module four
Cybersecurity and operational resilience.
Six sub-modules, fifty minutes. Assumes Modules 2 and 3.
Funding narrative — Q2
v14
Program delivery — reporting period two
A. Point — confirm the allocation figure
Records/Funding
Locked for review — version history retained

what it covers
Defending what you hold.
The four routes that actually cause loss, least-privilege access, backup and restore testing, and the notification clock after an incident. Six sub-modules, ending in a posture assessment and an incident procedure scoped to your own systems. What is at risk is membership records, health information, land claims material and language.
01
Rank the holdings by consequence
The threat routes that apply to the organization, and its holdings ordered by the consequence of losing them.
02
Apply least privilege
Current rights measured against a least-privilege standard, and the places where decision rights are bundled.
03
Set the recovery objectives
How much work the organization can afford to lose and how long it can be down, stated for three critical systems.
04
Write the incident procedure
Roles, escalation triggers and notification obligations, with the timeline each one carries.
the sub-modules
Sub-modules.
Each one stands alone: a cold open on a real document, five to eight minutes of teaching, one activity on your own material, and five graded items.
Access architecture and controls
Least privilege, role-based access, and separating the authority to revise a record from the authority to certify or publish it.
Backup, recovery and continuity
Three-two-one in practice, immutable copies, and the restore test almost everyone skips.
continued
Sub-modules, continued.
The last three sub-modules cover what arrives through contracts, what insurers require, and what stays with the Nation regardless.
Allocations FY2026
Sheet 1
Programme
Budget
Committed
Housing
412,000
388,140
Lands & Resources
260,500
191,220
Health services
305,000
305,000
Education
178,400
96,850
Total
1,155,900
981,210
Figures drawn from live records — no re-entry

Detection, response and notification
Who holds the authority to declare an incident, and the notification timelines that follow from it.
Third-party and supply-chain obligations
The security requirements that reach you through contracts, and what you should require of your own suppliers.
Cyber insurance and residual risk
The control preconditions insurers require, read as the de facto standard they have become.
The module artifact
A Security Posture Assessment and an Incident Response Procedure, both scoped to the organization’s real systems.
the take away
What the learner keeps.
Every sub-module ends in a downloadable written to be usable by someone who has not taken the course.
Posture assessment
The organization measured against a defined control set, scoped to its actual systems and staffing.
module artifact
Incident procedure
Who declares an incident, who is called, and what has to be notified within what window.
take away
Module credential
Sub-modules are individually completable and individually badged, and all ten modules make the credential.
badged
next step
Take this module on its own.
Modules are bought singly and the introduction is free. All ten make the credential.