English for Special Purposes

Cybersecurity English

A cybersecurity English curriculum for incident response, vulnerability triage, identity, threat modeling, risk communication, compliance, executive briefings, and security pushback.

  • 8 modules
  • 32 field terms
  • Interactive practice

Printable Curriculum

Download the full materials

Web Practice Lab

Practice the decisions, not only the vocabulary

Use the activities below to rehearse how a professional in this field clarifies risk, pushes back, and turns pressure into a concrete next step.

Module Focus

    Scenario Coach

    Respond under pressure

    Jargon Flashcard

    Pushback Builder

    Build a four-step response

    Dialogue Coach

    Model line

    Language notes

      Progress

      Practice checklist

      0 of 4 complete

      Student PDF in Web Form

      Module map

      Open Participant Workbook PDF
      1

      Security Triage and Alert Investigation

      Move from noisy alerts to risk-based investigation.

      SIEM, alert, false positive, privileged account

      2

      Incident Response and Containment

      Communicate urgency without speculation.

      incident, containment, ransomware, forensics

      3

      Vulnerability Management

      Prioritize vulnerabilities beyond CVSS alone.

      CVE, CVSS, exploitability, compensating control

      4

      Identity, Access, and Least Privilege

      Push back on excessive access requests.

      IAM, least privilege, MFA, RBAC

      5

      Threat Modeling and Secure Design

      Discuss security risk early in design.

      threat model, attack surface, trust boundary, abuse case

      6

      Governance, Risk, and Compliance

      Translate control gaps into business risk.

      control, audit evidence, risk acceptance, remediation

      7

      Security Awareness and Phishing

      Coach users without shaming them.

      phishing, social engineering, reporting culture, security awareness

      8

      Executive Risk Briefings

      Explain cyber risk in decision language.

      residual risk, threat actor, maturity, investment ask

      More EFSP Tracks

      Related pages