Information security education · Emerging markets

ISE. | [ SSi. ] by Aasfor

Beyond awareness.

Information security education for leaders and teams in emerging markets. Live online training and in-person seminars, shaped around your organisation.

  • Practice-led
  • Evidence-first
  • Human-accountable
Discover ISE.
03Areas of expertise 61Curated resources 08Regional collections 04Verification layers

Explore primary sources

Training & seminars

Knowledge.
Into action.

Built for organisations in emerging markets. International frameworks meet your local operating context, with learning focused on the decisions your people need to make.

Online

Live online training

Instructor-led sessions for distributed teams, combining discussion, practical cases and exercises. Timing and programme scope are agreed around your participants.

Discuss online training

In person

In-person seminars

Facilitated learning for organisations and professional groups, with cases adapted to your sector and operating environment. Location and delivery are arranged with you.

Plan a seminar
01

Information security education

Clear, non-theatrical learning for people who need to recognise risk, handle information responsibly and act under pressure.

  • Cyber hygiene and human-factor risk
  • Electronic documents and data handling
  • Role-specific workshops and exercises
Discuss education
02

Governance and readiness

Structured support for translating obligations and risk into usable policies, responsibilities and incident-ready practice.

  • Policy and control mapping
  • Risk and incident scenarios
  • Awareness programme design
Discuss governance
03

Verification research

Applied work on AI agents and public-source evidence for reviewing digital claims without removing human accountability.

  • Provenance and claim mapping
  • Evidence checking and RAG
  • Decision support and risk marking
Discuss research
For leaders and teams
  • Business & leadership teams
  • Public-sector organisations
  • Education & research
  • Professional communities

Approach

Real context.
Real decisions.

Each programme is adapted to the organisation’s operating environment, applicable frameworks and audience. International reference material is connected with locally relevant cases and decisions.

Request a programme outline
  1. 01

    Frame the context

    Audience, country or region, sector, priorities and operating context.

  2. 02

    Design the intervention

    Learning outcomes, cases, exercises and review criteria.

  3. 03

    Work through practice

    Facilitated analysis, realistic scenarios and documented limits.

  4. 04

    Support the next decision

    Action points, evidence trail and agreed follow-up materials.

Reference environment

A stronger
foundation.

Programmes can be mapped to the organisation’s applicable legal and standards context. A framework is used as a reference point—not as a substitute for evidence, professional judgement or formal legal advice.

ISE. | [ SSi. ] by Aasfor

Applied research

Strategic
Stability iNDEX.

A developing decision-support framework for examining organisational strategic sustainability through case evidence, incidents and internal and external variables.

Public communication describes the purpose and evidence logic only. Proprietary weights, thresholds, formulae and calibration are not disclosed.

Scope note

SSi. is not presented as a measure of training effect, an automated verdict or a replacement for accountable human judgement.

Global resource directory

Global
intelligence.

Explore 61 curated resources covering cybersecurity, governance, service management and high-performance computing. Find legislation, guidance, regional reports and data directly from their publishers.

61 resources · 8 regional collections · Reviewed

61 resources across 8 collections. Expand a region to browse.

Global & international12 resources
  • Global professional association

    ISACA (opens in a new tab)

    Governance, audit and risk resources, including COBIT, research and professional learning. Some materials require membership or purchase.

    • Standards & guidance
    • Reports & research
    • Learning & networks
    Explore ISACA resources (opens in a new tab)
  • Global · vendor guide

    Freshworks: ITIL guide (opens in a new tab)

    A practical introduction to ITIL and IT service management, including incident, change and configuration management. Published by software provider Freshworks.

    • Standards & guidance
    • Learning & networks
    freshworks.com
  • International standard

    ISO/IEC 27001 (opens in a new tab)

    Information security management system requirements from ISO. The overview is public; the full standard is sold separately.

    • Standards & guidance
    iso.org
  • International practitioner community

    CIS Controls (opens in a new tab)

    Prioritised safeguards and implementation resources from the Center for Internet Security.

    • Standards & guidance
    cisecurity.org
  • Global professional association

    ISC2 research (opens in a new tab)

    Research on cybersecurity workforce capacity, skills gaps, leadership and professional development.

    • Reports & research
    • Learning & networks
    isc2.org
  • Global research community

    Cloud Security Alliance (opens in a new tab)

    Cloud and AI security research, the Cloud Controls Matrix and assessment resources.

    • Standards & guidance
    • Reports & research
    cloudsecurityalliance.org
  • Global incident-response community

    FIRST (opens in a new tab)

    Incident-response cooperation, team directory and shared standards including CVSS and the Traffic Light Protocol.

    • Learning & networks
    • Alerts & response
    first.org
  • Global application-security community

    OWASP (opens in a new tab)

    Open projects, guidance and educational resources for building and assessing application security.

    • Standards & guidance
    • Learning & networks
    owasp.org
  • Worldwide · 2024 edition

    ITU Global Cybersecurity Index (opens in a new tab)

    Country and regional assessments of cybersecurity commitments across legal, technical, organisational, capacity and cooperation measures.

    • Data & indices
    • Reports & research
    itu.int
  • Worldwide · e-Governance Academy

    National Cyber Security Index (opens in a new tab)

    Country profiles and supporting evidence on national cybersecurity capacities. Check each profile’s assessment date and methodology.

    • Data & indices
    ncsi.ega.ee
  • Worldwide · Shadowserver Foundation

    Shadowserver Dashboard (opens in a new tab)

    Explore observed internet exposures and malicious activity by country and network. Coverage reflects Shadowserver’s measurement systems.

    • Data & indices
    dashboard.shadowserver.org
  • Worldwide · vulnerability data

    FIRST EPSS data (opens in a new tab)

    Download daily vulnerability exploitation-probability estimates and access the EPSS API. Predictions are distinct from confirmed exploitation.

    • Data & indices
    first.org
Europe19 resources
  • Bulgaria · Bulgarian

    Bulgarian Cybersecurity Act · original ЗКС (opens in a new tab)

    Original act published in State Gazette No. 94 on 13. November 2018. A historical starting point; later amendments must be read separately.

    • Legislation
    dv.parliament.bg
  • Bulgaria · Bulgarian

    Bulgarian Cybersecurity Act · 2026 amendment (opens in a new tab)

    Amending act published in State Gazette No. 17 on 13. February 2026, introducing the NIS2 framework into Bulgarian law. This publication contains amendments, not a consolidated text.

    • Legislation
    dv.parliament.bg
  • Bulgaria · Bulgarian

    Bulgarian minimum security requirements (opens in a new tab)

    Original ordinance adopted by Decree No. 186 of 19. July 2019, published on 26. July 2019. Minimum network and information security requirements; read alongside applicable amendments.

    • Legislation
    dv.parliament.bg
  • European Union · multilingual

    GDPR · General Data Protection Regulation (opens in a new tab)

    Regulation (EU) 2016/679: lawful processing, data-subject rights, accountability, security, breach response and international transfers of personal data.

    • Legislation
    eur-lex.europa.eu
  • Bulgaria · Bulgarian

    Bulgarian Personal Data Protection Act · ЗЗЛД (opens in a new tab)

    National provisions complementing GDPR, published by Bulgaria’s Commission for Personal Data Protection. Read together with the EU regulation.

    • Legislation
    cpdp.bg
  • European Union · multilingual

    NIS2 · Network and Information Security (opens in a new tab)

    Directive (EU) 2022/2555: cybersecurity risk management, incident reporting and supervision. Coverage depends on sector, entity characteristics and national implementation.

    • Legislation
    eur-lex.europa.eu
  • European Union · multilingual

    NIS2 · implementing requirements (opens in a new tab)

    Implementing Regulation (EU) 2024/2690: technical risk-management measures and significant-incident criteria for specified digital infrastructure, digital and trust-service providers.

    • Legislation
    eur-lex.europa.eu
  • European Union · financial sector

    DORA · Digital Operational Resilience Act (opens in a new tab)

    Regulation (EU) 2022/2554: ICT risk management, incident reporting, resilience testing and third-party risk for covered financial entities, with oversight of designated critical ICT providers.

    • Legislation
    eur-lex.europa.eu
  • European Union · digital products

    CRA · Cyber Resilience Act (opens in a new tab)

    Regulation (EU) 2024/2847: cybersecurity requirements for products with digital elements, including vulnerability handling and lifecycle obligations. Application is phased.

    • Legislation
    eur-lex.europa.eu
  • European Union · official summary

    AI Act · artificial intelligence rules (opens in a new tab)

    Official summary linking to Regulation (EU) 2024/1689: AI literacy, risk-based requirements, transparency and human oversight. Scope and application dates vary by provision.

    • Legislation
    eur-lex.europa.eu
  • European Union · critical entities

    CER · Critical Entities Resilience (opens in a new tab)

    Directive (EU) 2022/2557: all-hazards risk assessment, resilience and continuity for covered critical entities. Complements cybersecurity measures through national implementation.

    • Legislation
    eur-lex.europa.eu
  • European Union · official summary

    eIDAS · European Digital Identity (opens in a new tab)

    Official overview of the European Digital Identity framework, digital identity wallets and trust services. Regulation (EU) 2024/1183 amends the eIDAS framework in Regulation (EU) 910/2014.

    • Legislation
    eur-lex.europa.eu
  • European Union

    ENISA Threat Landscape (opens in a new tab)

    EU Agency for Cybersecurity reports on threats, attacker trends, affected sectors and mitigation measures.

    • Reports & research
    enisa.europa.eu
  • European Union institutions

    CERT-EU (opens in a new tab)

    Security advisories and threat reporting from the cybersecurity service for EU institutions, bodies, offices and agencies.

    • Alerts & response
    • Reports & research
    cert.europa.eu
  • United Kingdom

    NCSC UK (opens in a new tab)

    Practical security guidance, advisories and resources for organisations and individuals.

    • Alerts & response
    • Standards & guidance
    ncsc.gov.uk
  • Germany · English resource

    BSI IT-Grundschutz course (opens in a new tab)

    An introduction to the IT-Grundschutz information security approach from Germany’s Federal Office for Information Security.

    • Standards & guidance
    • Learning & networks
    bsi.bund.de
  • France · French and selected English reports

    ANSSI / CERT-FR (opens in a new tab)

    Official alerts, vulnerability notices, incident analyses and threat reports from France’s national and governmental CERT.

    • Alerts & response
    • Reports & research
    cert.ssi.gouv.fr
  • Bulgaria · Bulgarian resources

    CERT Bulgaria (opens in a new tab)

    National computer-security incident response, alerts and practical security information.

    • Alerts & response
    govcert.bg
  • European Union · multilingual

    EUR-Lex: EU Cybersecurity Act (opens in a new tab)

    Official summary with links to the legislation on ENISA and the European cybersecurity certification framework.

    • Legislation
    • Standards & guidance
    eur-lex.europa.eu
Asia7 resources
  • Asia-Pacific regional network

    APCERT (opens in a new tab)

    Regional incident-response cooperation, exercises and annual reports from member teams across Asia-Pacific.

    • Alerts & response
    • Reports & research
    • Learning & networks
    apcert.org
  • Japan · English reports

    JPCERT/CC quarterly reports (opens in a new tab)

    Periodic reports on incidents handled by JPCERT/CC. Use the reporting period and incident definitions when interpreting totals.

    • Reports & research
    • Data & indices
    jpcert.or.jp
  • India

    CERT-In (opens in a new tab)

    India’s national computer emergency response team: security advisories, vulnerability notes and incident-response information.

    • Alerts & response
    cert-in.org.in
  • Singapore

    CSA Singapore publications (opens in a new tab)

    Singapore Cyber Landscape reports and guidance on organisational, AI and infrastructure security.

    • Reports & research
    • Standards & guidance
    csa.gov.sg
  • Republic of Korea · English portal

    KISA (opens in a new tab)

    Cybersecurity publications, capacity-building materials and software supply-chain guidance from the Korea Internet & Security Agency.

    • Reports & research
    • Standards & guidance
    • Learning & networks
    kisa.or.kr
  • China · Chinese portal

    CNCERT/CC (opens in a new tab)

    National incident-response information, security notices and cybersecurity reporting from China’s coordination centre.

    • Alerts & response
    • Reports & research
    cert.org.cn
  • Hong Kong

    HKCERT (opens in a new tab)

    Security alerts, bulletins and threat information from the Hong Kong Computer Emergency Response Team Coordination Centre.

    • Alerts & response
    • Reports & research
    hkcert.org
Africa8 resources
Middle East2 resources
North America6 resources
  • United States · government programme

    HPC.mil — HPCMP (opens in a new tab)

    The High Performance Computing Modernization Program: supercomputing, research networks, scientific software and user guidance. Some services require authorised access.

    • Standards & guidance
    • Learning & networks
    hpc.mil
  • United States · used internationally

    NIST Cybersecurity Framework (opens in a new tab)

    CSF 2.0, quick-start guides, profiles, mappings and translations for managing organisational cybersecurity risk.

    • Standards & guidance
    nist.gov
  • United States · global software coverage

    NIST National Vulnerability Database (opens in a new tab)

    Searchable vulnerability records and supporting data for vulnerability assessment and management.

    • Data & indices
    • Alerts & response
    nvd.nist.gov
  • United States · global software coverage

    CISA Known Exploited Vulnerabilities (opens in a new tab)

    A catalog of vulnerabilities with evidence of exploitation, used to support remediation prioritisation.

    • Data & indices
    • Alerts & response
    cisa.gov
  • United States · global knowledge base

    MITRE ATT&CK (opens in a new tab)

    Documented adversary tactics and techniques, with mitigations and structured knowledge for defensive analysis.

    • Data & indices
    • Standards & guidance
    attack.mitre.org
  • Canada · English and French

    Canadian Centre for Cyber Security (opens in a new tab)

    National cyberthreat assessments, security alerts and practical guidance from Canada’s cyber security authority.

    • Alerts & response
    • Reports & research
    • Standards & guidance
    cyber.gc.ca
Latin America & Caribbean3 resources
  • Brazil · Portuguese

    CERT.br statistics (opens in a new tab)

    Public statistics on incident reports, phishing, exposed services and observed malicious traffic. Series have different collection methods.

    • Data & indices
    • Reports & research
    stats.cert.br
  • Americas · Latin America and Caribbean

    OAS cybersecurity programme (opens in a new tab)

    Regional cybersecurity capacity building, policy support, cooperation and resources from the Organization of American States.

    • Standards & guidance
    • Learning & networks
    oas.org
  • Uruguay · Spanish

    CERTuy (opens in a new tab)

    National incident-response guidance, security notices and publications from Uruguay’s CERT.

    • Alerts & response
    • Reports & research
    gub.uy
Oceania & Pacific4 resources
  • Australia

    ASD Australian Cyber Security Centre (opens in a new tab)

    Official alerts, security guidance and resources for government, organisations, businesses and individuals.

    • Alerts & response
    • Standards & guidance
    cyber.gov.au
  • Australia · defensive framework

    ASD Essential Eight (opens in a new tab)

    Mitigation strategies and supporting maturity guidance for reducing exposure to common cyber threats.

    • Standards & guidance
    cyber.gov.au
  • New Zealand

    NCSC New Zealand (opens in a new tab)

    Quarterly cyber security insights, annual threat reports, alerts and organisational guidance.

    • Reports & research
    • Alerts & response
    • Data & indices
    ncsc.govt.nz
  • Pacific island countries and territories

    PaCSON (opens in a new tab)

    Pacific operational cooperation, learning materials and links to national cybersecurity teams across the region.

    • Alerts & response
    • Learning & networks
    pacson.org

Data coverage, reporting periods and methods differ between publishers. Check the original methodology before comparing countries or incident totals. This directory links to external resources; it does not provide a live data feed.

Further reading & Aasfor Group

Open sources. Verifiable findings.

OSINT — Open-source intelligence

A practical introduction to responsible research, verification and the tools that support it.

OSINT is the structured collection, verification and analysis of publicly available information to answer a specific question. Sources may include official registers, publications, maps and publicly accessible websites. “Open source” describes the information sources; it does not mean every tool is free or open-source software.

ISE. and Aasfor Group neither sell nor advertise these tools or materials in any form and do not act as sales intermediaries. Links are provided solely for information and independent research. Any purchase or subscription is arranged directly with the external provider.

Lawful and transparent use

Define the purpose and legal basis

Public access is not unlimited permission to reuse information. Where GDPR applies, establish a lawful basis, collect only necessary personal data, keep it accurate and secure, and set a retention period. Assess transparency duties and any applicable exceptions.

Respect access and publication boundaries

Use sources you may lawfully access. Respect licences, copyright and platform terms. Do not bypass access controls or use stolen credentials. Active testing requires prior authorisation and an agreed scope. Before sharing findings, remove unnecessary personal data and assess potential harm.

This is general educational guidance, not legal advice or permission for a particular investigation. Applicable rules depend on the jurisdiction, data and purpose; seek qualified advice when the legal basis is unclear.

European Commission: GDPR principles (opens in a new tab)

A repeatable verification process

  1. Define a question, purpose and permitted scope before collecting data.
  2. Record the original source, URL, access date and relevant context. Preserve material only where permitted.
  3. Cross-check independent sources; examine dates, location and whether images or claims have been reused.
  4. Separate confirmed facts, assumptions and unresolved questions. A tool result is a lead, not proof.
  5. Document your reasoning and limitations. Share only what is necessary and review retention.
Berkeley Protocol: investigation methodology (opens in a new tab)

Tools and official provider links

These are reference examples, not a ranking, advertisement or claim of institutional approval. “Official” refers to the linked developer or provider page, not an official recommendation. Check current availability, licence terms and service limits with each provider.

Maltego Graph

Free and paid plans; provider limits apply.

Visual link analysis across datasets. Useful for organising relationships and documenting research leads; check the provenance and lawful use of every connected data source.

Official developer / provider (opens in a new tab)

SpiderFoot

Free open-source software; some external APIs may charge.

Automates collection and correlation from multiple sources. Review modules before use: some interact with target systems. Use passive sources for open-source research and obtain authorisation before active testing.

Official developer / provider (opens in a new tab)

InVID Verification Plugin

Free plugin; external services have their own terms.

Supports image and video verification through keyframes, reverse-image searches and metadata inspection. Results require context and independent confirmation.

Official developer / provider (opens in a new tab)

Google Earth Pro

Desktop edition; check current provider terms.

Compare terrain and historical imagery to assess location and changes over time. Check imagery dates and attribution requirements before drawing conclusions or publishing.

Official developer / provider (opens in a new tab)

For further discovery, Bellingcat maintains an investigation toolkit. Its inclusion here does not mean Bellingcat endorses this site or every example above.

Bellingcat: Online Investigation Toolkit (opens in a new tab)

Selected reading

Reading Library

15 books to deepen your understanding before and after a workshop. Choose a topic and a level that match your experience.

The books and external materials listed here are provided solely as reading and self-study guidance, not as advertising. ISE. and Aasfor Group do not sell, resell or advertise these books or materials in any form, have no involvement in their sale and do not act as sales intermediaries.

Descriptions and suggested learning uses are our editorial selection. Titles remain in their original language. The listed editions are references, not necessarily the latest; check current standards and software documentation alongside them.

Security governance3

Foundation

Cybersecurity Threats, Malware Trends, and Strategies

Tim Rains

2nd edition · 2023

Connect threat trends with security investment decisions. Useful for leadership discussions on priorities and risk.

Learning focus: Governance and readiness

Official book page (opens in a new tab)

Advanced

Industrial Cybersecurity

Pascal Ackerman

2nd edition · 2021

Explore the operational constraints of industrial systems. Use alongside current standards when discussing critical infrastructure resilience.

Learning focus: Governance and readiness

Official book page (opens in a new tab)

Advanced

Automotive Cybersecurity Engineering Handbook

Dr. Ahmad MK Nasser

1st edition · 2023

A sector-specific view of secure development and vehicle risk. Supports discussions of engineering responsibilities and supplier assurance.

Learning focus: Governance and readiness

Official book page (opens in a new tab)
OSINT and evidence4

Intermediate

Mastering Cyber Intelligence

Jean Nestor M. Dahj

1st edition · 2022

Follow the intelligence cycle from requirements to reporting. Useful for OSINT source assessment and turning observations into defensible conclusions.

Learning focus: Verification research

Official book page (opens in a new tab)

Intermediate

Incident Response with Threat Intelligence

Roberto Martinez

1st edition · 2022

Connect intelligence with investigation priorities. Supports exercises on choosing relevant evidence during an incident.

Learning focus: Verification research

Official book page (opens in a new tab)

Intermediate

Learn Computer Forensics

William Oettinger

2nd edition · 2022

Build disciplined evidence collection and documentation habits. A useful bridge between technical findings and a reviewable investigation.

Learning focus: Verification research

Official book page (opens in a new tab)

Advanced

Digital Forensics with Kali Linux

Shiva V. N. Parasram

3rd edition · 2023

Practise examining memory and network evidence in a controlled lab. Best for learners already comfortable with Linux.

Learning focus: Verification research

Official book page (opens in a new tab)
Cyber risk and response3

Intermediate

Digital Forensics and Incident Response

Gerard Johansen

3rd edition · 2022

Connect incident preparation, investigation and response. Useful for designing team scenarios and reviewing the evidence behind decisions.

Learning focus: Risk and incident scenarios

Official book page (opens in a new tab)

Intermediate

Mastering Defensive Security

Cesar Bravo

1st edition · 2022

Compare defensive measures across systems and infrastructure. Supports practical conversations about layered protection and control selection.

Learning focus: Risk and incident scenarios

Official book page (opens in a new tab)

Advanced

Malware Analysis Techniques

Dylan Barker

1st edition · 2021

Develop a structured approach to malware triage. Use for specialist defensive analysis in an isolated training environment.

Learning focus: Risk and incident scenarios

Official book page (opens in a new tab)
Technical foundations5

Foundation

Computer Security: Principles and Practice, Global Edition

William Stallings; Lawrie Brown

5th edition · 2024

A broad reference for core security concepts. Start here to build shared vocabulary before specialised workshops.

Learning focus: Information security education

Official book page (opens in a new tab)

Advanced

Cryptography Engineering

Niels Ferguson; Bruce Schneier; Tadayoshi Kohno

1st edition · 2010

Understand why secure cryptographic design depends on implementation choices. A conceptual reference to pair with current algorithm guidance.

Learning focus: Information security education

Official book page (opens in a new tab)

Intermediate

Learn Wireshark

Lisa Bock

2nd edition · 2022

Learn to interpret network traffic rather than guess at its meaning. Useful preparation for packet-analysis exercises.

Learning focus: Information security education

Official book page (opens in a new tab)

Intermediate

Mastering Linux Security and Hardening

Donald A. Tevault

3rd edition · 2023

Translate security principles into Linux administration tasks. Supports workshops on access controls and system hardening.

Learning focus: Information security education

Official book page (opens in a new tab)

Advanced

Attacking and Exploiting Modern Web Applications

Simone Onofri; Donato Onofri

1st edition · 2023

Understand web application weaknesses from a tester’s perspective. Use in authorised labs to connect findings with defensive improvements.

Learning focus: Information security education

Official book page (opens in a new tab)

Any purchases, payments and access arrangements are solely between the reader and the external publisher, author or supplier. This catalogue does not host or distribute book files.

About

Aasfor
Group.

Aasfor Group brings an international perspective to information security education, responsible governance and applied research, with a focus on emerging markets.

Aasfor Limited was registered in Paddington, London, on .

Through ISE. | [ SSi. ], we connect international frameworks and regional evidence with each organisation’s operating context. Programmes are shaped around local priorities, professional communities and the decisions leaders and teams need to make.

Clear professional boundaries

Training and advisory support are scoped for each engagement. They do not represent legal advice, an accredited audit or third-party certification unless this is expressly documented.

ISE. | [ SSi. ] creator, conceptual lead & researcher: Tony Aasfor · ORCID (opens in a new tab)

Contact

Make your
next move.

Tell us where your team operates, what they need to learn and whether you prefer online training or an in-person seminar. We’ll discuss the scope and delivery with you.

Connect to AASFOR

Programmes for organisations and professional groups in emerging markets.

Delivery and programme scope by arrangement.

Start with your priorities

Enquire about training.

Share your learning priorities and preferred format.

All fields are required. Your details are used to respond to your enquiry. Privacy notice.