Online
Live online training
Instructor-led sessions for distributed teams, combining discussion, practical cases and exercises. Timing and programme scope are agreed around your participants.
Discuss online trainingInformation security education · Emerging markets
Beyond awareness.
Information security education for leaders and teams in emerging markets. Live online training and in-person seminars, shaped around your organisation.
Explore primary sources
Training & seminars
Built for organisations in emerging markets. International frameworks meet your local operating context, with learning focused on the decisions your people need to make.
Online
Instructor-led sessions for distributed teams, combining discussion, practical cases and exercises. Timing and programme scope are agreed around your participants.
Discuss online trainingIn person
Facilitated learning for organisations and professional groups, with cases adapted to your sector and operating environment. Location and delivery are arranged with you.
Plan a seminarClear, non-theatrical learning for people who need to recognise risk, handle information responsibly and act under pressure.
Structured support for translating obligations and risk into usable policies, responsibilities and incident-ready practice.
Applied work on AI agents and public-source evidence for reviewing digital claims without removing human accountability.
Approach
Each programme is adapted to the organisation’s operating environment, applicable frameworks and audience. International reference material is connected with locally relevant cases and decisions.
Request a programme outlineAudience, country or region, sector, priorities and operating context.
Learning outcomes, cases, exercises and review criteria.
Facilitated analysis, realistic scenarios and documented limits.
Action points, evidence trail and agreed follow-up materials.
Reference environment
Programmes can be mapped to the organisation’s applicable legal and standards context. A framework is used as a reference point—not as a substitute for evidence, professional judgement or formal legal advice.
Bulgaria · Legislative record
Dates identify publication in the State Gazette. The 2026 link contains the amending act; read it together with the consolidated base before that amendment (PDF) (opens in a new tab).
Consolidated Cybersecurity Act · Ciela — includes later amendments, including State Gazette No. 55 of 16. June 2026. This is an updated reference, not a snapshot as at 13. February 2026.
Browse legislation: GDPR, NIS2 & related actsApplied research
A developing decision-support framework for examining organisational strategic sustainability through case evidence, incidents and internal and external variables.
Public communication describes the purpose and evidence logic only. Proprietary weights, thresholds, formulae and calibration are not disclosed.
SSi. is not presented as a measure of training effect, an automated verdict or a replacement for accountable human judgement.
Global resource directory
Explore 61 curated resources covering cybersecurity, governance, service management and high-performance computing. Find legislation, guidance, regional reports and data directly from their publishers.
61 resources across 8 collections. Expand a region to browse.
Global professional association
Governance, audit and risk resources, including COBIT, research and professional learning. Some materials require membership or purchase.
Global · vendor guide
A practical introduction to ITIL and IT service management, including incident, change and configuration management. Published by software provider Freshworks.
International standard
Information security management system requirements from ISO. The overview is public; the full standard is sold separately.
International practitioner community
Prioritised safeguards and implementation resources from the Center for Internet Security.
Global professional association
Research on cybersecurity workforce capacity, skills gaps, leadership and professional development.
Global research community
Cloud and AI security research, the Cloud Controls Matrix and assessment resources.
Global incident-response community
Incident-response cooperation, team directory and shared standards including CVSS and the Traffic Light Protocol.
Global application-security community
Open projects, guidance and educational resources for building and assessing application security.
Worldwide · 2024 edition
Country and regional assessments of cybersecurity commitments across legal, technical, organisational, capacity and cooperation measures.
Worldwide · e-Governance Academy
Country profiles and supporting evidence on national cybersecurity capacities. Check each profile’s assessment date and methodology.
Worldwide · Shadowserver Foundation
Explore observed internet exposures and malicious activity by country and network. Coverage reflects Shadowserver’s measurement systems.
Worldwide · vulnerability data
Download daily vulnerability exploitation-probability estimates and access the EPSS API. Predictions are distinct from confirmed exploitation.
Bulgaria · Bulgarian
Original act published in State Gazette No. 94 on 13. November 2018. A historical starting point; later amendments must be read separately.
Bulgaria · Bulgarian
Amending act published in State Gazette No. 17 on 13. February 2026, introducing the NIS2 framework into Bulgarian law. This publication contains amendments, not a consolidated text.
Bulgaria · Bulgarian
Original ordinance adopted by Decree No. 186 of 19. July 2019, published on 26. July 2019. Minimum network and information security requirements; read alongside applicable amendments.
European Union · multilingual
Regulation (EU) 2016/679: lawful processing, data-subject rights, accountability, security, breach response and international transfers of personal data.
Bulgaria · Bulgarian
National provisions complementing GDPR, published by Bulgaria’s Commission for Personal Data Protection. Read together with the EU regulation.
European Union · multilingual
Directive (EU) 2022/2555: cybersecurity risk management, incident reporting and supervision. Coverage depends on sector, entity characteristics and national implementation.
European Union · multilingual
Implementing Regulation (EU) 2024/2690: technical risk-management measures and significant-incident criteria for specified digital infrastructure, digital and trust-service providers.
European Union · financial sector
Regulation (EU) 2022/2554: ICT risk management, incident reporting, resilience testing and third-party risk for covered financial entities, with oversight of designated critical ICT providers.
European Union · digital products
Regulation (EU) 2024/2847: cybersecurity requirements for products with digital elements, including vulnerability handling and lifecycle obligations. Application is phased.
European Union · official summary
Official summary linking to Regulation (EU) 2024/1689: AI literacy, risk-based requirements, transparency and human oversight. Scope and application dates vary by provision.
European Union · critical entities
Directive (EU) 2022/2557: all-hazards risk assessment, resilience and continuity for covered critical entities. Complements cybersecurity measures through national implementation.
European Union · official summary
Official overview of the European Digital Identity framework, digital identity wallets and trust services. Regulation (EU) 2024/1183 amends the eIDAS framework in Regulation (EU) 910/2014.
European Union
EU Agency for Cybersecurity reports on threats, attacker trends, affected sectors and mitigation measures.
European Union institutions
Security advisories and threat reporting from the cybersecurity service for EU institutions, bodies, offices and agencies.
United Kingdom
Practical security guidance, advisories and resources for organisations and individuals.
Germany · English resource
An introduction to the IT-Grundschutz information security approach from Germany’s Federal Office for Information Security.
France · French and selected English reports
Official alerts, vulnerability notices, incident analyses and threat reports from France’s national and governmental CERT.
Bulgaria · Bulgarian resources
National computer-security incident response, alerts and practical security information.
European Union · multilingual
Official summary with links to the legislation on ENISA and the European cybersecurity certification framework.
Asia-Pacific regional network
Regional incident-response cooperation, exercises and annual reports from member teams across Asia-Pacific.
Japan · English reports
Periodic reports on incidents handled by JPCERT/CC. Use the reporting period and incident definitions when interpreting totals.
India
India’s national computer emergency response team: security advisories, vulnerability notes and incident-response information.
Singapore
Singapore Cyber Landscape reports and guidance on organisational, AI and infrastructure security.
Republic of Korea · English portal
Cybersecurity publications, capacity-building materials and software supply-chain guidance from the Korea Internet & Security Agency.
China · Chinese portal
National incident-response information, security notices and cybersecurity reporting from China’s coordination centre.
Hong Kong
Security alerts, bulletins and threat information from the Hong Kong Computer Emergency Response Team Coordination Centre.
Pan-African network
Regional collaboration, incident-response coordination and capacity building for African security teams.
Kenya
National cybersecurity reporting from the Communications Authority of Kenya, with quarterly threat statistics and trends.
Ghana
National cybersecurity guidance, public alerts and information on the authority’s regulatory and capacity-building activities.
Morocco · French resource
Morocco’s official centre for monitoring, detecting and coordinating responses to computer-security incidents.
Rwanda
National cybersecurity strategy, security directives and policy documents from Rwanda’s National Cyber Security Authority.
South Africa
Research capabilities in information security, cybersecurity and digital identity from South Africa’s Council for Scientific and Industrial Research.
Africa · regional reporting
Regional cyberthreat assessments and law-enforcement capacity work through the African Joint Operation against Cybercrime initiative.
African Union · multilingual
Official treaty text and status list for the convention on cybersecurity and personal data protection.
Saudi Arabia · English resource
Essential Cybersecurity Controls and implementation guidance published by the National Cybersecurity Authority.
Qatar · English portal
Publications from Qatar’s National Cyber Security Agency, including cybersecurity policy and guidance materials.
United States · government programme
The High Performance Computing Modernization Program: supercomputing, research networks, scientific software and user guidance. Some services require authorised access.
United States · used internationally
CSF 2.0, quick-start guides, profiles, mappings and translations for managing organisational cybersecurity risk.
United States · global software coverage
Searchable vulnerability records and supporting data for vulnerability assessment and management.
United States · global software coverage
A catalog of vulnerabilities with evidence of exploitation, used to support remediation prioritisation.
United States · global knowledge base
Documented adversary tactics and techniques, with mitigations and structured knowledge for defensive analysis.
Canada · English and French
National cyberthreat assessments, security alerts and practical guidance from Canada’s cyber security authority.
Brazil · Portuguese
Public statistics on incident reports, phishing, exposed services and observed malicious traffic. Series have different collection methods.
Americas · Latin America and Caribbean
Regional cybersecurity capacity building, policy support, cooperation and resources from the Organization of American States.
Uruguay · Spanish
National incident-response guidance, security notices and publications from Uruguay’s CERT.
Australia
Official alerts, security guidance and resources for government, organisations, businesses and individuals.
Australia · defensive framework
Mitigation strategies and supporting maturity guidance for reducing exposure to common cyber threats.
New Zealand
Quarterly cyber security insights, annual threat reports, alerts and organisational guidance.
Pacific island countries and territories
Pacific operational cooperation, learning materials and links to national cybersecurity teams across the region.
No matching resources. Try a broader term or clear the filters.
Data coverage, reporting periods and methods differ between publishers. Check the original methodology before comparing countries or incident totals. This directory links to external resources; it does not provide a live data feed.
Open sources. Verifiable findings.
A practical introduction to responsible research, verification and the tools that support it.
OSINT is the structured collection, verification and analysis of publicly available information to answer a specific question. Sources may include official registers, publications, maps and publicly accessible websites. “Open source” describes the information sources; it does not mean every tool is free or open-source software.
Public access is not unlimited permission to reuse information. Where GDPR applies, establish a lawful basis, collect only necessary personal data, keep it accurate and secure, and set a retention period. Assess transparency duties and any applicable exceptions.
Use sources you may lawfully access. Respect licences, copyright and platform terms. Do not bypass access controls or use stolen credentials. Active testing requires prior authorisation and an agreed scope. Before sharing findings, remove unnecessary personal data and assess potential harm.
This is general educational guidance, not legal advice or permission for a particular investigation. Applicable rules depend on the jurisdiction, data and purpose; seek qualified advice when the legal basis is unclear.
European Commission: GDPR principles (opens in a new tab)These are reference examples, not a ranking, advertisement or claim of institutional approval. “Official” refers to the linked developer or provider page, not an official recommendation. Check current availability, licence terms and service limits with each provider.
Free and paid plans; provider limits apply.
Visual link analysis across datasets. Useful for organising relationships and documenting research leads; check the provenance and lawful use of every connected data source.
Official developer / provider (opens in a new tab)Free open-source software; some external APIs may charge.
Automates collection and correlation from multiple sources. Review modules before use: some interact with target systems. Use passive sources for open-source research and obtain authorisation before active testing.
Official developer / provider (opens in a new tab)Free plugin; external services have their own terms.
Supports image and video verification through keyframes, reverse-image searches and metadata inspection. Results require context and independent confirmation.
Official developer / provider (opens in a new tab)Desktop edition; check current provider terms.
Compare terrain and historical imagery to assess location and changes over time. Check imagery dates and attribution requirements before drawing conclusions or publishing.
Official developer / provider (opens in a new tab)Free and open-source software.
Analyse geographic data and compare map layers. Useful for spatial context; verify the accuracy, date and licence of each dataset separately.
Official developer / provider (opens in a new tab)For further discovery, Bellingcat maintains an investigation toolkit. Its inclusion here does not mean Bellingcat endorses this site or every example above.
Bellingcat: Online Investigation Toolkit (opens in a new tab)Selected reading
15 books to deepen your understanding before and after a workshop. Choose a topic and a level that match your experience.
The books and external materials listed here are provided solely as reading and self-study guidance, not as advertising. ISE. and Aasfor Group do not sell, resell or advertise these books or materials in any form, have no involvement in their sale and do not act as sales intermediaries.
Descriptions and suggested learning uses are our editorial selection. Titles remain in their original language. The listed editions are references, not necessarily the latest; check current standards and software documentation alongside them.
Foundation
2nd edition · 2023
Connect threat trends with security investment decisions. Useful for leadership discussions on priorities and risk.
Learning focus: Governance and readiness
Official book page (opens in a new tab)Advanced
2nd edition · 2021
Explore the operational constraints of industrial systems. Use alongside current standards when discussing critical infrastructure resilience.
Learning focus: Governance and readiness
Official book page (opens in a new tab)Advanced
1st edition · 2023
A sector-specific view of secure development and vehicle risk. Supports discussions of engineering responsibilities and supplier assurance.
Learning focus: Governance and readiness
Official book page (opens in a new tab)Intermediate
1st edition · 2022
Follow the intelligence cycle from requirements to reporting. Useful for OSINT source assessment and turning observations into defensible conclusions.
Learning focus: Verification research
Official book page (opens in a new tab)Intermediate
1st edition · 2022
Connect intelligence with investigation priorities. Supports exercises on choosing relevant evidence during an incident.
Learning focus: Verification research
Official book page (opens in a new tab)Intermediate
2nd edition · 2022
Build disciplined evidence collection and documentation habits. A useful bridge between technical findings and a reviewable investigation.
Learning focus: Verification research
Official book page (opens in a new tab)Advanced
3rd edition · 2023
Practise examining memory and network evidence in a controlled lab. Best for learners already comfortable with Linux.
Learning focus: Verification research
Official book page (opens in a new tab)Intermediate
3rd edition · 2022
Connect incident preparation, investigation and response. Useful for designing team scenarios and reviewing the evidence behind decisions.
Learning focus: Risk and incident scenarios
Official book page (opens in a new tab)Intermediate
1st edition · 2022
Compare defensive measures across systems and infrastructure. Supports practical conversations about layered protection and control selection.
Learning focus: Risk and incident scenarios
Official book page (opens in a new tab)Advanced
1st edition · 2021
Develop a structured approach to malware triage. Use for specialist defensive analysis in an isolated training environment.
Learning focus: Risk and incident scenarios
Official book page (opens in a new tab)Foundation
5th edition · 2024
A broad reference for core security concepts. Start here to build shared vocabulary before specialised workshops.
Learning focus: Information security education
Official book page (opens in a new tab)Advanced
1st edition · 2010
Understand why secure cryptographic design depends on implementation choices. A conceptual reference to pair with current algorithm guidance.
Learning focus: Information security education
Official book page (opens in a new tab)Intermediate
2nd edition · 2022
Learn to interpret network traffic rather than guess at its meaning. Useful preparation for packet-analysis exercises.
Learning focus: Information security education
Official book page (opens in a new tab)Intermediate
3rd edition · 2023
Translate security principles into Linux administration tasks. Supports workshops on access controls and system hardening.
Learning focus: Information security education
Official book page (opens in a new tab)Advanced
1st edition · 2023
Understand web application weaknesses from a tester’s perspective. Use in authorised labs to connect findings with defensive improvements.
Learning focus: Information security education
Official book page (opens in a new tab)Any purchases, payments and access arrangements are solely between the reader and the external publisher, author or supplier. This catalogue does not host or distribute book files.
About
Aasfor Group brings an international perspective to information security education, responsible governance and applied research, with a focus on emerging markets.
Aasfor Limited was registered in Paddington, London, on .
Through ISE. | [ SSi. ], we connect international frameworks and regional evidence with each organisation’s operating context. Programmes are shaped around local priorities, professional communities and the decisions leaders and teams need to make.
Training and advisory support are scoped for each engagement. They do not represent legal advice, an accredited audit or third-party certification unless this is expressly documented.
ISE. | [ SSi. ] creator, conceptual lead & researcher: Tony Aasfor · ORCID (opens in a new tab)
Contact
Tell us where your team operates, what they need to learn and whether you prefer online training or an in-person seminar. We’ll discuss the scope and delivery with you.
Programmes for organisations and professional groups in emerging markets.
Start with your priorities
Share your learning priorities and preferred format.