We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SigmAcademy · Role-based paths

Role-Based Security Learning Paths

Generic security training fails because the developer, the finance officer and the administrator face different threats and controls. Role-based paths teach each person the security their actual job touches — which is also exactly what auditors mean by "appropriate to role".

Why role-based beats one-size

Engineers need secure coding and secrets handling; operations needs hardening and change discipline; everyone needs phishing resistance — one course serves nobody well.

How SigmAcademy structures it

Learning paths assigned by role, built the way engagements actually run — the scenarios come from real assessment and audit practice, not stock content.

Progress you can evidence

Completion and assessment tracking per person and role — the artefact ISO 27001 A.6.3, SOC 2 CC1/CC2 and PCI 12.6 sampling asks for.

Keeping it current

Paths evolve with the threat and regulatory landscape the practice works in daily — training content with the same currency discipline as our published research.

FAQ

Which roles are covered?

Paths are organised around the roles compliance frameworks care about — technical, operational and general staff — and tailored at onboarding to your org structure.

Does completion satisfy PCI 12.6 / ISO A.6.3?

Those controls require awareness appropriate to role with records; role-based paths plus completion tracking produce exactly that evidence. The control owner remains you.

Can we add company-specific content?

Programmes are tailored during onboarding so your policies and incidents can be reflected in the paths.

Assessments & labs

See SigmAcademy on your environment

Scoped to your stack in one conversation — with the CyberSigma practice behind the platform.