After a virus, they scan the USB and then restore.
Nigerian example: A Nigerian company uses an air-gapped backup system – a backup that is physically disconnected from the network – to prevent ransomware from encrypting it.
+---------------------------------------------+
| CLEAN BACKUP CHECKLIST |
+---------------------------------------------+
| ☐ Backup is from before the incident. |
| ☐ Backup has been scanned for viruses. |
| ☐ Backup is stored offline. |
| ☐ Backup has been tested recently. |
+---------------------------------------------+
Mini Summary: Only restore from backups you know are clean to avoid reinfection.
Definition: Restoring means copying the data from your backup back to your computer or system.
Why it's important: Restoring replaces corrupted or lost files with clean copies, so you can continue your work.
Simple explanation: Restoring is like retrieving a toy from a toy box. You open the box (backup) and take out the toy (file) you need.
Steps to restore:
School example: The school’s server had a corrupted database. The IT teacher restored the database from the previous night's backup.
Home example: Your mom's phone broke. She restored her contacts and photos from an iCloud backup to a new phone.
Nigerian example: A Nigerian university restores student records from a backup after a server crash.
+---------------------------------------------+
| RESTORATION PROCESS |
+---------------------------------------------+
| Backup ----> Restore ----> System |
| (clean) | (working) |
| V |
| Verify it's okay. |
+---------------------------------------------+
Mini Summary: Restoring from backup is the key to getting your data back.
Definition: Sometimes, you need to reinstall the operating system or applications because they might have been damaged or compromised during the incident.
Why it's important: Even if you removed the malware, there might be hidden changes to system files. Reinstalling gives you a clean slate.
Simple explanation: Reinstalling is like wiping a whiteboard clean so you can draw new, perfect pictures.
When to reinstall:
Steps:
School example: The school's lab computers were infected with a bootkit. The IT teacher reinstalled Windows on all 30 computers from a clean image.
Nigerian example: A bank's ATM software was compromised. They reimaged all ATMs with a clean software version.
+---------------------------------------------+
| REINSTALLATION STEPS |
+---------------------------------------------+
| 1. Get clean installation media. |
| 2. Wipe the hard drive. |
| 3. Install OS/software. |
| 4. Apply patches. |
| 5. Restore data from backup. |
+---------------------------------------------+
Mini Summary: Reinstalling gives you a fresh, clean system.
Definition: Testing means checking that everything works correctly after you have restored and reinstalled.
Why it's important: You want to make sure that the system is not only clean but also functional. Testing catches issues before users start working.
Simple explanation: Testing is like tasting your food before serving it to others. You want to make sure it's good!
What to test:
School example: After restoring the lab computers, the IT teacher logs in with a student account, opens Word, saves a document, and prints it.
Nigerian example: A Nigerian bank tests their online banking portal after a DDoS attack to ensure all services are working.
+---------------------------------------------+
| POST-RECOVERY TEST CHECKLIST |
+---------------------------------------------+
| ☐ Logins work. |
| ☐ Internet and network work. |
| ☐ Apps open and run. |
| ☐ Files can be saved and opened. |
| ☐ Performance is normal. |
+---------------------------------------------+
Mini Summary: Always test after recovery to ensure everything works as expected.
Definition: Monitoring means keeping a close watch on your systems after recovery to ensure no threats reappear.
Why it's important: Sometimes, malware can come back if it was not fully removed. Monitoring gives you early warning.
Simple explanation: Monitoring is like checking your room for a few days to make sure the mouse you caught is really gone.
What to monitor:
School example: The IT teacher keeps the antivirus logs open and checks them each morning for a week after the incident.
Nigerian example: A Nigerian company sets up extra monitoring on their servers for a month after a ransomware attack to ensure no residual activity.
+---------------------------------------------+
| POST-RECOVERY MONITORING |
+---------------------------------------------+
| Tools: Antivirus, IDS, SIEM, system logs. |
| Duration: At least 1-2 weeks. |
| Action: If anything suspicious, re-investigate.|
+---------------------------------------------+
Mini Summary: Monitoring after recovery helps catch any leftover threats.
Definition: Documentation is the record of everything that happened during the incident, including identification, containment, eradication, and recovery.
Why it's important: Documentation is like a history book for your incident. It helps you learn, improve, and prove compliance.
What to document:
School example: The IT teacher writes a report: "On 2025-10-15, a ransomware was detected. Contained by isolating PC#12. Eradicated by removing files and patching. Recovered by restoring from backup."
Nigerian example: A Nigerian bank keeps a detailed incident report for regulatory compliance with the Central Bank of Nigeria.
+---------------------------------------------+
| INCIDENT DOCUMENTATION EXAMPLE |
+---------------------------------------------+
| Incident ID: IR-2025-001 |
| Date: 2025-10-15 |
| Description: Ransomware attack on server.|
| Steps: |
| - 09:00 Detected. |
| - 09:05 Contained: isolated server. |
| - 09:30 Eradicated: removed malware. |
| - 10:00 Recovery: restored from backup. |
| Root cause: Unpatched SMB vulnerability. |
| Lessons: Update patch management. |
+---------------------------------------------+
Mini Summary: Documentation captures the entire incident for learning and improvement.
Definition: Cloud recovery involves restoring virtual machines, databases, and other cloud resources after an incident.
Why it's important: Many organizations use cloud services. You need to know how to recover there too.
Actions:
School example: The school uses Google Workspace. After a phishing attack, they restore a teacher's deleted files from Google Drive's trash.
Nigerian example: A Nigerian startup uses AWS. After a crypto-miner attack, they terminate the compromised EC2 instance and launch a new one from a clean AMI, then restore data from S3 backup.
+---------------------------------------------+
| CLOUD RECOVERY STEPS |
+---------------------------------------------+
| 1. Restore from cloud backup/snapshot. |
| 2. Rebuild instances from trusted images. |
| 3. Rotate keys and credentials. |
| 4. Adjust security groups. |
| 5. Monitor cloud logs. |
+---------------------------------------------+
Mini Summary: Cloud recovery uses similar principles but with cloud-specific tools.
Definition: Lessons learned is the process of reviewing the incident to identify what went wrong and how to improve.
Why it's important: You want to prevent the same incident from happening again. Learning makes you stronger.
Questions to ask:
School example: After a phishing incident, the school realizes they need more training on spotting phishing emails. They schedule a workshop.
Nigerian example: A Nigerian company discovers that their patch management was poor. They implement a new automated patching system.
+---------------------------------------------+
| LESSONS LEARNED PROCESS |
+---------------------------------------------+
| 1. Conduct a post-incident review. |
| 2. Identify root causes. |
| 3. Propose improvements. |
| 4. Implement changes. |
| 5. Train staff on new measures. |
+---------------------------------------------+
Mini Summary: Lessons learned help you improve and prevent future incidents.
Definition: A recovery checklist is a list of all recovery tasks to ensure nothing is missed.
Why it's important: Checklists help you stay organized and thorough.
Sample checklist:
School example: The IT teacher uses a checklist for each lab computer after an incident to ensure all steps are done.
Nigerian example: A Nigerian bank has a recovery checklist that must be signed off by the IT manager.
+---------------------------------------------+
| RECOVERY CHECKLIST |
+---------------------------------------------+
| ☐ Data restored from clean backup. |
| ☐ Systems rebuilt or reinstalled. |
| ☐ Patches applied. |
| ☐ Passwords changed. |
| ☐ Tests passed. |
| ☐ Monitoring started. |
| ☐ Incident documented. |
| ☐ Lessons learned review done. |
+---------------------------------------------+
Mini Summary: A checklist ensures you complete all recovery steps.
| Word | Simple Definition |
|---|---|
| Recovery | Restoring systems to normal operation. |
| Clean Backup | A backup free from malware. |
| Restore | Copying data from backup to the system. |
| Reinstall | Installing the OS/apps again from scratch. |
| Testing | Checking that everything works. |
| Monitoring | Watching for signs of trouble. |
| Documentation | Writing down what happened. |
| Lessons Learned | Reviewing to improve. |
| Cloud Recovery | Recovering cloud-based resources. |
| Integrity | Confirming files are unaltered. |
+---------------------------------------------+
| RECOVERY STEPS |
+---------------------------------------------+
| 1. Restore clean data. |
| 2. Reinstall apps if needed. |
| 3. Patch vulnerabilities. |
| 4. Change passwords. |
| 5. Test everything. |
| 6. Monitor for a while. |
| 7. Document the incident. |
| 8. Learn and improve. |
+---------------------------------------------+
|
+---------------------------------------------+
| RECOVERY FLOWCHART |
+---------------------------------------------+
| START |
| | |
| V |
| Restore data from clean backup. |
| | |
| V |
| Reinstall software if needed. |
| | |
| V |
| Apply patches. |
| | |
| V |
| Change passwords. |
| | |
| V |
| Test systems. |
| | |
| +--(Fail)--> Go back and fix. |
| | |
| V |
| Monitor for threats. |
| | |
| +--(Detect)--> Re-investigate. |
| | |
| V |
| Document and learn. |
| | |
| V |
| END |
+---------------------------------------------+
+---------------------------------------------+
| BACKUP & RECOVERY CYCLE |
+---------------------------------------------+
| Data ----> Backup ----> (Incident) |
| | |
| V |
| Restore ----> Recovery ----> Normal |
| | |
| +---> Backup again (new) |
+---------------------------------------------+
| Method | When to Use | Pros | Cons |
|---|---|---|---|
| Restore from Backup | When data is lost or corrupted. | Fast, reliable if backup is clean. | Backup might be outdated. |
| Rebuild from Scratch | When system is heavily compromised. | Guaranteed clean. | Time-consuming. |
| Cloud Snapshot Restore | In cloud environments. | Quick, automated. | Requires cloud knowledge. |
| Phase | Recovery Action |
|---|---|
| Prepare | Create backups and test them. |
| Identify | N/A (recovery happens later). |
| Contain | N/A |
| Eradicate | N/A |
| Recover | Restore, test, monitor, document. |
| Backup Type | Description | Use Case |
|---|---|---|
| Full Backup | Copy of all data. | Primary recovery. |
| Incremental Backup | Only changes since last backup. | Faster, less storage. |
| Differential Backup | Changes since last full backup. | Faster restore than incremental. |
|
Congratulations! You have completed Module 6 of the CCIH course. In this module, you learned:
Key takeaway: Recovery is not just about restoring data – it's about restoring confidence, learning from the experience, and becoming stronger and more resilient. |
1. What is the goal of recovery?
To bring systems back to normal operation safely.
2. Why must backups be clean?
Because restoring infected backups will bring the malware back.
3. What is the difference between restoration and rebuilding?
Restoration copies data; rebuilding reinstalls the entire system from scratch.
4. How long should I monitor after recovery?
At least one to two weeks.
5. What should I document in an incident report?
Timeline, actions, tools, findings, lessons learned.
6. Can I recover a system without a backup?
It's much harder and riskier. You might need to rebuild manually.
7. How often should I test backups?
At least once a month.
8. What if the backup is huge – how do I restore efficiently?
Use incremental or differential backups to speed up.
9. Is recovery different in the cloud?
It uses similar principles but with cloud-specific tools.
10. Why are lessons learned important?
They help you prevent future incidents.
| Answers: 1. Recovery, 2. clean, 3. Restoring, 4. Reinstalling, 5. test, 6. Monitoring, 7. document, 8. Lessons learned, 9. checklist, 10. Immutable |
| Answers: 1. False, 2. False, 3. False, 4. True, 5. False, 6. True, 7. False, 8. True, 9. True, 10. False |
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. Recovery | A. Copying data from backup |
| 2. Clean Backup | B. Restoring systems to normal |
| 3. Restore | C. A backup free from malware |
| 4. Monitoring | D. Watching for signs of trouble |
| 5. Lessons Learned | E. Reviewing to improve |
| Answers: 1-B, 2-C, 3-A, 4-D, 5-E |
Scenario 1: A school's computer lab was hit by a virus that deleted many student projects. The IT teacher contained and eradicated the virus. Now they have to recover the lab. They have a backup from a week ago. What steps should they take?
Scenario 2: A Nigerian bank's online banking system was down due to a DDoS attack. After the attack stopped, they need to recover normal services. What does recovery look like for them?
Scenario 3: Your family's home computer had a ransomware attack. You restored files from a backup, but you are not sure if the backup is clean. What do you do?
Activity: "Recovery Role-Play"
Activity: "My Personal Recovery Plan"
Project: "Create a Recovery Poster"
Assignment: Interview a local business owner or an IT professional about their recovery experience.
Challenge: "Simulate a Recovery"
Fantastic work! You have completed all five steps of incident handling: Prepare, Identify, Contain, Eradicate, and Recover. You are now a certified cyber incident handler in training!
In Module 7, we will look at the big picture – how to build a complete incident response program for an organization.
You will learn:
Before the next class: Think about what you would do if you were in charge of cyber security for a whole country. What would you put in place to handle incidents?
See you in Module 7, cyber hero! 🌟
🎉 End of Module 6 – CCIH 🎉
Recover, reflect, and be ready for anything!
Certified Cyber Security Incident Handler (CCIH) – Beginner Level
Hello, cyber hero! You have learned the five steps of incident handling: Prepare, Identify, Contain, Eradicate, and Recover. You know how to handle a single incident from start to finish. But what if you are responsible for an entire organization – a school, a bank, or even a whole country?
That's where a Cyber Incident Response Program comes in. It's not just about handling one incident; it's about building a system that can handle any incident, any time, and improve over time.
In this final module, you will learn:
By the end of this module, you will be ready to lead a cyber incident response team and make your organization a fortress against digital threats.
After studying this module, you will be able to:
|
Meet Mrs. Nwosu, the Chief Information Security Officer (CISO) of a large bank in Lagos, Nigeria. Her bank had faced several cyber attacks over the years. Each time, they handled the incident, but it felt like they were always reacting, never prepared. Mrs. Nwosu decided to build a Cyber Incident Response Program – a complete system that would handle any incident, learn from it, and improve continuously. She did this:
After two years, the bank had reduced incident response time by 70%. They were no longer just reacting – they were preventing and preparing. Mrs. Nwosu said, “A program is like a garden. You don't just plant seeds; you water them, pull weeds, and watch them grow. That's what we did with our incident response.” |
Definition: A Cyber Incident Response Program is a comprehensive framework that includes policies, procedures, people, and tools to handle cyber incidents effectively and continuously improve.
Why it's important: A single incident response plan is good, but a program ensures you are always ready, even for incidents you haven't thought of.
Simple explanation: A program is like a school curriculum. It's not just one lesson; it's a whole system of learning, testing, and improving over the years.
Components of a program:
Nigerian example: The Central Bank of Nigeria requires all banks to have a comprehensive incident response program as part of their cybersecurity guidelines.
+---------------------------------------------+
| INCIDENT RESPONSE PROGRAM COMPONENTS |
+---------------------------------------------+
| Policy ── Procedures ── Team ── Tools |
| │ │ │ │ |
| └───────────┴───────────┴───────┘ |
| │ |
| Training & Exercises |
| │ |
| Measurement & Improvement |
+---------------------------------------------+
Mini Summary: A program is a complete system for handling incidents, not just a one-time plan.
Definition: A maturity model is a way to measure how advanced your incident response program is. It has levels from 1 (lowest) to 5 (highest).
Why it's important: You can't improve if you don't know where you are. A maturity model gives you a benchmark.
The 5 levels (simplified):
School example: A school with no cyber security plan is Level 1. A school that has an IT teacher with a checklist is Level 2. A school with a full cyber policy and regular drills is Level 3 or 4.
Nigerian example: Many Nigerian banks are at Level 3 or 4, while small businesses might be at Level 1 or 2.
+---------------------------------------------+
| MATURITY LEVELS |
+---------------------------------------------+
| 5 – Optimized (always improving) |
| 4 – Managed (measured) |
| 3 – Defined (standardized) |
| 2 – Repeatable (basic) |
| 1 – Initial (chaotic) |
+---------------------------------------------+
Mini Summary: Maturity levels help you understand where your program stands and where you need to go.
Definition: Metrics are numbers that help you track how well your incident response program is performing.
Why it's important: If you can't measure it, you can't manage it. Metrics show you what's working and what's not.
Simple explanation: Metrics are like a thermometer for your program. They tell you if you have a fever (slow response) or are healthy (fast response).
Common metrics:
School example: The IT teacher tracks how long it takes to detect a student's virus report. They aim to detect within 5 minutes.
Nigerian example: A Nigerian company measures its MTTD and aims to reduce it by 20% each year.
+---------------------------------------------+
| KEY METRICS |
+---------------------------------------------+
| MTTD = Time to detect |
| MTTC = Time to contain |
| MTTE = Time to eradicate |
| MTTR = Time to recover |
| All should be as short as possible! |
+---------------------------------------------+
Mini Summary: Metrics help you measure your program's effectiveness and identify areas for improvement.
Definition: Continuous improvement is a cycle of planning, doing, checking, and acting (PDCA). It means you never stop improving your program.
Why it's important: Cyber threats change every day. Your program must change with them.
The PDCA cycle:
Simple explanation: PDCA is like learning to ride a bike. You try (Plan/Do), you fall (Check), you adjust (Act), and you try again.
School example: The school notices that phishing emails are increasing. They plan a training session (Plan), run it (Do), test students (Check), and then add more frequent training (Act).
Nigerian example: A Nigerian fintech company uses PDCA to improve their firewall rules. They monitor traffic, adjust rules, and measure if attacks are blocked.
+---------------------------------------------+
| PDCA CYCLE |
+---------------------------------------------+
| Plan ──> Do ──> Check ──> Act ──> (repeat) |
| │ │ │ │ |
| └─────────┴────────┴─────────┘ |
+---------------------------------------------+
Mini Summary: Continuous improvement ensures your program stays effective against new threats.
Definition: Training is formal education for your incident response team. Awareness is for all employees so they can spot and report incidents.
Why it's important: People are your first line of defense. Well-trained people make fewer mistakes and react faster.
What to train:
School example: The school holds a "Cyber Safety Week" with workshops for students and teachers.
Nigerian example: A Nigerian company has mandatory annual cyber security training for all employees, with a test at the end.
+---------------------------------------------+
| TRAINING PROGRAM |
+---------------------------------------------+
| IR Team: Technical skills |
| Employees: Awareness (phishing, passwords) |
| Leadership: Strategic understanding |
+---------------------------------------------+
Mini Summary: Training and awareness build a security-conscious culture.
Definition: A tabletop exercise is a discussion-based session where the team talks through a fictional incident scenario. A drill is a hands-on practice, like a fire drill.
Why it's important: Practice makes perfect. Exercises reveal gaps in your plan and help everyone know their roles.
How to run a tabletop:
School example: The school IT team runs a tabletop on a phishing attack. They discuss who would do what and how to communicate.
Nigerian example: A Nigerian bank runs a quarterly tabletop exercise with the incident response team and the legal team.
+---------------------------------------------+
| TABLETOP EXERCISE |
+---------------------------------------------+
| Scenario: Ransomware attack. |
| Questions: |
| - Who contains? |
| - Who communicates? |
| - What do we say to customers? |
| - How do we recover? |
+---------------------------------------------+
Mini Summary: Exercises prepare your team for real incidents.
Definition: Security culture means that everyone in the organization thinks about security as part of their daily work. It's not just the IT team's job.
Why it's important: When everyone cares about security, the organization becomes much stronger.
How to build it:
School example: The principal sends a weekly email with a "Cyber Tip of the Week" to all teachers.
Nigerian example: A Nigerian company holds an annual "Cyber Hero" award for the employee who reports the most phishing attempts.
+---------------------------------------------+
| SECURITY CULTURE PILLARS |
+---------------------------------------------+
| Leadership commitment |
| Employee engagement |
| Continuous communication |
| Recognition and rewards |
+---------------------------------------------+
Mini Summary: A strong security culture makes everyone a part of the defense.
Definition: External coordination means working with people and organizations outside your company, such as law enforcement, regulators (like the Central Bank), and internet service providers.
Why it's important: Sometimes an incident is too big to handle alone. Law enforcement can catch criminals, regulators need to be informed, and ISPs can help block attacks.
Who to coordinate with:
School example: If a student's identity is stolen, the school might work with the police.
Nigerian example: A Nigerian bank reports a major cyber attack to the CBN and also to the police.
+---------------------------------------------+
| EXTERNAL PARTNERS |
+---------------------------------------------+
| - Police (investigation) |
| - Regulators (compliance) |
| - ISPs (traffic blocking) |
| - Industry (threat sharing) |
+---------------------------------------------+
Mini Summary: Sometimes you need help from outside; know who to call.
Definition: Communication during an incident is about telling the right people the right information at the right time.
Why it's important: Bad communication can cause panic, rumors, and loss of trust. Good communication keeps everyone calm and informed.
Who to communicate with:
What to say:
School example: The school sends an email to parents: "We are investigating a data breach. We will update you soon."
Nigerian example: A bank uses social media and its website to inform customers about a service outage due to a cyber attack.
+---------------------------------------------+
| COMMUNICATION PLAN |
+---------------------------------------------+
| Internal: Employees, management |
| External: Customers, media, regulators |
| Key: Honest, timely, clear |
+---------------------------------------------+
Mini Summary: Good communication builds trust and reduces confusion.
Definition: A business case is a set of arguments and evidence you use to convince leadership to invest in your incident response program.
Why it's important: Programs cost money. You need to show leaders that the investment is worth it.
What to include:
School example: The IT teacher shows the principal that a ransomware attack could cost ₦10 million, while a program costs only ₦1 million. It's a good investment.
Nigerian example: A Nigerian company calculates that the NDPR fine for a data breach is up to 2% of annual turnover. Investing in a program avoids that fine.
+---------------------------------------------+
| BUSINESS CASE ELEMENTS |
+---------------------------------------------+
| - Cost of breach vs. cost of program |
| - Compliance requirements |
| - Reputation protection |
| - Competitive advantage |
+---------------------------------------------+
Mini Summary: A good business case helps you get the resources you need.
Definition: Leadership (CEOs, board members) must actively support and participate in the incident response program.
Why it's important: If leaders don't care, no one else will. Leaders set the tone.
What leaders should do:
School example: The principal attends a tabletop exercise and asks questions, showing that security matters.
Nigerian example: The CEO of a Nigerian bank receives monthly cyber security reports and reviews them personally.
+---------------------------------------------+
| LEADERSHIP ROLE |
+---------------------------------------------+
| - Provide resources |
| - Set the example |
| - Demand accountability |
| - Communicate priority |
+---------------------------------------------+
Mini Summary: Leadership buy-in is essential for a successful program.
Definition: Review and update means regularly looking at your program and making changes based on new threats, lessons learned, and changes in the organization.
Why it's important: The cyber world changes fast. A program that is not updated becomes useless.
When to review:
School example: The school reviews its program every June, before the new school year starts.
Nigerian example: A Nigerian company reviews its program every quarter to keep up with evolving threats.
+---------------------------------------------+
| REVIEW CYCLE |
+---------------------------------------------+
| After incidents |
| Annually |
| When things change |
| When new threats emerge |
+---------------------------------------------+
Mini Summary: Regular reviews keep your program relevant and effective.
| Word | Simple Definition |
|---|---|
| Incident Response Program | A complete system for handling incidents. |
| Maturity Model | A way to measure how advanced your program is. |
| Metric | A number that measures performance (like speed). |
| PDCA | A cycle for continuous improvement (Plan, Do, Check, Act). |
| Tabletop Exercise | A discussion-based practice session. |
| Security Culture | When everyone cares about security. |
| External Coordination | Working with outside parties (police, regulators). |
| Business Case | Arguments to get resources for your program. |
| Leadership Buy-in | Support from top management. |
| Review | Checking and updating the program. |
+---------------------------------------------+
| BUILDING A PROGRAM STEPS |
+---------------------------------------------+
| 1. Assess |
| 2. Roadmap |
| 3. Policies |
| 4. Team |
| 5. Tools |
| 6. Training |
| 7. Exercises |
| 8. Metrics |
| 9. Improve |
| 10. Communicate |
+---------------------------------------------+
|
+---------------------------------------------+
| INCIDENT RESPONSE PROGRAM |
+---------------------------------------------+
| +--------+ +--------+ +--------+ |
| | Policy | | Team | | Tools | |
| +--------+ +--------+ +--------+ |
| | | | |
| +------+------+------------+ |
| | |
| +----+----+ |
| |Training | |
| +----+----+ |
| | |
| +----+----+ |
| |Exercises | |
| +----+----+ |
| | |
| +----+----+ |
| |Metrics | |
| +----+----+ |
| | |
| +----+----+ |
| |Improve | (PDCA) |
| +----+----+ |
+---------------------------------------------+
+---------------------------------------------+
| MATURITY LEVELS |
+---------------------------------------------+
| Level 5 - Optimized (best) |
| Level 4 - Managed (measured) |
| Level 3 - Defined (standard) |
| Level 2 - Repeatable (basic) |
| Level 1 - Initial (chaotic) |
+---------------------------------------------+
+---------------------------------------------+
| PLAN |
| (Identify improvement) |
| | |
| V |
| DO |
| (Implement the plan) |
| | |
| V |
| CHECK |
| (Measure results) |
| | |
| V |
| ACT |
| (Adjust or standardize) |
| | |
| +-------+ |
| | |
| V |
| REPEAT |
+---------------------------------------------+
| Level | Description | Example |
|---|---|---|
| 1 – Initial | No formal process; chaotic. | A school with no cyber plan. |
| 2 – Repeatable | Basic procedures, inconsistent. | A small business with a checklist. |
| 3 – Defined | Standard, documented process. | A company with a formal IR plan. |
| 4 – Managed | Measured and tracked. | A bank with MTTD metrics. |
| 5 – Optimized | Continuously improving. | A tech giant with constant updates. |
| Training | Awareness |
|---|---|
| For the incident response team. | For all employees. |
| Deep, technical skills. | Basic knowledge (e.g., phishing). |
| Formal sessions, often certified. | Informal, regular tips. |
| Frequency: several times a year. | Frequency: ongoing. |
|
Congratulations! You have completed Module 7, the final module of the CCIH course. In this module, you learned:
Key takeaway: A successful incident response program is not a destination – it's a journey of constant learning, adapting, and improving. You now have the knowledge to be a leader in cyber security. |
1. What is the difference between an incident response plan and a program?
A plan is a document; a program is the whole system including people, tools, training, and continuous improvement.
2. What is a maturity model?
It's a scale from 1 to 5 that shows how advanced your program is.
3. Why should I measure metrics?
To know if your program is getting better over time.
4. What is PDCA?
A cycle for continuous improvement: Plan, Do, Check, Act.
5. How often should we run exercises?
At least twice a year.
6. What is security culture?
When everyone in the organization cares about security.
7. Who should we coordinate with externally?
Police, regulators, ISPs, and industry peers.
8. How do I get leadership support?
Build a business case showing the cost of breaches vs. the cost of the program.
9. What is a tabletop exercise?
A discussion-based practice session without actually doing anything on computers.
10. How often should we review our program?
At least annually, and after every major incident.
| Answers: 1. program, 2. Maturity model, 3. MTTD, 4. PDCA, 5. tabletop, 6. Security culture, 7. Nigeria Police Force, 8. business case, 9. Leadership, 10. review |
| Answers: 1. False, 2. True, 3. False, 4. True, 5. False, 6. False, 7. False, 8. True, 9. False, 10. False |
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. Maturity Model | A. A cycle for improvement |
| 2. PDCA | B. A measure of detection speed |
| 3. MTTD | C. A scale to assess your program |
| 4. Tabletop | D. Everyone cares about security |
| 5. Security Culture | E. A discussion-based exercise |
| Answers: 1-C, 2-A, 3-B, 4-E, 5-D |
Scenario 1: You are the new IT manager at a school. The school has no incident response program. Teachers don't know what to do if a virus appears. Develop a plan to build a program from scratch.
Scenario 2: A Nigerian bank is at Level 2 maturity. The CBN has mandated that all banks must reach Level 4 by next year. What steps should the bank take to improve?
Scenario 3: Your company had a major breach. After handling it, you want to improve. What would you do as part of lessons learned and program review?
Activity: "Build a Program for a Fictional School"
Activity: "Assess Your Home's Cyber Maturity"
Project: "Create a Program Poster"
Assignment: Interview a manager or leader in a company about their cyber security program.
Challenge: "Design a Tabletop Exercise"
You have finished all seven modules of the Certified Cyber Security Incident Handler (CCIH) course. You now know the entire incident handling process from preparation to recovery, and you understand how to build a complete program for an organization.
What's next?
Remember, cyber security is not just a job – it's a way of thinking. Always be curious, always be cautious, and always be a cyber hero.
Thank you for being part of this journey. Stay safe, stay secure, and never stop learning!
🎉 End of Module 7 – CCIH Complete! 🎉
You are now a certified cyber incident handler in training. Go make the digital world safer!
Certified Cyber Security Incident Handler (CCIH) – Beginner Level
Hello, cyber hero! You have come a long way. You started by learning the basics of cyber security, then you learned the 5 steps of incident handling: Prepare, Identify, Contain, Eradicate, and Recover. Then you learned how to build a whole program. Now, it's time to look ahead.
Cyber threats are always changing. New technologies bring new dangers. Criminals find new ways to attack. In this final module, we will explore the future of cyber incident handling. You will learn about advanced topics that will help you stay ahead of the bad guys.
In this module, you will learn:
By the end of this module, you will be ready to face the cyber challenges of tomorrow.
After studying this module, you will be able to:
|
Meet Grace, a young cyber security expert in Lagos. She works for a company that protects schools from cyber attacks. One day, a new threat emerged – an AI-powered chatbot that tricked students into giving their passwords. Grace knew she had to prepare for the future. She did this:
When the AI chatbot attack hit, Grace was ready. She identified it quickly, contained it, and eradicated the threat. The school didn't lose any data. Grace said, “The future of cyber security is about staying ahead. You can't fight tomorrow's battles with yesterday's weapons.” |
Definition: Emerging threats are new types of cyber dangers that are just starting to appear. They come from new technologies.
Why it's important: If you only focus on old threats, you'll be surprised by new ones. You must stay updated.
Simple explanation: Emerging threats are like new viruses that doctors haven't seen before. You need new medicines.
Types of emerging threats:
School example: A school uses smart boards (IoT) – if a hacker controls them, they could disrupt lessons.
Nigerian example: Many Nigerian businesses are moving to the cloud. They must learn to configure cloud security properly.
+---------------------------------------------+
| EMERGING THREATS |
+---------------------------------------------+
| AI – smarter phishing |
| IoT – smart devices (cameras, fridges) |
| Cloud – misconfigured storage |
| Quantum – breaks encryption (future) |
+---------------------------------------------+
Mini Summary: Emerging threats come from new technologies. Stay informed to protect against them.
Definition: Threat intelligence is information about potential or current threats. It helps you prepare and respond better.
Why it's important: If you know what attacks are coming, you can stop them before they hit.
Simple explanation: Threat intelligence is like a weather forecast for cyber storms. You know when to batten down the hatches.
Sources of threat intelligence:
How to use it:
School example: A school subscribes to a threat intelligence feed. It alerts them about a new phishing campaign targeting schools. They warn teachers.
Nigerian example: Nigerian banks share threat intelligence through the CBN's cybersecurity framework.
+---------------------------------------------+
| THREAT INTELLIGENCE CYCLE |
+---------------------------------------------+
| Collect data → Analyze → Share → Act |
| ↑ ↓ |
| └────────── Learn ────┘ |
+---------------------------------------------+
Mini Summary: Threat intelligence gives you early warning about cyber dangers.
Definition: Legal and regulatory frameworks are laws and rules that organizations must follow regarding cyber security and data protection.
Why it's important: Breaking the law can lead to fines, lawsuits, and even jail. Following the law protects you and builds trust.
Key laws in Nigeria:
Simple explanation: Laws are like rules of the road. If you don't follow them, you can cause an accident and get a ticket.
School example: A school must protect student data under NDPR. They must not share it without permission.
Nigerian example: A bank failing to protect customer data could be fined by CBN under its guidelines.
+---------------------------------------------+
| NIGERIAN CYBER LAWS |
+---------------------------------------------+
| NDPR – data protection |
| Cybercrime Act – illegal activities |
| CBN Guidelines – banking security |
| NITDA Guidelines – general framework |
+---------------------------------------------+
Mini Summary: Know the laws that affect your organization to stay compliant.
Definition: Working with law enforcement means cooperating with police and other agencies to investigate and prosecute cybercriminals.
Why it's important: You can't always handle everything alone. Police have the power to arrest and prosecute criminals.
Simple explanation: If someone breaks into your house, you call the police. It's the same with cybercrime.
How to work with them:
School example: A student's identity is stolen online. The school reports it to the police and provides all evidence.
Nigerian example: A Nigerian company reports a major cyber theft to the police, who investigate and arrest the perpetrators.
+---------------------------------------------+
| WORKING WITH POLICE |
+---------------------------------------------+
| 1. Report the incident. |
| 2. Provide evidence. |
| 3. Cooperate with investigation. |
| 4. Let them lead. |
+---------------------------------------------+
Mini Summary: Law enforcement is your partner in fighting cybercrime.
Definition: Crisis communication is how you talk to the public, customers, and media during a cyber incident.
Why it's important: If you don't communicate well, people will panic, rumors will spread, and your reputation will suffer.
Simple explanation: Crisis communication is like a spokesperson who tells everyone what's happening so they stay calm.
Tips for good crisis communication:
School example: A school has a data breach. The principal sends a letter to parents: "We found a breach. We are investigating. We will keep you updated."
Nigerian example: A bank experiences a service outage due to a DDoS attack. They use social media to inform customers and apologize for the inconvenience.
+---------------------------------------------+
| CRISIS COMMUNICATION TIPS |
+---------------------------------------------+
| - Be truthful. |
| - Be timely. |
| - Be empathetic. |
| - Have a single spokesperson. |
+---------------------------------------------+
Mini Summary: Good communication builds trust during a crisis.
Definition: Critical infrastructure are systems that are vital to a country's functioning, like power grids, water supply, transportation, and hospitals.
Why it's important: If these systems are attacked, people could lose electricity, water, or even lives.
Simple explanation: Critical infrastructure is like the body's vital organs – if they fail, the whole body suffers.
Examples:
How to protect them:
Nigerian example: The Nigerian government has a national cyber security strategy that includes protecting critical infrastructure.
+---------------------------------------------+
| CRITICAL INFRASTRUCTURE |
+---------------------------------------------+
| - Power |
| - Water |
| - Transport |
| - Healthcare |
| - Oil & Gas |
+---------------------------------------------+
Mini Summary: Protecting critical infrastructure is a national priority.
Definition: Supply chain security means protecting the flow of goods and services from your suppliers to your customers. In cyber, it's about making sure your partners don't introduce vulnerabilities.
Why it's important: Attackers often target smaller, less secure suppliers to get into big companies.
Simple explanation: It's like a chain – if one link is weak, the whole chain breaks.
How to improve supply chain security:
School example: A school uses a vendor for online learning platforms. The school checks that the vendor has good security.
Nigerian example: A Nigerian telecom company ensures that its equipment suppliers don't have backdoors.
+---------------------------------------------+
| SUPPLY CHAIN SECURITY |
+---------------------------------------------+
| Your Company ←→ Supplier 1 ←→ Supplier 2 |
| If Supplier 2 is weak, you are at risk! |
+---------------------------------------------+
Mini Summary: Your security is only as strong as your weakest supplier.
Definition: Ethical hacking is when you use hacking techniques to find vulnerabilities, but with permission and to help, not harm. A penetration test (pentest) is a simulated attack to test your defenses.
Why it's important: You can't know if your security is strong until you test it. Ethical hackers find weaknesses before criminals do.
Simple explanation: Ethical hacking is like hiring a burglar to test your locks. They tell you which locks are weak.
Types of penetration tests:
School example: The school hires an ethical hacker to test its network. The hacker finds a vulnerability in the Wi‑Fi and reports it. The school fixes it.
Nigerian example: Nigerian banks often hire ethical hackers to test their online banking platforms.
+---------------------------------------------+
| ETHICAL HACKING PROCESS |
+---------------------------------------------+
| 1. Get permission. |
| 2. Plan the test. |
| 3. Execute the test (try to break in). |
| 4. Report vulnerabilities. |
| 5. Help fix them. |
+---------------------------------------------+
Mini Summary: Ethical hacking helps you find and fix weaknesses safely.
Definition: Continuous learning means always updating your skills. Certifications are formal qualifications that prove your knowledge.
Why it's important: Cyber security changes every day. If you stop learning, you become outdated.
Simple explanation: It's like practicing a sport – you must keep training to stay good.
Ways to learn:
School example: A teacher takes a CCIH course (like you!) to learn incident handling.
Nigerian example: Many Nigerian IT professionals pursue certifications to advance their careers.
+---------------------------------------------+
| CERTIFICATION PATH |
+---------------------------------------------+
| Beginner: CCIH, Security+ |
| Intermediate: CEH, CISM |
| Advanced: CISSP, OSCP |
+---------------------------------------------+
Mini Summary: Keep learning and get certified to stay relevant.
Definition: A career in cyber security means working to protect computers, networks, and data from attacks. There are many roles you can choose.
Why it's important: Cyber security is a growing field with many opportunities. You can make a difference.
Simple explanation: It's like choosing to be a doctor for computers – you heal sick systems.
Career paths:
How to start:
School example: A student interested in cyber security joins a cyber club and learns about incident handling.
Nigerian example: Many Nigerian companies are hiring cyber security professionals to comply with regulations.
+---------------------------------------------+
| CAREER PATHS |
+---------------------------------------------+
| - Incident Responder |
| - Security Analyst |
| - Ethical Hacker |
| - Security Engineer |
| - CISO |
+---------------------------------------------+
Mini Summary: Cyber security offers many exciting career opportunities.
| Word | Simple Definition |
|---|---|
| Emerging Threat | New types of cyber dangers from new technologies. |
| Threat Intelligence | Information about potential or current threats. |
| NDPR | Nigeria Data Protection Regulation – protects personal data. |
| Critical Infrastructure | Vital systems like power and water. |
| Supply Chain | The network of suppliers and partners. |
| Ethical Hacking | Using hacking skills to help, with permission. |
| Penetration Test | A simulated attack to test security. |
| Certification | A formal qualification proving skills. |
| Crisis Communication | Communication during a crisis. |
| Law Enforcement | The police and other investigative agencies. |
+---------------------------------------------+
| STAY AHEAD – STEP BY STEP |
+---------------------------------------------+
| 1. Get threat intelligence. |
| 2. Update tools. |
| 3. Test your defenses (pentest). |
| 4. Train staff. |
| 5. Share with peers. |
| 6. Update IR plan. |
| 7. Know the laws. |
| 8. Build relationships. |
+---------------------------------------------+
|
+---------------------------------------------+
| EMERGING THREATS |
+---------------------------------------------+
| AI Attacks → Smarter phishing |
| IoT Hacks → Smart devices compromised |
| Cloud Risks → Misconfigured storage |
| Quantum → Encryption broken |
+---------------------------------------------+
+---------------------------------------------+
| COLLECT → ANALYZE → SHARE → ACT |
| ↑ ↓ ↓ ↓ |
| └──────────┴──────────┴──────────┘ |
| LEARN |
+---------------------------------------------+
| Traditional Threats | Future/Emerging Threats |
|---|---|
| Simple viruses | AI-powered malware |
| Basic phishing emails | Deepfake voice phishing |
| On-premise attacks | Cloud and IoT attacks |
| Manual hacking | Automated, AI-driven hacking |
| Level | Certification | Focus |
|---|---|---|
| Beginner | CCIH, Security+ | Basic incident handling, fundamentals |
| Intermediate | CEH, CISM | Ethical hacking, management |
| Advanced | CISSP, OSCP | Deep technical, leadership |
|
Congratulations! You have completed Module 8, the final module of the CCIH course. In this module, you learned:
Key takeaway: Cyber security is a journey, not a destination. The threats will keep changing, but with the right knowledge, skills, and mindset, you can protect yourself and others. You are now equipped to be a cyber hero for the future! |
1. What are emerging threats?
New types of cyber dangers from new technologies like AI, IoT, and quantum computing.
2. What is threat intelligence?
Information about current or potential threats that helps you prepare.
3. What is NDPR?
Nigeria Data Protection Regulation – a law that protects personal data.
4. Why work with law enforcement?
Because they can investigate and prosecute cybercriminals.
5. What is crisis communication?
How you talk to the public and media during an incident.
6. What is critical infrastructure?
Vital systems like power, water, and transport that need protection.
7. What is supply chain security?
Making sure your partners don't compromise your security.
8. What is ethical hacking?
Using hacking skills to find vulnerabilities, with permission.
9. How can I keep learning?
Read blogs, take courses, get certifications.
10. What careers are in cyber security?
Incident Responder, Security Analyst, Ethical Hacker, CISO, and many more.
| Answers: 1. Emerging, 2. Threat intelligence, 3. NDPR, 4. Crisis, 5. Critical, 6. Supply chain, 7. Ethical, 8. penetration, 9. Continuous, 10. certification |
| Answers: 1. False, 2. True, 3. True, 4. False, 5. False, 6. True, 7. False, 8. False, 9. True, 10. False |
Match the term on the left with its definition on the right.
| Term | Definition |
|---|---|
| 1. NDPR | A. A simulated attack to test security |
| 2. Threat Intelligence | B. Information about potential threats |
| 3. Penetration Test | C. A law protecting personal data in Nigeria |
| 4. Crisis Communication | D. Protecting vital systems like power |
| 5. Critical Infrastructure | E. How you talk during a crisis |
| Answers: 1-C, 2-B, 3-A, 4-E, 5-D |
Scenario 1: A Nigerian company faces a new AI-powered phishing attack that is targeting its employees. The company's traditional security tools are not catching it. What should they do?
Scenario 2: A school's student data is leaked. The principal is worried about parent complaints. How should the school communicate the crisis?
Scenario 3: A critical infrastructure company (power plant) is concerned about cyber attacks. They want to start a penetration testing program. What steps should they take?
Activity: "Future Threat Debate"
Activity: "My Cyber Career Plan"
Project: "Create a Future Threat Awareness Campaign"
Assignment: Research a recent cyber incident that involved an emerging threat (like AI or IoT).
Challenge: "Design a Threat Intelligence Strategy"
This is the end of the Certified Cyber Security Incident Handler (CCIH) course. You have completed all eight modules.
You now have a solid foundation in cyber security incident handling. You can identify, contain, eradicate, and recover from incidents. You can also build a program and prepare for the future.
What to do next:
Remember, cyber security is not just a job – it's a mindset. Always think about security, always be cautious, and always be ready to help.
Thank you for being part of this journey. You are now a cyber hero – go make the digital world a safer place!
🎉 End of Module 8 – CCIH Complete! 🎉
Congratulations, cyber hero! You are ready for the future.