Intrusion Detection and Incident Response
Author(s): William Greg McCulley
Edition: 1
Copyright: 2026
Pages: 284
PMP For Cyber: A Guide for Cyberspace and IT Operators by William Greg McCulley bridges the gap between project management principles and the fast-paced world of cybersecurity and IT operations. Whether you're a cyber or IT professional looking to formalize your project management skills, or a student building a career at the intersection of technology and leadership, this book delivers practical, exam-ready knowledge grounded in real-world applications. Covering essential topics from Agile and Scrum to scope, schedule, and team performance management, McCulley translates PMP concepts into the language of cyberspace operators — equipping readers with the tools to lead projects, manage teams, and drive mission success in high-stakes technical environments (and to excel on the PMP exam, too!).
Table of Contents
Preface
Chapter 1 What is Cybersecurity and Why Should You Care?
The Digital World You Live In
So What Is Cybersecurity, Exactly?
A (Very) Brief History of Hacking and Security
So Why Should You Care?
The Cybersecurity Mindset
Key Concepts and Terminology
Why People Are the Weakest Link
The Scope of the Field: It is Bigger Than You Might Think
Ethics in Cybersecurity: With Great Power Comes Great Responsibility
What to Expect from This Book
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Your Personal Security Audit
End Notes
Chapter 2 Thinking Like the Enemy
Why Think Like an Attacker?
Who Are the Attackers?
Why Do They Attack?
The Attack Lifecycle: How Attacks Actually Work
Threat Modeling: Thinking Systematically About Risk
Common Attack Techniques: A Preview
Thoughts on Risk: Not Everything Is Equally Dangerous
The Threat Landscape Never Stops Moving
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Reconnaissance on Yourself
End Notes
Chapter 3 The ABCs of CIA* (and sometimes “N”)
The CIA Triad: Security’s Holy Trinity
Confidentiality: Keeping the Secrets Secret
Integrity: Trusting What You See
Availability: Being There When It Matters
When the Pillars Pull Against Each Other
Beyond the Triad: The Other Big Security Principles
The Parkerian Hexad: A Broader View
Putting the CIA Triad to Work
Myths and Misconceptions
Nonrepudiation: You Cannot Take It Back
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: CIA Triad Risk Assessment
End Notes
Chapter 4 Ones, Zeros, and Secrets
What Is Cryptography?
A Brief History of Keeping Secrets
Symmetric Encryption: One Key to Rule Them All
Asymmetric Encryption: The Key Pair Revolution
Hashing: The Digital Fingerprint
Digital Signatures: Proving Who Sent It
Digital Certificates and PKI: Trust at Scale
Encryption in Practice: At Rest and In Transit
Key Management: The Hardest Part
When (and How) Cryptography Fails
The Quantum Threat: Tomorrow’s Problem Today
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Exploring Cryptography in the Real World
End Notes
Chapter 5 Authentication, Accountability, and Access Control
Authentication: Proving You Are Who You Claim to Be
The Password Problem
The Passwordless Future
Authorization: Deciding What You Can Do
Identity and Access Management: Putting All this in Action
Accountability: Keeping Track of Who Did What and When
When Access Control Fails
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Auditing Your Own Access Control
End Notes
Chapter 6 Network Security
Network Fundamentals: How Data Moves
Common Network Attacks
Network Defenses: Building the Walls
Wireless Security: Securing Your Airwaves
Cloud and Modern Network Security Challenges
Practical Network Security for Everyone
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Network Reconnaissance and Defense
End Notes
Chapter 7 Social Engineering
What Is Social Engineering?
The Psychology Behind the Attack
Phishing: Casting the Wide Net
Social Engineering in the Cyber Kill Chain
Defending Against Social Engineering
Social Engineering in the Age of AI
Social Engineering Assessments: Testing the Human Firewall
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Recognizing and Analyzing Social Engineering
End Notes
Chapter 8 Malware and Threats
What Is Malware?
A Brief History of Malware
Types of Malware
Adware
How Malware Gets in and What it Does
Detecting Malware
Defending Against Malware
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Analyzing Malware Behavior
End Notes
Chapter 9 The Minefield of Application Security
The OWASP Top 10
Injection Attacks
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
Broken Access Control
Cryptographic Failures
Insecure Design
Security Misconfiguration
Vulnerable and Outdated Components
Authentication and Session Management Failures
Defending Against Application Vulnerabilities
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Vulnerability Assessment
End Notes
Chapter 10 Operating System and Endpoint Security
Operating System Fundamentals
OS Hardening
Host-Based Firewalls
Antivirus and Endpoint Detection and Response
Application Sandboxing
Mobile Operating Systems
Windows Versus Linux Versus macOS: Comparative Security
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: OS Hardening Assessment
End Notes
Chapter 11 Cloud and Virtualization Security
Virtualization Fundamentals
Containers and Container Security
Cloud Computing Models
Cloud Access Security Brokers (CASB)
Cloud Identity and Access Management (IAM)
Data Security in the Cloud
Misconfigured Cloud Storage
Serverless Security
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Cloud Security Audit
End Notes
Chapter 12 Incident Response Day
The Incident Response Process
Detection
Indicators of Compromise (IoCs)
Containment and Eradication (and the Tradeoffs)
Digital Forensics
Timeline Reconstruction
Breach Notification and Communication
Post-Incident Analysis
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Incident Response Simulation
End Notes
Chapter 13 GRC: Playing by Rules
Risk Management
Risk Response Strategies
Compliance Regimes
Audit and Assessment
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Risk Assessment
End Notes
Chapter 14 Security Monitoring, Logging, and the SIEM
Why Monitoring Matters
The Raw Material: Logs and Telemetry
From Logs to Insight: The SIEM
Detection Engineering: Turning Knowledge Into Alerts
The SOC: People Behind the Screens
Fighting the Flood: Tuning and Automation
Measuring What Matters
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Thinking Like a SOC Analyst
End Notes
Chapter 15 Penetration Testing: Breaking In on Purpose
What Is Penetration Testing?
Varieties of Testing
The Methodology: A Structured Attack
Vulnerability Scan, Penetration Test, Red Team
The Tools of the Trade
Bug Bounties and Responsible Disclosure
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Scoping a Test the Right Way
End Notes
Chapter 16 IoT Security
What Is IoT?
Why IoT Security Is Hard
The IoT Attack Surface
Common IoT Vulnerabilities
When Things Go Botnet
IoT and Privacy: The Other Side of the Coin
Defending IoT
Standards, Regulations, and the Path Forward
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: IoT Inventory and Risk Assessment
End Notes
Chapter 17 Industrial Security Systems and Operational Technology
What Is ICS/OT?
Why OT Security Is Different
The Architecture of Industrial Networks
Industrial Protocols and Their Sins
Stuxnet: The Watershed Moment
The IT/OT Convergence Problem
Threats to Critical Infrastructure
Defending OT
The Regulatory Landscape
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Critical Infrastructure Threat Analysis
End Notes
Appendix A: Glossary
Appendix B: Frameworks and Standards at a Glance
Greg McCulley is the COO at SandTech Solutions and oversees federal and commercial contract activities in across 14 US Government contracts. He is an established cybersecurity and academic leader with 29 years’ experience in leadership, IT management, Information Warfare, and risk management. His background includes Combat Mission Ready certification on the Cyber Vulnerability Assessment/Hunt weapon system as a Cyberspace Analyst, leading the first AF Cyber Protection Teams. He authored the original concept for the AF Mission Defense Team construct while serving at HQ AFSPC, in Colorado Springs.
During his military career, he served in and commanded, the 92d Cyber Operations Squadron when the 92d was the AF’s Information Warfare Aggressor Squadron and IW Red Team, earning his Red Team Operator badge during the inaugural operator’s course. He was an AF certified Red Team Operations and Military Deception Operations instructor. He also commanded the 721st Communications Squadron in the Cheyenne Mountain complex, one of a handful of NORAD/USNORTHCOM’s cryptographically-cleared Nuclear Watch Officers entrusted to manage mission risk for the nation’s Integrated Tactical Warning/Attack Assessment mission. As a deployed member, he led data analytics support, intelligence support, and combat zone communications installation.
Greg also serves as an Assistant Professor of Practice, Grant Researcher, and Bootcamp Instructor for the University of Texas-San Antonio for cybersecurity coursework. He previously served as a Guest Lecturer for the US Air Force Academy at Colorado Springs. Greg is also an advisor to the Cyber Security Forum Initiative (CSFI).
PMP For Cyber: A Guide for Cyberspace and IT Operators by William Greg McCulley bridges the gap between project management principles and the fast-paced world of cybersecurity and IT operations. Whether you're a cyber or IT professional looking to formalize your project management skills, or a student building a career at the intersection of technology and leadership, this book delivers practical, exam-ready knowledge grounded in real-world applications. Covering essential topics from Agile and Scrum to scope, schedule, and team performance management, McCulley translates PMP concepts into the language of cyberspace operators — equipping readers with the tools to lead projects, manage teams, and drive mission success in high-stakes technical environments (and to excel on the PMP exam, too!).
Table of Contents
Preface
Chapter 1 What is Cybersecurity and Why Should You Care?
The Digital World You Live In
So What Is Cybersecurity, Exactly?
A (Very) Brief History of Hacking and Security
So Why Should You Care?
The Cybersecurity Mindset
Key Concepts and Terminology
Why People Are the Weakest Link
The Scope of the Field: It is Bigger Than You Might Think
Ethics in Cybersecurity: With Great Power Comes Great Responsibility
What to Expect from This Book
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Your Personal Security Audit
End Notes
Chapter 2 Thinking Like the Enemy
Why Think Like an Attacker?
Who Are the Attackers?
Why Do They Attack?
The Attack Lifecycle: How Attacks Actually Work
Threat Modeling: Thinking Systematically About Risk
Common Attack Techniques: A Preview
Thoughts on Risk: Not Everything Is Equally Dangerous
The Threat Landscape Never Stops Moving
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Reconnaissance on Yourself
End Notes
Chapter 3 The ABCs of CIA* (and sometimes “N”)
The CIA Triad: Security’s Holy Trinity
Confidentiality: Keeping the Secrets Secret
Integrity: Trusting What You See
Availability: Being There When It Matters
When the Pillars Pull Against Each Other
Beyond the Triad: The Other Big Security Principles
The Parkerian Hexad: A Broader View
Putting the CIA Triad to Work
Myths and Misconceptions
Nonrepudiation: You Cannot Take It Back
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: CIA Triad Risk Assessment
End Notes
Chapter 4 Ones, Zeros, and Secrets
What Is Cryptography?
A Brief History of Keeping Secrets
Symmetric Encryption: One Key to Rule Them All
Asymmetric Encryption: The Key Pair Revolution
Hashing: The Digital Fingerprint
Digital Signatures: Proving Who Sent It
Digital Certificates and PKI: Trust at Scale
Encryption in Practice: At Rest and In Transit
Key Management: The Hardest Part
When (and How) Cryptography Fails
The Quantum Threat: Tomorrow’s Problem Today
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Exploring Cryptography in the Real World
End Notes
Chapter 5 Authentication, Accountability, and Access Control
Authentication: Proving You Are Who You Claim to Be
The Password Problem
The Passwordless Future
Authorization: Deciding What You Can Do
Identity and Access Management: Putting All this in Action
Accountability: Keeping Track of Who Did What and When
When Access Control Fails
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Auditing Your Own Access Control
End Notes
Chapter 6 Network Security
Network Fundamentals: How Data Moves
Common Network Attacks
Network Defenses: Building the Walls
Wireless Security: Securing Your Airwaves
Cloud and Modern Network Security Challenges
Practical Network Security for Everyone
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Network Reconnaissance and Defense
End Notes
Chapter 7 Social Engineering
What Is Social Engineering?
The Psychology Behind the Attack
Phishing: Casting the Wide Net
Social Engineering in the Cyber Kill Chain
Defending Against Social Engineering
Social Engineering in the Age of AI
Social Engineering Assessments: Testing the Human Firewall
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Recognizing and Analyzing Social Engineering
End Notes
Chapter 8 Malware and Threats
What Is Malware?
A Brief History of Malware
Types of Malware
Adware
How Malware Gets in and What it Does
Detecting Malware
Defending Against Malware
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Analyzing Malware Behavior
End Notes
Chapter 9 The Minefield of Application Security
The OWASP Top 10
Injection Attacks
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
Broken Access Control
Cryptographic Failures
Insecure Design
Security Misconfiguration
Vulnerable and Outdated Components
Authentication and Session Management Failures
Defending Against Application Vulnerabilities
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Vulnerability Assessment
End Notes
Chapter 10 Operating System and Endpoint Security
Operating System Fundamentals
OS Hardening
Host-Based Firewalls
Antivirus and Endpoint Detection and Response
Application Sandboxing
Mobile Operating Systems
Windows Versus Linux Versus macOS: Comparative Security
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: OS Hardening Assessment
End Notes
Chapter 11 Cloud and Virtualization Security
Virtualization Fundamentals
Containers and Container Security
Cloud Computing Models
Cloud Access Security Brokers (CASB)
Cloud Identity and Access Management (IAM)
Data Security in the Cloud
Misconfigured Cloud Storage
Serverless Security
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Cloud Security Audit
End Notes
Chapter 12 Incident Response Day
The Incident Response Process
Detection
Indicators of Compromise (IoCs)
Containment and Eradication (and the Tradeoffs)
Digital Forensics
Timeline Reconstruction
Breach Notification and Communication
Post-Incident Analysis
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Incident Response Simulation
End Notes
Chapter 13 GRC: Playing by Rules
Risk Management
Risk Response Strategies
Compliance Regimes
Audit and Assessment
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Risk Assessment
End Notes
Chapter 14 Security Monitoring, Logging, and the SIEM
Why Monitoring Matters
The Raw Material: Logs and Telemetry
From Logs to Insight: The SIEM
Detection Engineering: Turning Knowledge Into Alerts
The SOC: People Behind the Screens
Fighting the Flood: Tuning and Automation
Measuring What Matters
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Thinking Like a SOC Analyst
End Notes
Chapter 15 Penetration Testing: Breaking In on Purpose
What Is Penetration Testing?
Varieties of Testing
The Methodology: A Structured Attack
Vulnerability Scan, Penetration Test, Red Team
The Tools of the Trade
Bug Bounties and Responsible Disclosure
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Scoping a Test the Right Way
End Notes
Chapter 16 IoT Security
What Is IoT?
Why IoT Security Is Hard
The IoT Attack Surface
Common IoT Vulnerabilities
When Things Go Botnet
IoT and Privacy: The Other Side of the Coin
Defending IoT
Standards, Regulations, and the Path Forward
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: IoT Inventory and Risk Assessment
End Notes
Chapter 17 Industrial Security Systems and Operational Technology
What Is ICS/OT?
Why OT Security Is Different
The Architecture of Industrial Networks
Industrial Protocols and Their Sins
Stuxnet: The Watershed Moment
The IT/OT Convergence Problem
Threats to Critical Infrastructure
Defending OT
The Regulatory Landscape
Myths and Misconceptions
Chapter Summary
Key Terms
Review Questions
Hands-On Exercise: Critical Infrastructure Threat Analysis
End Notes
Appendix A: Glossary
Appendix B: Frameworks and Standards at a Glance
Greg McCulley is the COO at SandTech Solutions and oversees federal and commercial contract activities in across 14 US Government contracts. He is an established cybersecurity and academic leader with 29 years’ experience in leadership, IT management, Information Warfare, and risk management. His background includes Combat Mission Ready certification on the Cyber Vulnerability Assessment/Hunt weapon system as a Cyberspace Analyst, leading the first AF Cyber Protection Teams. He authored the original concept for the AF Mission Defense Team construct while serving at HQ AFSPC, in Colorado Springs.
During his military career, he served in and commanded, the 92d Cyber Operations Squadron when the 92d was the AF’s Information Warfare Aggressor Squadron and IW Red Team, earning his Red Team Operator badge during the inaugural operator’s course. He was an AF certified Red Team Operations and Military Deception Operations instructor. He also commanded the 721st Communications Squadron in the Cheyenne Mountain complex, one of a handful of NORAD/USNORTHCOM’s cryptographically-cleared Nuclear Watch Officers entrusted to manage mission risk for the nation’s Integrated Tactical Warning/Attack Assessment mission. As a deployed member, he led data analytics support, intelligence support, and combat zone communications installation.
Greg also serves as an Assistant Professor of Practice, Grant Researcher, and Bootcamp Instructor for the University of Texas-San Antonio for cybersecurity coursework. He previously served as a Guest Lecturer for the US Air Force Academy at Colorado Springs. Greg is also an advisor to the Cyber Security Forum Initiative (CSFI).