Training and certification

Build your expertise in vulnerability management and the Cyberwatch platform. Two complementary paths to understand the industry, master the software, and certify your skills.

Software training

Cyberwatch User Program (CUP)

Software training

User Program Certification

By the end of this one-day training course, participants will be able to configure Cyberwatch, scan their assets, analyze results, define a prioritization strategy, deploy security patches, verify asset compliance, and keep their environment up to date.

The training focuses on practical use cases and hands-on interface experience.

duration

1 day

Format

In-person or remote

Detailed program

1

Introduction, overview, and getting started

  • Introduction to Cyberwatch and its architecture
  • Application terminology: assets, scan policies, connectors
  • Positioning Cyberwatch within a security ecosystem
  • Exploring the interface and menus
2

Vulnerability management

  • Overview of CVE, CPE, and CVSS standards
  • Vulnerability lifecycle and disclosure process
3

 Assets Module

  • Asset management and overview of the different sections
  • Asset discovery and bulk imports
  • Projects and groups
4

Vulnerability Module

  • Understanding critical scope and priority CVEs in Cyberwatch
  • Security vulnerabilities and results analysis
  • Detailed page overview: dashboard, inventory, asset details, filtered views
  • Automated actions (analysis policies, deployments, exclusions, criticality levels)
  • Custom reports
5

Compliance Management

  • Major market frameworks (CIS, ANSSI) and Anglo-Saxon vs. French comparison
  • Standard included frameworks and dashboard widget
  • Compliance metrics: inventory, asset profile, compliance tab
  • Add or edit a framework for an asset
  • Encyclopedia of rules, frameworks, and custom policies
6

Administration Module

  • Overview and configurations (SMTP, proxy, identity provider)
  • Connector management and user creation
  • Nodes, integrations, and alerts
  • Logs and monitoring
7

 Closing

  • Application updates (Docker, core, application)
  • Overview of documentation and API access
  • Overview of the certification test
  • Q&A

Badge

Cyberwatch Partner Certification (CPC)

Administration and Deployment Training

Partner Certification

This certification training is designed for administrators and engineers responsible for deploying, advanced configuration, and integrating Cyberwatch into their infrastructure.

duration

2 days + exam (4 hours)

Format

In-person or remote

Certification

Cyberwatch Partner Certification

Detailed program

1

Day 1 — Deployment

  • Installing Docker on various operating systems (including offline mode)
  • Deploying Cyberwatch in standalone, master/satellite, and offline modes
  • Deploying a Docker scanner for Cyberwatch
1

Day 2 — API, integrations, and customization

  • Consume the Cyberwatch API using Python libraries and the CLI
  • Air-gapped mode: CMDB connection and offline operation
  • Connect Cyberwatch to a third-party system via native integrations
  • Create custom analytics, compliance rules, and reports
  • Create automated alerts

Certification objectives

Learn how to deploy Cyberwatch autonomously

Learn how to use the Cyberwatch API with Python

Learn how to connect Cyberwatch with a third-party system

Learn how to customize Cyberwatch (scans, compliance, dashboards)

Certification exam

Deploy Cyberwatch on an Ubuntu instance

Scan 3 machines (CentOS, Debian, Ubuntu) in agent-based mode

Install and use the Cyberwatch Python API client

Define a custom criticality and assign it to a machine

Propose a remediation action plan

Testimonials

The platform centralizes both our PCI compliance for online billing operations and our broader IT vulnerability management, which simplifies our security oversight.

CISO, energy

CISO

Quarterly ASV scans and the supplementary pentest provide us with a comprehensive view of our PCI DSS compliance, with reports that are directly actionable for our QSA auditors.

Payment Security Manager, Finance

Payment Security Manager

Hardening our configurations according to CIS Benchmarks allowed us to close entry points we hadn't even considered, all without interrupting our production.

Systems Administrator, industry

Systems and Network Administrator

Continuous auditing of our Active Directory revealed several poorly managed privileged accounts, which we were able to remediate quickly.

CISO, healthcare

CISO

Pouvoir déployer une console complète isolée d'Internet, avec mise à jour manuelle de la base de vulnérabilités, était un prérequis pour certains de nos environnements les plus critiques.

Exemple à remplacer — Responsable sécurité, secteur public

Responsable sécurité des systèmes d'information

Le mode air-gap totalement déconnecté correspond exactement à nos exigences de sécurité pour les systèmes les plus sensibles, sans compromis sur la qualité de la détection.

Exemple à remplacer — Responsable SSI, défense

Responsable de la sécurité des systèmes d'information

Le suivi de notre conformité NIS2 est désormais centralisé et actualisé en continu, ce qui simplifie considérablement nos rapports aux autorités compétentes.

Exemple à remplacer — RSSI, énergie

RSSI

La génération automatisée de preuves d'audit nous fait gagner un temps précieux lors de nos revues de conformité DORA et de nos échanges avec nos auditeurs.

Exemple à remplacer — Responsable conformité, finance

Responsable conformité

La formation Cyberwatch Certified Professional a permis à nos équipes de monter en compétence rapidement et d'exploiter pleinement les fonctionnalités de remédiation de la plateforme.

Exemple à remplacer — Responsable IT, industrie

Responsable infrastructure IT

Le patch management intégré et les tickets générés automatiquement dans notre outil ITSM ont nettement réduit nos délais de correction.

Exemple à remplacer — DSI, secteur public

DSI

Avec des centaines de dispositifs médicaux à surveiller, la priorisation par criticité métier nous permet de ne pas nous disperser tout en respectant la continuité des soins.

Exemple à remplacer — RSSI, santé

RSSI

Le scoring contextuel nous aide à concentrer nos équipes sur les vulnérabilités qui présentent un risque réel pour nos installations, plutôt que de traiter des milliers de CVE sans distinction.

Exemple à remplacer — Responsable cybersécurité, énergie

Responsable cybersécurité

Pouvoir cartographier nos environnements sensibles sans connexion réseau permanente était une exigence non négociable. Cyberwatch répond à cette contrainte tout en gardant un inventaire à jour.

Exemple à remplacer — Officier sécurité, défense

Officier de sécurité des systèmes d'information

La cartographie automatique de nos actifs nous a permis de découvrir des serveurs oubliés que nos audits précédents n'avaient jamais identifiés. C'est un vrai gain de visibilité sur notre Shadow IT.

Exemple à remplacer — Responsable sécurité, finance

Responsable sécurité IT

L'accompagnement de l'équipe Cyberwatch a été déterminant pour déployer la plateforme sur nos sites de production sans perturber nos lignes. Le support dédié répond vite et comprend nos contraintes industrielles.

Exemple à remplacer — DSI, industrie

DSI

Avec Cyberwatch, nous avons enfin une vue exhaustive de notre parc informatique et pouvons prioriser nos actions de remédiation selon un risque réel plutôt qu'une simple liste de CVE. La plateforme s'intègre bien à nos contraintes de souveraineté.

Exemple à remplacer — RSSI, secteur public

RSSI