A 15-module academic curriculum that teaches the human side of cybersecurity — emotional intelligence under pressure — with measurable outcomes mapped to the NICE Framework and CAE-CD Knowledge Units. Free for educators; drops into any cybersecurity program or LMS.
At a glance
Modules
across five EQ domains
15
NICE work roles
supported
15
CAE-CD knowledge units
addressed
9
The fifteen modules
Number, title, domain and the time a student should set aside.
Security management / leadership courses, capstones, or the second half of a two-part sequence.
Incident Response Focus
Stress, burnout, regulation, psychological safety, and crisis leadership — plus a tabletop — in 6 weeks.
6 weeks · modules 4, 5, 6, 14, 15 · 8 assignments
Incident response, SOC operations, or digital forensics courses that want the human side of IR.
Modules, outcomes, and alignment
01
Module 1: Recognizing Emotional Triggers
Self-Awareness
Learning outcomes — students will be able to
Identify personal emotional triggers common in security work — authority challenges, time pressure, blame attribution, resource constraints, and competence threats.
Describe the five-stage trigger-response cycle and locate the point between physiological response and emotional experience where intervention is most effective.
Maintain a personal trigger inventory and recognize early physical warning signs in low-stakes situations.
NICE work roles
Cyber Defense Analyst (PR-CDA-001)
Cyber Defense Incident Responder (PR-CIR-001)
Systems Security Analyst (OM-ANA-001)
NICE-aligned competencies
Ability to recognize and manage personal stress responses in high-tempo operational environments.
Skill in self-assessment and reflective practice to sustain analytical judgment.
CAE-CD knowledge units
Cybersecurity Foundations (CSF · Foundational)
Cybersecurity Principles (CSP · Foundational)
02
Module 2: Understanding Bias in Threat Assessment
Self-Awareness
Learning outcomes — students will be able to
Explain how availability, confirmation, anchoring, optimism, and authority bias distort threat assessment.
Apply debiasing techniques — pre-mortems, red-team thinking, structured analysis, diverse input, decision journaling — to a security decision.
Audit recent analytical decisions for bias and document the influence found.
NICE work roles
Threat/Warning Analyst (AN-TWA-001)
Cyber Defense Analyst (PR-CDA-001)
Vulnerability Assessment Analyst (PR-VAM-001)
Security Control Assessor (SP-RSK-002)
NICE-aligned competencies
Knowledge of cognitive biases that affect analysis and risk assessment.
Skill in applying structured analytic techniques to reduce analytical error.
Ability to evaluate information for reliability, validity, and relevance.
CAE-CD knowledge units
Cyber Threats (CTH · Non-Technical Core)
Security Risk Analysis (SRA · Non-Technical Core)
Cybersecurity Principles (CSP · Foundational)
03
Module 3: Fatigue and Performance Awareness
Self-Awareness
Learning outcomes — students will be able to
Explain how fatigue narrows attention, degrades pattern recognition, distorts risk assessment, and weakens emotional regulation.
Recognize personal physical, cognitive, emotional, and behavioral fatigue indicators.
Set fatigue-aware operating policies for which decisions to defer or hand off when depleted.
NICE work roles
Cyber Defense Analyst (PR-CDA-001)
Cyber Defense Infrastructure Support Specialist (PR-INF-001)
Systems Security Analyst (OM-ANA-001)
NICE-aligned competencies
Knowledge of human-performance factors (fatigue, workload, stress) affecting security operations.
Ability to sustain performance and judgment over extended operational periods.
CAE-CD knowledge units
Cybersecurity Foundations (CSF · Foundational)
Cybersecurity Planning and Management (CPM · Non-Technical Core)
04
Module 4: Stress Management During Incidents
Self-Management
Learning outcomes — students will be able to
Distinguish helpful from harmful stress during incidents and identify the personal tipping point between them.
Apply the PACE protocol (Pause, Assess, Choose, Execute) during a simulated incident.
Explain how a responder's emotional state sets the response team's emotional baseline, and why recovery speed sustains performance.
NICE work roles
Cyber Defense Incident Responder (PR-CIR-001)
Cyber Defense Analyst (PR-CDA-001)
Cyber Defense Infrastructure Support Specialist (PR-INF-001)
NICE-aligned competencies
Ability to function effectively in a high-stress, time-critical incident environment.
Skill in maintaining composure and decision quality while responding to security incidents.
CAE-CD knowledge units
Basic Cyber Operations (BCO · Optional)
Cyber Threats (CTH · Non-Technical Core)
Cybersecurity Foundations (CSF · Foundational)
05
Module 5: Preventing Analyst Burnout
Self-Management
Learning outcomes — students will be able to
Describe the four stages of burnout and why recovery takes longer than the descent.
Design sustainable work practices — micro-recoveries, boundaries, purpose connection, support systems, physical foundations.
Assess one's own position on the burnout continuum and identify one boundary to restore.
NICE work roles
Cyber Defense Analyst (PR-CDA-001)
Cyber Workforce Developer and Manager (OV-SPP-001)
Information Systems Security Manager (OV-MGT-001)
NICE-aligned competencies
Knowledge of workforce sustainability and retention factors in security operations.
Ability to plan and maintain sustainable performance over a security career.
CAE-CD knowledge units
Cybersecurity Planning and Management (CPM · Non-Technical Core)
Security Program Management (SPM · Non-Technical Core)
06
Module 6: Emotional Regulation Under Pressure
Self-Management
Learning outcomes — students will be able to
Explain the neurological basis of the six-second pause and affect labeling.
Apply cognitive reappraisal, emotional distancing, future-self perspective, and values anchoring in a high-stakes exchange.
Demonstrate strategic expression — channeling emotion into effective communication — during a confrontation.
NICE work roles
Cyber Defense Incident Responder (PR-CIR-001)
Information Systems Security Manager (OV-MGT-001)
Cyber Defense Analyst (PR-CDA-001)
NICE-aligned competencies
Ability to regulate emotional responses under pressure and confrontation.
Skill in communicating difficult information with composure.
CAE-CD knowledge units
Cybersecurity Foundations (CSF · Foundational)
Basic Cyber Operations (BCO · Optional)
07
Module 7: Reading Stakeholder Emotions
Social Awareness
Learning outcomes — students will be able to
Interpret non-verbal and verbal cues to assess stakeholder emotional state during security conversations.
Translate surface objections ("too complicated", "no time", "IT always says no") into underlying stakeholder needs.
Use reflective statements to confirm understanding of a stakeholder's concern before proposing solutions.
NICE work roles
Information Systems Security Manager (OV-MGT-001)
Cyber Policy and Strategy Planner (OV-SPP-002)
Security Control Assessor (SP-RSK-002)
NICE-aligned competencies
Skill in communicating with non-technical stakeholders about security risk.
Ability to interpret interpersonal dynamics that affect security decisions.
CAE-CD knowledge units
Cybersecurity Planning and Management (CPM · Non-Technical Core)
Security Program Management (SPM · Non-Technical Core)
08
Module 8: Understanding Security Fatigue in End Users
Social Awareness
Learning outcomes — students will be able to
Identify the causes of security fatigue — constant vigilance, friction accumulation, alert overload, unclear purpose, absent positive feedback.
Recognize early signs of fatigue (workarounds, malicious compliance, delayed responses) before they become non-compliance.
Redesign a security communication to lead with "why" and reduce friction, contrasting security-enabled with security-enforced culture.
NICE work roles
Cyber Workforce Developer and Manager (OV-SPP-001)
Cyber Instructor (OV-TEA-002)
Information Systems Security Manager (OV-MGT-001)
NICE-aligned competencies
Knowledge of security awareness and behavior-change principles.
Ability to design security controls and communications that sustain user engagement.
CAE-CD knowledge units
Security Program Management (SPM · Non-Technical Core)
Cybersecurity Planning and Management (CPM · Non-Technical Core)
Policy, Legal, Ethics, and Compliance (PLE · Non-Technical Core)
09
Module 9: Navigating Organizational Politics
Social Awareness
Learning outcomes — students will be able to
Map informal power structures — influencers, gatekeepers, connectors, historians, champions — relevant to a security initiative.
Plan pre-selling, coalition-building, timing, and quick-win strategies to advance a security proposal.
Analyze why technically sound initiatives fail for organizational reasons.
NICE work roles
Information Systems Security Manager (OV-MGT-001)
Cyber Policy and Strategy Planner (OV-SPP-002)
Program Manager (OV-PMA-001)
Executive Cyber Leadership (OV-EXL-001)
NICE-aligned competencies
Knowledge of organizational structure, governance, and decision processes.
Ability to build consensus and influence decision-makers across organizational units.
CAE-CD knowledge units
Security Program Management (SPM · Non-Technical Core)
Cybersecurity Planning and Management (CPM · Non-Technical Core)
Policy, Legal, Ethics, and Compliance (PLE · Non-Technical Core)
10
Module 10: Building Trust with Non-Security Teams
Relationship Management
Learning outcomes — students will be able to
Identify behaviors that build trust (reliability, competence, listening first, saying yes when possible, owning mistakes) and those that break it.
Diagnose "get it approved before security finds out" as a trust problem and propose a repair plan.
Reframe a security requirement as "yes, and here's how we do it securely."
NICE work roles
Information Systems Security Manager (OV-MGT-001)
Security Control Assessor (SP-RSK-002)
Program Manager (OV-PMA-001)
NICE-aligned competencies
Ability to establish and maintain productive working relationships with mission partners.
Skill in positioning security as an enabling business partner.
CAE-CD knowledge units
Security Program Management (SPM · Non-Technical Core)
Cybersecurity Planning and Management (CPM · Non-Technical Core)
Cybersecurity Ethics (CSE · Optional)
11
Module 11: Conflict Resolution in Security Contexts
Relationship Management
Learning outcomes — students will be able to
Explain why most security conflicts are about competing priorities, resources, and power rather than security itself.
Apply the SOLVE framework (Seek, Outline, List, Validate, Establish) to a security disagreement.
Resolve a conflict while preserving the working relationship and documenting agreed next steps.
NICE work roles
Information Systems Security Manager (OV-MGT-001)
Program Manager (OV-PMA-001)
Security Control Assessor (SP-RSK-002)
NICE-aligned competencies
Skill in negotiation and conflict resolution in a security context.
Ability to identify shared interests across competing organizational priorities.
CAE-CD knowledge units
Security Program Management (SPM · Non-Technical Core)
Policy, Legal, Ethics, and Compliance (PLE · Non-Technical Core)
Cybersecurity Ethics (CSE · Optional)
12
Module 12: Influencing Without Authority
Relationship Management
Learning outcomes — students will be able to
Contrast compliance (authority) with commitment (influence) and their effects on security behavior when nobody is watching.
Apply expertise, relationships, reciprocity, consistency, and social proof to drive adoption of a security practice.
Redesign a control so the secure path is the easiest path.
NICE work roles
Cyber Workforce Developer and Manager (OV-SPP-001)
Cyber Policy and Strategy Planner (OV-SPP-002)
Cyber Instructor (OV-TEA-002)
Information Systems Security Manager (OV-MGT-001)
NICE-aligned competencies
Ability to influence behavior change across an organization without positional authority.
Knowledge of security awareness and behavior-change principles.
CAE-CD knowledge units
Security Program Management (SPM · Non-Technical Core)
Cybersecurity Planning and Management (CPM · Non-Technical Core)
Policy, Legal, Ethics, and Compliance (PLE · Non-Technical Core)
13
Module 13: Mentoring Security Professionals
Security Leadership
Learning outcomes — students will be able to
Apply the GROW model (Goal, Reality, Options, Will) to a development conversation.
Practice ask-before-tell mentoring that builds independent capability rather than dependency.
Create safety for failure and stretch opportunities for a mentee; articulate one's legacy in terms of people developed.
NICE work roles
Cyber Workforce Developer and Manager (OV-SPP-001)
Skill in coaching and structured development conversations.
CAE-CD knowledge units
Security Program Management (SPM · Non-Technical Core)
Cybersecurity Ethics (CSE · Optional)
14
Module 14: Creating Psychological Safety
Security Leadership
Learning outcomes — students will be able to
Explain why psychological safety functions as a security control — early surfacing of threats, near-misses, and mistakes.
Demonstrate leader behaviors that build safety: modeling vulnerability, responding well to bad news, inviting dissent, focusing on learning, following through.
Distinguish candor from comfort and recognize how a single punitive response destroys safety.
NICE work roles
Information Systems Security Manager (OV-MGT-001)
Cyber Workforce Developer and Manager (OV-SPP-001)
Cyber Defense Analyst (PR-CDA-001)
Executive Cyber Leadership (OV-EXL-001)
NICE-aligned competencies
Knowledge of team dynamics and reporting culture as they affect security outcomes.
Ability to lead teams that surface problems early.
CAE-CD knowledge units
Security Program Management (SPM · Non-Technical Core)
Cybersecurity Ethics (CSE · Optional)
Cybersecurity Planning and Management (CPM · Non-Technical Core)
15
Module 15: Crisis Leadership & The Midnight Breach
Security Leadership
Learning outcomes — students will be able to
Describe what teams need from a leader during a crisis — direction, calm, decisions, protection, communication, care.
Apply the 70% rule and reversible/irreversible framing to incident decisions with incomplete information, and know when to escalate.
Document incident decisions (what, why, what was known) and conduct a learning-focused post-incident review.
NICE work roles
Cyber Defense Incident Responder (PR-CIR-001)
Information Systems Security Manager (OV-MGT-001)
Executive Cyber Leadership (OV-EXL-001)
Cyber Crime Investigator (IN-INV-001)
NICE-aligned competencies
Ability to lead incident response and make decisions under uncertainty and time pressure.
Skill in incident communication with executives and stakeholders.
Knowledge of post-incident review and lessons-learned processes.
CAE-CD knowledge units
Basic Cyber Operations (BCO · Optional)
Cyber Threats (CTH · Non-Technical Core)
Cybersecurity Planning and Management (CPM · Non-Technical Core)
Security Program Management (SPM · Non-Technical Core)
Crosswalk prepared for curriculum-committee review. NICE work roles are cited by name and 2017 role ID (NIST SP 800-181); competencies are expressed as NICE-style knowledge/skill/ability statements. Confirm alignment against the current NICE Framework revision and the CAE-CD Knowledge Unit list for your designation cycle.
Bring it to your program
Free for educators. Sign up with your institutional email and create your first course in minutes — or ask us to set up a cohort for your department.