Workshops
2–3 November 2026 • Nairobi, KenyaFrom Certified Artificial Intelligence Professional with Remi Afon to DFIR in Action: From Evidence to Incident Report with Dr. Robinson Tombari Sibe to Building & Operating a Modern SOC: From Charter to Capability Roadmap with Marvin Ngoma, this year's workshops are not be missed
WORKSHOP 1Certified Artificial Intelligence Professionalwith Remi Afon, Founder of Lynsec (PECB Partner)
This 2-day intensive workshop provides a comprehensive, hands-on introduction to Artificial Intelligence (AI) and its practical applications in today's digital world. Participants will gain a solid understanding of AI concepts, machine learning fundamentals, generative AI technologies, and real-world implementation strategies. Designed for professionals, students, and technology enthusiasts, the workshop focuses on practical skills, industry use cases, and responsible AI adoption.
Overview
The workshop begins with the foundations of Artificial Intelligence, exploring key concepts, terminology, and the evolution of AI technologies. Participants will then dive into machine learning principles, data-driven decision-making, generative AI tools, prompt engineering, and AI-powered business solutions. Throughout the program, attendees will engage in interactive exercises, demonstrations, and hands-on activities that reinforce learning and build confidence in applying AI tools effectively.
By the end of the workshop, participants will understand how AI systems work, identify opportunities for AI adoption within their organizations, leverage modern AI platforms to improve productivity, and apply best practices for ethical and responsible AI usage. Each day combines theory with practical application, ensuring participants leave with actionable knowledge and skills they can immediately use in their careers and businesses.
Introduction
This workshop will cover the core principles, technologies, and practices that drive modern Artificial Intelligence (AI). You will learn how AI systems are designed, developed, and deployed, while gaining practical knowledge in machine learning, deep learning, natural language processing (NLP), computer vision, robotics, AI governance, and risk management.
Throughout the workshop, you will explore real-world AI applications, participate in practical exercises, and work through hands-on demonstrations designed to reinforce key concepts. You will gain exposure to industry-relevant tools, methodologies, and frameworks used to build intelligent systems and support data-driven decision-making. In addition, you will receive resources and guidance to continue developing your AI expertise beyond the training.
These interactive sessions are designed to strengthen your understanding of AI technologies, improve your ability to identify and implement AI opportunities, and equip you with the skills needed to manage AI initiatives responsibly. The workshop encourages collaboration, discussion, and knowledge sharing, enabling participants to learn from both the instructor and fellow professionals from diverse backgrounds.
By the end of this workshop, you will understand the foundational and advanced concepts of Artificial Intelligence, be able to apply machine learning and deep learning techniques to real-world challenges, evaluate AI risks and ethical considerations, and align AI solutions with organizational objectives. This workshop is ideal for AI practitioners, data scientists, IT professionals, technology leaders, business decision-makers, and anyone seeking to build or advance a career in Artificial Intelligence.
Pre-requisites
A basic understanding of computer systems, data concepts, and information technology is recommended. Familiarity with programming, data analysis, or digital technologies can be beneficial but is not required. No prior experience in Artificial Intelligence or Machine Learning is necessary.
Who Is This Workshop For?
This workshop is designed for professionals and decision-makers who want to develop practical knowledge and skills in Artificial Intelligence and its business applications. It is particularly useful for:
- AI professionals involved in the development, deployment, or management of AI solutions
- Data scientists and data analysts seeking to expand their expertise in machine learning and deep learning
- IT managers and technology leaders overseeing AI initiatives and digital transformation projects
- Software developers and engineers interested in integrating AI into applications and business processes
- Risk, compliance, and governance professionals responsible for managing AI-related risks and regulatory requirements
- Business executives, including CIOs, CTOs, CEOs, and COOs, involved in AI strategy and decision-making
- Project managers leading AI implementation and innovation initiatives
- Aspiring AI practitioners and technology enthusiasts looking to build or advance a career in Artificial Intelligence
What Will You Learn?
By completing this workshop, you will gain a practical understanding of Artificial Intelligence concepts, technologies, and implementation strategies, enabling you to confidently apply AI solutions in professional and organizational settings.
You will learn:
- The foundational concepts, principles, and real-world applications of Artificial Intelligence
- How to analyze, prepare, and visualize data to support AI-driven decision-making
- The fundamentals of machine learning, including supervised and unsupervised learning techniques
- How deep learning models, neural networks, and advanced AI architectures are used to solve complex problems
- The principles and applications of Natural Language Processing (NLP), Large Language Models (LLMs), and generative AI technologies
- How computer vision and robotics systems enable intelligent automation and advanced decision-making
- Strategies for identifying, managing, and mitigating AI-related risks, privacy concerns, and compliance requirements
- Best practices for implementing ethical AI, governance frameworks, and AI strategies aligned with organizational goals
Business/Organization Benefits
Organizations that invest in AI capabilities gain a competitive advantage through improved efficiency, innovation, and data-driven decision-making.
This workshop will help your organization:
- Accelerate digital transformation initiatives through the effective adoption of Artificial Intelligence
- Improve operational efficiency and productivity by leveraging AI-powered automation and intelligent systems
- Enable better business decisions through data analysis, predictive insights, and machine learning applications
- Identify and manage AI-related risks while ensuring compliance with ethical, privacy, and regulatory requirements
- Develop internal AI expertise to reduce reliance on external resources and consultants
- Align AI initiatives with strategic business objectives to maximize value and return on investment
- Foster innovation by identifying new opportunities for AI-driven products, services, and process improvements
- Establish a strong foundation for responsible, scalable, and sustainable AI implementation across the organization
Requirements
A basic understanding of computer systems, information technology, and digital tools is recommended. No prior experience in Artificial Intelligence or Machine Learning is required.
For the best learning experience, participants are encouraged to use their own laptop to participate in hands-on exercises, demonstrations, and practical activities throughout the workshop. Individuals without suitable hardware can follow along using the instructor's live demonstration environment and guided examples.
General Information
- Certification and examination fees are included in the price of the training course
- An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
- Candidates who have completed the training course but failed the exam are eligible to retake it once for free within a 12-month period from the initial date of the exam.
Trainer Profile
Remi Afon is a cybersecurity and artificial intelligence security professional, certified trainer and Founder of Lynsec, a PECB Partner. He specialises in AI security, responsible AI governance, cloud security, DevSecOps, application security and secure digital transformation.
Remi holds a BSc in Computer Science and an MSc in Information Security, complemented by specialist training in Artificial Intelligence for Cyber Security from the University of Oxford. His professional certifications include Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Cloud Security Automation Certification (GCSA), Certified Artificial Intelligence Professional, Certified ISO42001 and ISO27001 Lead Implementer and Certified Ethical Hacker (CEH). He is also a PECB Certified Trainer and EC Council Certified Trainer.
Through Lynsec, Remi delivers professional training in artificial intelligence, AI governance and cybersecurity, including the PECB Certified Artificial Intelligence Professional – CAIP®, ISO/IEC 42001 Artificial Intelligence Management Systems and ISO/IEC 27001 Information Security Management Systems programmes.
At ACDF 2026, Remi will lead the PECB/Lynsec CAIP® Intensive Training, combining academic knowledge, professional certification and practical industry experience to help participants understand AI technologies, manage emerging risks and support the secure, ethical and responsible adoption of artificial intelligence.
Workshop Itinerary
Day 1 [MORNING]:
Foundations of Artificial Intelligence and Data Analysis
We begin by exploring the fundamentals of Artificial Intelligence, its evolution, and its impact across industries. You will learn the core principles of AI, understand how data drives intelligent systems, and gain practical insights into data analysis and visualization techniques.
- Welcome and workshop overview
- Introduction to Artificial Intelligence: Concepts, history, and applications
- AI terminology, types, and key technologies
- The role of data in AI systems
- Fundamentals of data analysis and interpretation
- Data visualization techniques for AI projects
- Hands-on: Exploring datasets and creating meaningful visualizations
DAY 1 [AFTERNOON]:
Machine Learning Fundamentals
Day two focuses on machine learning, the foundation of modern AI systems. You will learn how machines learn from data, explore different learning approaches, and understand the complete machine learning workflow.
- Introduction to Data Science and Machine Learning
- Understanding the machine learning lifecycle
- Data preparation and feature engineering
- Supervised learning concepts and algorithms
- Unsupervised learning concepts and applications
- Model evaluation and performance measurement
- Advanced machine learning concepts and business applications
- Hands-on: Building and evaluating a basic machine learning model
DAY 2 [MORNING]:
Deep Learning and Natural Language Processing (NLP)
This day introduces advanced AI techniques that power modern intelligent applications. You will learn how deep learning architectures work and how AI systems understand, process, and generate human language.
- Introduction to Deep Learning and Neural Networks
- Deep learning architectures and applications
- Fundamentals of Natural Language Processing (NLP)
- Text processing and language understanding
- Transformers and Large Language Models (LLMs)
- Generative AI and modern NLP applications
- Future trends in NLP and AI-powered communication
- Hands-on: Working with NLP tools and generative AI models
Day 2 [Afternoon]:
Computer Vision, Robotics, AI Governance, and Risk Management
Day four explores specialized AI domains and the strategic considerations required for responsible AI adoption. You will learn how AI interprets visual data, powers autonomous systems, and operates within governance and ethical frameworks.
- Computer Vision fundamentals and applications
- Image recognition, object detection, and visual intelligence
- Introduction to Robotics and AI-driven automation
- Generative AI models and specialized architectures
- AI security considerations and emerging threats
- AI ethics, bias, fairness, and transparency
- AI governance frameworks and organizational strategy
- AI risk management, privacy, and regulatory compliance
- Hands-on: Evaluating AI risks and developing governance strategies
- Examination guidance and best practices

Remi Afon
CISSP | CISM | CEH | PECB Certified Trainer | EC Council Certified Trainer | GIAC Cloud Security Automation Certification (GCSA) | SANS Gen AI & LLL Application Security
Lynsec
DATES2–3 Nov 2026
VENUEHyatt Place, WestlandsNAIROBI, KENYA
WORKSHOP COSTUSD 1,250PER DELEGATE


WORKSHOP 2DFIR in Action: From Evidence to Incident Reportwith Dr. Robinson Tombari Sibe, CEO & Lead Forensic Examiner, Digital Footprints Nigeria Limited
Africa’s cybersecurity community has made significant strides in threat detection and monitoring. Yet detection without investigation is an incomplete defence. When an incident occurs, the ability to determine what happened, how far the attacker moved, what was taken, and who was responsible — and to prove it — is what separates organisations that recover cleanly from those that remain exposed. That capability is digital forensics.
Overview
DFIR in Action: From Evidence to Incident Report is a two-day, hands-on workshop that delivers the complete Digital Forensics and Incident Response practitioner lifecycle — from the moment an alert fires to the moment a forensically sound report reaches the CISO’s desk. Participants will master each core forensic discipline in sequence: live acquisition, disk examination, memory forensics, log analysis, and network forensics. Crucially, every skill is taught in the context of an active incident, using real tools and real workflows, so participants learn not just what to do but when to do it, in what order, and why it matters.
The workshop is divided into two phases. Phase 1 is a facilitated skills build. The facilitator teaches each forensic discipline, demonstrates it live, then immediately places every participant in a structured hands-on exercise on the same evidence. Phase 2 is built around a multi-layerd cyber incident, in which participants will use the skillset gotten in Phase 1 to respond to. They produce a forensic report and brief the room.
Target Audience
This workshop is designed for practitioners who need to build or consolidate digital forensics skills in a hands-on environment. It suits those new to forensics as much as those who have used individual tools but have never integrated them into a complete IR workflow.
- Incident Responders & SOC Analysts
- Digital Forensics Practitioners
- Law Enforcement Cybercrime Units
- National CERTs & CSIRTs
- Military & Intelligence Cyber Units
- Financial Sector Security Teams
- IT Security Engineers Moving into DFIR
Workshop Structure
Day 1 — 2 November 2026
- Participant orientation, tool verification, and introduction to the two-phase workshop structure
- Module 1: Evidence acquisition — order of volatility, live vs. dead acquisition, disk imaging with hash verification, RAM capture, and chain of custody documentation
- Module 2: Disk and artefact forensics — Windows registry, prefetch data, LNK files, and browser history examined hands-on using Autopsy and supporting tools
- Module 3: Log analysis and timeline construction — Windows Event Log triage using Chainsaw, proxy log analysis, and building a corroborated attack timeline from multiple sources
- Module 4: Memory forensics — Volatility 3 from first principles, covering process listing, network connections, code injection detection, credential exposure, and command-line reconstruction
Day 2 Morning — 3 November 2026
- Module 5: Network forensics — PCAP analysis in Wireshark, C2 beacon identification, exfiltration detection, and lateral movement tracing in network logs
- Phase 1 synthesis: facilitator-led session connecting all five modules into a single end-to-end investigation workflow
- Scenario brief: Case dossier distributed, investigation rules explained
- Independent investigation: participants work through all five evidence types — disk artefacts, event logs, PowerShell transcripts, memory evidence, and network captures — without investigative guidance
- Forensic report writing: participants produce a complete report covering executive summary, timeline, key findings, TTPs, and recommendations
- Findings briefings: each participant delivers a two-minute verbal summary to the room
- Full debrief, scenario solution revealed, and certificates issued
Learning Outcomes
By the end of DFIR Foundations, every participant will be able to:
- Evidence Acquisition: Execute a structured first-responder triage workflow; acquire forensically sound disk images and RAM captures with hash verification and compliant chain of custody documentation.
- Disk Forensics: Conduct a structured examination of a Windows logical evidence set: recover deleted files, extract registry artefacts, prefetch data, LNK files, and browser history.
- Log Analysis: Triage Windows Event Logs and proxy logs using Chainsaw and manual analysis to identify authentication events, PowerShell activity, log clearing, and lateral movement.
- Timeline Building: Construct a chronological, corroborated attack timeline from multiple evidence sources, with each event linked to a specific named artefact or log entry.
- Memory Forensics: Deploy Volatility 3 against a RAM capture: identify malicious processes, injected code, active network connections, and credentials exposed in memory.
- Network Forensics: Analyse a PCAP in Wireshark: identify C2 beacon patterns, data exfiltration events, and lateral movement in network traffic.
- Evidence Synthesis: Combine findings across all five evidence types into a single coherent investigation narrative with no evidentiary gaps.
- Forensic Reporting: Produce a structured, legally defensible forensic investigation report covering executive summary, scope, timeline, methodology, findings, TTPs, and recommendations
Minimum System Requirements
- Processor: 64-bit quad-core CPU, 2.0 GHz or higher (Intel Core i5/i7 or AMD Ryzen 5/7 recommended)
- RAM: 8 GB minimum; 16 GB strongly recommended
- Storage: 50 GB free disk space minimum (for VM image, evidence package, and tool outputs)
- USB: One USB 3.0 port (for evidence package and toolkit distribution)
- Operating System: Windows 10/11 (64-bit)
Dr. Robinson Tombari Sibe
Dr. Robinson Tombari Sibe is the CEO and Lead Forensic Examiner of Digital Footprints Limited, Nigeria’s foremost private digital forensics laboratory and cybersecurity consulting company, based in Abuja. He has over 2 decades of high impact consulting experience across several sectors. He holds Ph.D and Master of Science qualifications in Digital Forensics from the University of the Cumberlands (USA) and is completing an LLM in Cybercrime, Cybersecurity and International Law at the University for Peace/UNICRI. He also holds a Master of Engineering degree in Electronic/Telecommunication Engineering and a Bachelors degree in Computer Engineering.
Practitioner Credentials
- Active Lead Forensic Examiner with a caseload spanning financial fraud, cybercrime, insider threats, and complex corporate investigations across Nigeria and beyond.
- Forensic laboratory architect: designed forensic laboratories, SOPs and governance frameworks for the sovereign entities, agencies, academia, and corporate institutions.
- International capacity-building delivery in partnership with ICMPD, FCDO, the Commonwealth Secretariat, ECOWAS, and others. Facilitated high impact forensic and cybersecurity trainings across several countries.
- Consulted for Law Enforcement Agencies, Criminal Justice Department, Military Institutions, financial institutions, National CERTs, and multiple national cybercrime investigation.
Academic & Thought Leadership
- Respected scholar-practioner, with affiliations with several universities such as University of South Wales, United Kingdom (Visiting Fellow), Capitol Technology University, USA (Dissertation Chair), University of the Cumberlands, USA (PhD IT Advisory Board Member), Rivers State University (Lecturer), MIVA Open University (Professor of Practice), and National Open University of Nigeria (Industry Supervisor).
- Co-author: Cybercrime, Digital Forensic Readiness and Financial Crime Investigation in Nigeria (Springer Nature)
- Authored several Peer-reviewed publications in respected journals.
- Written several expert opinion articles across channels such as Forbes, Guardian, Business Day, and featured as cybercrime and digital forensic expert on BBC, Channels TV, and many other global broadcasting stations.
- Member of the Board of Africa ICT Alliance (AfICTA).
Industry Certifications
Dr. Sibe holds several industry certifications, some of which include:
- EC-Council Certified Chief Information Security Officer (CCISO)
- PECB ISO/IEC 42001 (Artificial Intelligence Management System) Senior Lead Implementer
- PECB Certified Lead Forensic Examiner (PECB, Canada)
- PECB Certified Chief Information Security Officer (CCISO) (PECB, Canada)
- PECB Lead Cybersecurity Manager (PECB, Canada)
- PECB Certified Trainer (PECB, Canada)
- Certified Cyber Crime Examiner – National White Collar Crime Center (NW3C), USA
- Certified Economic Crimes Forensic Examiner (CECFE) – NW3C Inc, USA.
- Cellebrite Certified Mobile Examiner (CCME)
- Cellebrite Certified Physical Analyst (CCPA)
- Cellebrite Certified Operator (CCO)
- Cellebrite Certified Mobile Fundamentals (CMFF)
- Belkasoft Certified Instructor (BelkaCI)
- Belkasoft Certified Examiner (BelkaCE)
- Mobile Device Investigator – ADF Solutions Inc, USA
- Mobile Communication and Cell Forensic Analyst – SecurCube, Italy

Dr. Robinson Tombari Sibe
CEO & Lead Forensic Examiner
Digital Footprints Nigeria
DATES2–3 Nov 2026
VENUEHyatt Place WestlandsNAIROBI, KENYA
WORKSHOP COSTUSD 1,250PER DELEGATE

Workshop Modules
Each module below follows the same three-step cycle: explain and demonstrate, guided practice, group debrief. All practice exercises use the Case scenario evidence package loaded on participant USB drives.
Module 1: IR Triage & Evidence Acquisition
The first hour of a DFIR engagement determines whether the investigation succeeds or fails. This module teaches the disciplined first-responder approach: what to collect, in what order, and how to document it so the evidence holds up.
- Order of volatility — from RAM and network connections down to archive and backup — and why it governs every acquisition decision
- Live vs. dead acquisition: the forensic trade-offs and how to document the decision
- FTK Imager: disk imaging with hash verification, demonstrated live from selection of source to completion
- WinPmem: RAM capture from a running system without contaminating the process list
- Chain of custody: completing a legally defensible seizure log and evidence manifest
Module 2: Disk & Artefact Forensics
Windows cannot help leaving forensic traces, even when an attacker tries to cover them. This module covers the artefacts that survive and what each one proves.
- Autopsy logical file ingestion: adding the workstation artefact folder as a Logical Files data source and navigating the result
- Browser forensics: Chrome’s History SQLite database — visits, downloads, and what timestamps prove. Live demo using the workshop evidence.
- Registry forensics: the Run key as a persistence mechanism. Live demo: identify the malicious entry in the .reg export.
- Prefetch analysis: what execution timestamps prove. Live demo: identify tools run for the first time on the incident date from the PECmd CSV.
- PowerShell transcripts: how script block logging captures the full attacker command sequence even when obfuscated
Module 3: Log Analysis & Timeline Construction
Logs are the story of what every account and process did across every system. But only if you know which events matter and how to combine them with artefacts into a timeline.
- Windows Event Log structure: the six key channels and the twelve Event IDs that matter most in DFIR
- Chainsaw: sigma-rule-based triage of large event log sets. Live demo: run Chainsaw against the Security log XML.
- PowerShell Operational log (Event ID 4104): script block logging as the investigator’s best friend
- Proxy log format: reading Apache/SQUID combined log, filtering by IP, identifying C2 beacon patterns
- Timeline construction: merging artefact and log timestamps into a single corroborated narrative. Every event needs a named source.
Module 4: Memory Forensics
RAM is the one source that captures what an attacker was doing inside legitimate processes — activity that leaves no trace on disk and is gone the moment a system powers off.
- Why RAM is irreplaceable: the classes of evidence that exist only in memory
- Volatility 3 from first principles: what it is, how plugins work, what each plugin answers
- pslist / windows.pstree: enumerate processes, identify suspicious parent-child relationships.
- netstat: every active network connection. Correlate to known IPs from log analysis. Live demo.
- malfind: detect process injection — the attacker’s technique for hiding in legitimate processes.
- hashdump: recover NTLM hashes. What this means for understanding credential exposure and lateral movement.
- cmdline: reconstruct the exact command line of every process, including attacker tools
Module 5: Network Forensics
Network traffic captures the attacker’s actions across the entire environment — not just the systems already examined. It answers what disk and memory cannot: what left the network, where it went, and how much.
- PCAP structure and Wireshark orientation: protocol hierarchy, conversation statistics, navigating large captures
- Display filters: isolating relevant traffic instantly with ip.addr, tcp.port, http filters
- C2 beacon identification: periodic callback intervals, unusual user agents, DNS-based channels
- Data exfiltration detection: large outbound POST requests, total bytes per conversation, staging server patterns
- Lateral movement in traffic: SMB authentication, PsExec signatures
- Following a TCP stream: reading the full client-server conversation
Module 6: Case Investigation
This is a realistic multi-layered cyber incident affecting the East African Federation Ministry of Finance — a fictional institution built on documented attack patterns from real African financial sector breaches. Participants must investigate it using only the evidence package and the skills from Modules 1-5.
- The evidence is deliberately layered: no single source tells the full story. Disk artefacts establish initial access. Logs reveal lateral movement. The PCAP answers what was stolen. Only by combining all five evidence types does the complete picture emerge.
- The attacker actively covered their tracks: the Security event log was partially cleared. Participants must work with incomplete evidence — exactly as in a real investigation.
- There is a plausible red herring in the proxy log: one IP initially looks suspicious but proves to be a legitimate cloud update service. Jumping to conclusions without corroboration costs time.
- The scenario has a satisfying resolution: when all five evidence types are correctly combined, the complete attack chain from phishing email to ransomware deployment and data exfiltration is fully reconstructable.
WORKSHOP 3Building & Operating a Modern SOC: From Charter to Capability Roadmapwith Marvin Ngoma, Cybersecurity Operations Expert, Committee of Experts Member, ACDF
This 2-day intensive workshop provides a comprehensive, practitioner-focused guide to planning, building, and operating a modern Security Operations Center (SOC). Participants will gain a solid understanding of SOC governance, detection engineering, triage and investigation workflows, incident response integration, and performance measurement. Designed for security leaders, SOC managers, analysts, and IT professionals, the workshop emphasizes practical frameworks, structured templates, and hands-on exercises that participants can immediately apply within their organizations.
Overview
The workshop begins with the strategic foundations of the SOC: its mission, governance structure, operating model, and telemetry collection strategy. Participants then move into the operational core of SOC work: threat-driven detection engineering, detection quality management, structured triage and investigation, and incident response integration. The program concludes with SOC resilience design, AI-augmented operations, performance metrics, and the development of a phased capability roadmap.
The program follows a lifecycle-driven model: Planning → Collection → Detection → Triage → Investigation → Response → Continuous Improvement — and is framework-driven, vendor-neutral, and tool-informed, exposing participants to widely adopted industry reference tools and structured templates.
By the end of the workshop, participants will have drafted a SOC charter, designed an escalation model, built a telemetry onboarding roadmap, mapped attack scenarios to detection logic, developed an incident response playbook, defined a SOC KPI framework, and consolidated these outputs into a phased 90-day and 12-month capability roadmap. Each day combines strategic guidance with practical application, ensuring participants leave with actionable artifacts they can immediately use in their organizations.
Introduction
This workshop will cover the core principles, methodologies, and practices required to establish or mature a Security Operations Center. You will learn how SOCs are governed, structured, and operated, while gaining practical knowledge in detection engineering lifecycle management, detections-as-code concepts, alert triage, hypothesis-driven investigation, incident response playbook design, and SOC performance measurement.
Throughout the workshop, you will work through guided exercises using structured templates; including SOC charter templates, RACI matrices, log source prioritization matrices, detection design worksheets, ATT&CK Navigator coverage mapping, playbook templates, and KPI dashboards. You will gain exposure to industry-relevant frameworks and reference tools used by mature security operations teams worldwide, and you will receive resources and guidance to continue developing your SOC capability beyond the training.
These interactive sessions are designed to strengthen your ability to align SOC operations with institutional priorities and regulatory requirements, improve detection quality and measurability, and design a SOC that is resilient against modern challenges, including encrypted traffic limitations, cloud and identity-centric attacks, AI-enabled threats, and attacks targeting SOC tooling itself. The workshop encourages collaboration, discussion, and knowledge sharing, enabling participants to learn from both the instructor and fellow professionals from diverse backgrounds.
By the end of this workshop, you will understand how to define a SOC mandate and governance model, prioritize telemetry collection, engineer and continuously improve detections, run structured investigations, integrate incident response, measure SOC performance, and plan a phased maturity roadmap. This workshop is ideal for CISOs, SOC managers, security analysts, detection engineers, incident responders, and IT leaders responsible for building or improving security operations capabilities.
Pre-requisities
A basic understanding of information security concepts, IT infrastructure, and networking fundamentals is recommended. Familiarity with security monitoring tools (such as SIEM platforms) or incident handling can be beneficial but is not required. No prior experience in building or managing a SOC is necessary.
Who Is This Workshop For?
This workshop is designed for professionals and decision-makers responsible for establishing, managing, or improving security operations capabilities. It is particularly useful for:
- CISOs and security leaders planning to establish or restructure a SOC
- SOC managers and team leads seeking to mature existing operations
- Security analysts (Tier 1–3) looking to strengthen triage and investigation practices
- Detection engineers and threat hunters developing structured detection programs
- Incident responders integrating response processes into SOC workflows
- IT managers and infrastructure leaders supporting security monitoring initiatives
- Risk, compliance, and governance professionals responsible for security monitoring obligations
- MSSP professionals and consultants delivering SOC services to clients
What Will You Learn?
By completing this workshop, you will gain a practical understanding of how to plan, build, and operate a measurable and resilient Security Operations Center aligned to organizational priorities.
You will learn:
- How to define a SOC mission, charter, governance structure, and tiered operating model
- How to design escalation workflows, severity classification, and role responsibilities
- How to build a detection-driven telemetry strategy with phased log onboarding priorities
- The detection engineering lifecycle — design, validation, deployment, tuning, and continuous improvement — including detections-as-code concepts
- How to classify, enrich, and tune alerts to systematically reduce false positives
- Structured triage and hypothesis-driven investigation methodologies with proper case documentation
- How to design incident response playbooks and integrate response into SOC workflows
- How to secure the SOC itself against modern threats, including attacks on monitoring infrastructure
- How to responsibly adopt AI-augmented and agentic workflows in SOC operations
- How to define SOC metrics (MTTD, MTTR, detection quality KPIs) and build a phased 90-day and 12-month capability roadmap
Business/Organization Benefits
Organizations that invest in structured SOC capabilities gain measurable improvements in threat detection, response speed, and operational resilience.
This workshop will help your organization:
- Establish or mature a SOC using proven, framework-driven approaches rather than costly trial and error
- Align security monitoring with regulatory obligations, risk priorities, and institutional mandates
- Improve detection quality and reduce alert fatigue through structured tuning and quality management
- Accelerate incident response with well-designed playbooks and clear escalation paths
- Demonstrate SOC value to executives through meaningful metrics and reporting frameworks
- Reduce dependency on external consultants by developing internal SOC design expertise
- Prepare for emerging challenges including cloud attacks, identity-centric threats, and AI-enabled adversaries
- Leave with reusable artifacts — charters, matrices, roadmaps, and playbooks tailored to your organization
Requirements
A basic understanding of information security and IT concepts is recommended. No prior SOC management experience is required.
For the best learning experience, participants are encouraged to bring their own laptop to work on the guided templates and exercises throughout the workshop. Individuals without suitable hardware can follow along using provided worksheets and the instructor's guided walkthroughs.
General Information
- Certificate of attendance is included in the price of the training course fees
- All workshop templates and frameworks are provided to participants for continued use after the training
Trainer Profile
Marvin Ngoma is a cybersecurity leader, author, and security evangelist. He specialises in security operations, detection engineering, threat detection and response, and the strategic design of Security Operations Center capabilities.
He holds a Master of Computer Science & Engineering from Chalmers University of Technology, a Masters of Science in Information Security from Luleå University of Technology, both in Sweden. He also holds a bachelor of Computer Science from the University of Zambia. His professional certifications include Certified Information Systems Security Professional (CISSP), GIAC Security Operations Manager Certification (GSOM), Elastic Certified SIEM Analyst, among others.
A seasoned consultant with experience spanning both the private and public sector in Europe, Middle East and Africa (EMEA), Marvin has led numerous engagements architecting and building security operations and intelligence capabilities for organizations, unifying tools, processes, and people into measurable, sustainable programmes. He works with organizations throughout EMEA on how best to create security value, bridging strategic governance requirements, including regulatory drivers such as PCI DSS, NIS2, etc, with hands-on operational detection and response practice.
Marvin is a regular speaker and educator in the international cybersecurity community. He has presented at conferences including the ACDF Forum, Nordic Cyber Summit, BSides events across Africa and Europe, among others. He is a published author, writing on threat intelligence integration, context-driven security, practical realities of generative AI in threat detection and response, analyst alert fatigue reduction, and large-scale cyber defense exercises such as NATO's Locked Shields, and has appeared on industry podcasts discussing AI in security operations.
At ACDF 2026, Marvin will lead the Building & Operating a Modern SOC: From Charter to Capability Roadmap workshop, combining strategic governance guidance with hands-on operational methodologies to help participants build sustainable, measurable, and resilient security operations capabilities.
Workshop Itinerary
Day 1 [MORNING]:
SOC Foundations — Mission, Governance, Operating Model & Telemetry Strategy
We begin with the strategic foundations of the SOC: its institutional mandate, governance structure, and daily operating model, followed by a detection-driven approach to telemetry collection.
- Welcome and workshop overview
- SOC mandate, institutional role, and constituency mapping
- Governance structure, steering committee, and regulatory monitoring alignment
- Tiered SOC structure, roles, responsibilities, and escalation workflows
- Detection-driven telemetry strategy and identity-first monitoring
- Log onboarding prioritization, data quality, and normalization
- Hands-on: Draft SOC mission and charter; design escalation matrix; build phased telemetry onboarding roadmap
DAY 1 [AFTERNOON]:
Threat-Driven Detection Engineering & Detection Quality
The afternoon focuses on the full detection lifecycle — from threat-informed design through validation, deployment, tuning, and continuous improvement.
- Threat-informed detection strategy and coverage modeling with ATT&CK Navigator
- Detection engineering lifecycle: design, validation, deployment, tuning, improvement
- Detections-as-code concepts: versioning, testing, auditability
- Threat intelligence as input to detection development and enrichment
- Alert classification (True Positive / False Positive / Benign Positive / Undetermined) and outcome tagging
- Detection tuning methodology and the continuous improvement loop
- Hands-on: Map an attack scenario to detection logic and telemetry requirements; alert classification and tuning simulation
DAY 2 [MORNING]:
Triage, Investigation & Incident Response Integration
Day two moves into the operational heart of the SOC: structured triage, hypothesis-driven investigation, and integrated incident response.
- Alert prioritization models and investigation methodology
- Hypothesis-driven analysis, structured decision-making, and case documentation standards
- Coordination with digital forensics and specialized investigation functions
- Incident response lifecycle: containment, eradication, recovery
- Playbook design principles and post-incident improvement cycle
- Hands-on: Investigation decision-tree walkthrough with case documentation; build a phishing or credential-compromise response playbook
Day 2 [Afternoon]:
Resilient & Future-Ready SOC — Metrics, AI Augmentation & Capability Roadmap
The final session addresses modern SOC challenges, AI-augmented operations, performance measurement, and consolidates all workshop outputs into a phased capability roadmap.
- Encrypted traffic visibility limitations; cloud and identity-centric attacks
- AI-enabled threats, attacks targeting SOC tooling, and monitoring the monitoring systems
- AI-assisted investigation, automation vs augmentation, and phased AI adoption
- SOC metrics: MTTD, MTTR, detection performance, analyst workload, executive KPIs
- Advanced capability expansion: threat hunting, threat intelligence, purple teaming, digital forensics
- Hands-on: Identify controls to secure SOC infrastructure; identify 3 safe AI augmentation opportunities; build SOC KPI framework and phased 90-day / 12-month capability roadmap
- Wrap-up: consolidating workshop artifacts and next steps

