Questions, answered plainly
Including the uncomfortable ones. If something you need is not here, ask us directly — we would rather answer it than have you guess.
Getting started
No prior security experience is required for the Foundation programs. You do need basic comfort with computers and a rough idea of what an IP address and a port are — we cover the rest. Practitioner and Advanced programs assume either our Foundation material or equivalent hands-on experience, and the consultation exists to work out honestly which of those applies to you.
Often, yes — several of the strongest analysts we have worked with came from non-technical backgrounds. What matters is whether you enjoy pulling a problem apart and can commit consistently. What we will not do is pretend it is quick. Expect several months of sustained work, and expect the early part to feel steep. If the consultation suggests you need groundwork first, we will tell you that rather than enrol you.
Forty-five minutes with a mentor, not a sales call. We look at your background, what you can already do, the roles you are targeting and the time you realistically have. You leave with a written recommendation — which sometimes says that a different program, or a few months of preparation first, would serve you better.
If you are new to security, SOC Analyst Foundation, almost always. If you already triage alerts at work, Threat Detection & Incident Response is the right entry point. If your organisation has moved to cloud and you own part of that estate, Cloud Security Foundation. The Learning Paths page sequences these around a target role.
Programs & curriculum
A certification course is built backwards from an exam blueprint. Ours is built backwards from what an analyst does in a working week. The practical difference is where your time goes: most of your hours here are spent investigating cases and writing up the results for review, rather than covering objectives. Certification overlap is listed on each program page, but it is a by-product rather than the goal.
Four: SOC Analyst Foundation, Threat Detection & Incident Response, Cloud Security Foundation and Cloud Security Advanced. They are deliberately few. Each one is built around a specific transition in a security career, and we would rather run four programs properly than twelve badly.
Yes, on completion — but we are deliberately unenthusiastic about it. What gets you hired is the portfolio of documented investigations you finish with and your ability to reason aloud through an alert. We spend our effort there.
Cloud identity and cloud telemetry appear from the Foundation programs onward, because that is where the systems and the attacks are. Cloud Security Foundation and Cloud Security Advanced go deep across Azure and AWS. AI security is covered in Cloud Security Advanced, alongside applying AI assistance to investigation work in Threat Detection & Incident Response.
Every module ends in assessed, written work built on realistic case material — partial evidence, background noise and decisions that have consequences. Your write-ups are reviewed line by line by a practitioner and returned with comments. The specifics of the practical setup are covered on the consultation call, since they vary by program and cohort.
Time & format
Yes — most of our students do. Live sessions run on weekday evenings and weekends, and every session is recorded. The one thing that does not work is trying to compress it: the reviewed write-ups take the time they take. We will talk through what the schedule looks like for your cohort on the consultation call.
Live, in small cohorts, with recordings available afterwards. The live session is where you get questioned on your reasoning, which is the part that produces the improvement — recordings are a backup for when life happens, not the product.
Recordings cover missed sessions, and office hours run regularly for catching up. If you fall behind significantly you can defer to the next cohort once at no cost. We would rather you finish a cohort late than finish it badly.
Capped, deliberately. Reviewing written investigations line by line does not scale, and it is the highest-value thing we do, so we limit enrolment rather than dilute it.
Fees & enrolment
Fees vary by program and by whether you enrol in a single program or a full Learning Path, and paths are priced below the sum of their parts. We share current fees during the consultation alongside a recommendation, so you are pricing the right program rather than the catalogue. Instalment options are available.
Instalment plans are available on all programs. We also hold a limited number of partial scholarships each cohort for students facing genuine financial constraints — raise it in the consultation and we will explain the process.
If you withdraw within the first two weeks of a cohort, you receive a full refund. After that, refunds are considered case by case. The full policy is published on its own page rather than buried in terms.
Careers & outcomes
No, and we would be cautious of anyone who does. Placement depends on the market, your location, your interview performance and factors outside anyone's control. What we are accountable for is capability: that you finish able to investigate properly, with documented work to show and interview practice behind you. We publish completion rates rather than placement rates for that reason.
Most commonly SOC Analyst (Tier 1), Security Analyst and Information Security Analyst for those starting out. Students with existing IT experience often move into Tier 2, detection engineering or cloud security roles. The Career Roadmaps page breaks down the skills, day-to-day work and market context for each.
Portfolio review, resume and LinkedIn rebuild, mock interviews with practitioners who hire, and written feedback on your answers and delivery. It is a scheduled part of the curriculum, not an upsell. Alumni keep community access and office hours afterwards.
Threat Detection & Incident Response and Cloud Security Advanced are built for you — detection engineering, incident leadership, cloud architecture and AI workload security. Students at this level typically join for a specific capability gap rather than a full path, and the consultation is the fastest way to work out which one.
Still unsure?
Email connectbluelayersacademy@gmail.com or book a consultation — no obligation.
Talk to someone who has done the job
Book a consultation and leave with a written plan mapped to your background and the roles you are targeting — whether or not you enrol.
Prefer email? connectbluelayersacademy@gmail.com
What the call actually is
- 45 minutes, with a mentor rather than a sales team
- A written recommendation you keep either way
- An honest answer if a program is not right for you yet
We do not guarantee placement, and we will say so on the call. What we are accountable for is whether you finish able to do the work.
