Cyber Security MSc



This online NCSC-certified Masters delivers modern enterprise Cyber Security coupled with Digital Forensics and AI for Security & Forensics

Course overview

Computer security is one of the key challenges in contemporary computing. You will gain critical knowledge within the cyber security and digital forensic domains, combining academic principles and industrial practice.

The course is informed by current research in security and digital forensics and is underpinned by our experience with external partners in law enforcement, the cyber security industry, financial institutions and other knowledge transfer activities.

Course specialisms include network security, penetration testing, incident response, malware analysis, cryptography, audit and compliance, and host and mobile digital forensics. The specialisation you gain in the taught modules is further developed through an extensive research-based MSc dissertation project, leading towards a mastery of a subject area and enhancing your particular specialism.

The range of key Cyber Security and Digital Forensic subjects covered in the taught modules, practical experience in labs, along with a deep dive into a specialism with the research dissertation, means our graduates are well equipped for a career in industry, be it a blue team, red team, or forensic investigation or research role.

This part-time, distance learning route is a fully online version of our popular on-campus MSc Cyber Security degree. It was developed with flexibility in mind, with the option to spread the course modules out over a number of years, making it ideal for students who cannot attend on-campus classes or those in employment. Distance learning students will have the opportunity to come to campus for some classes or to visit, if they wish.

Typical entry points to this course are in September and January. Please enquire for more information.

Two female students in the SOC lab looking at computers

Mode of Study:

Part Time Distance learning (available as Full-time | Part-time)

Duration:

2.5 - 4 years

Start date:

Jan

NCSC Certified Education

This MSc is one of a very small number of courses certified by the National Cyber Security Centre (NCSC), in recognition of our excellence in cyber security education.

Course details

Cyber security is a growth industry and is vital in modern computing environments. You will gain foundation knowledge in all the key areas of cyber security, both defensive and offensive, as well as post-incident response and malware analysis. The digital forensic aspects of the course include network and computer forensics, allowing you to develop the knowledge required to conduct computer-related investigations across networks, systems and other digital devices. AI for Security is embedded in all modules, with Security of AI featured as well, addressing key issues emerging in the field.

We have close ties with industry, law enforcement, and the public sector, through partnerships with organisations such as Cisco Systems, Guidance Software, Symantec, NCC Group, NCA, Police Scotland, and many others. This helps inform the course, and provides guest lecturers by industry experts. Extensive innovative research is also carried out in key domains by academics and PhD students in our dedicated cyber security and forensic research group.

Study from anywhere in the world on this distance learning course. Practical activities in every module are provided via our online award-winning virtual cyber teaching environments. You'll benefit from flexible, student-centric learning, with teaching aligned to our on-campus course, but flexibility within modules to study at the time or day that suits you. You can take 1-3 modules per trimester, adjusting each term as needed, with study breaks of up to a year available during the course. Recorded materials such as lectures and demonstrations, and online practical activities are accessible at any time, with evening support sessions provided for each module.

  • calendar

    How you’ll be taught

    Our industry-informed course combines thorough coverage of academic theory aligned with extensive hands-on practical activities, supported by fully online web-based materials with virtualised lab environments that provide an equivalent experience to our on-campus specialist facilities.

    This is a distance learning course which you can start in September or January with flexibility in the number of taught modules taken in each trimester. The distance learning course runs in parallel with our on-campus course and is aligned to the same three academic trimesters, including the assessments, which are taken in the same weeks as on-campus students. Students normally take 2.5 years to complete this course but you can take up to 4 years depending on your commitments and availability.

    As the teaching runs to the same weekly schedule, distance learning students who wish to attend some of the taught classes here in Edinburgh are more than welcome, but there is no requirement to attend. The course content and assessments are fully online and are supported by the same staff as the on-campus teaching, leading to an academically equivalent MSc degree.

  • note and pen

    Assessments

    Your knowledge of the information security taught subjects on the course is assessed via a variety of mechanisms including exams, written reports and essays, and practical scenario-based assessments.

    Assessments are all fully online including virtualised practical environments for hands on assessments.

  • library

    Facilities

    This course is taught online.

    You will have access to extensive online, materials, and virtualised safe lab environments for authentic scenario-based practical work such as malware analysis and offensive network security exercises.

    At Edinburgh Napier University, we offer state-of-the-art facilities to support our cyber security students. These consist of physical spaces with powerful computers, where students meet, collaborate and learn together at our Merchiston campus. We also offer students the chance to use virtual learning environments, so students can gain hands-on skills in the latest technology in a safe and controlled space. You'll have access to custom cyber security labs, as well as virtualised authentic cyber practical platforms providing 24/7 access to course practical activities.

    vSoC (Virtual Security Operations Centre): Our uniquely designed Virtual Security Operations Centre (VSOC) mimics the real-life SOC environment. Through the virtualised system, students can safely identify real world risks and explore tools and techniques in scenarios including exploitation, malware, insider threats and data loss.

    LinuxZoo: LinuxZoo is a unique environment developed to provide temporary virtualised infrastructure including servers, networks, and desktop machines on demand to students. Users gain access to a set of virtual computers and networks dedicated to that user, which are built dynamically as required. This is like a hands-on traditional computer lab, where resource is allocated to each user for the duration of a lab session, but here the resource from the user’s viewpoint is completely cloud-based.

Modules

Modules that you will study* as part of this course

Applied Cryptography and Trust ( CSN11131 )

The focus of this module is to provide a core understanding of the fundamental areas of cryptography, identity, and trust. A key feature is to cover both the theoretical areas, while often demonstrating practical applications including key protocols. The module key areas are:• Privacy, and Cryptography Fundamentals (Confidentiality, Sec Models, Cipher types) • Asymmetric Key Encryption. Including RSA and Elliptic Curve Cryptography (ECC).• Symmetric Key Encryption. Including AES and associated modes.• Hashing and MAC Methods. Including MD5, SHA-1, SHA-256, SHA-3 and PBKDF2.• Security Protocols: HTTPS, SSL/TLS, DNSSec, IPSec, WPA • Key Exchange. Diffie-Hellman Method, ECDH.• Trust Infrastructures. Digital Certificates, Signatures, Key Distribution Centres (Kerberos), OAuth • Identity and Authentication (Passwords, Authentication tokens, Key pair identity, Multi-factor, Biometric Authentication).• Distributed Systems: Blockchain, Distributed Ledgers and Cryptocurrency. Smart Contracts, Data Tokenization, and Transactions.• Future Cryptography: Zero Knowledge Proof, Homomorphic Encryption, Light-weight cryptography, and Quantum robust methods.• Host and Domains: Trust systems. Authentication with Active Directory Authorisation: Log integration and rights.

Further information

Computer Penetration Testing ( CSN11127 )

This module will cover a range of elements concerned with penetration testing, security testing and offensive security methods. Considerable practical focus is made on methods and tools to assist in penetration testing. Areas of study include:• Testing methodologies and processes, attack frameworks, testing preparation, reporting, and law. Infrastructure and Linux for pentesting. • Information gathering, including passive and active reconnaissance. • Infrastructure security testing, including recon, enumeration and vulnerability analysis. Vulnerabilities, exploits and payloads. • Exploitation types, methods, exploit frameworks and post-exploit methods. • Web App technologies, vulnerabilities, and security testing methods. Injection attack methods. • Authentication credential and password attack methods and testing. • AI for Security Testing, testing AI systems, and current related research.

Further information

Host-Based Forensics (DL) ( CSN11126 )

This module will cover elements of operating system disk-level architectures, such as Windows and Linux. This will allow students to study how operating systems store system and user data, and thus students will gain an understanding as to what information could technically be held on such systems. This data could include user files, as well as user activities such as login session data, browsing histories, operating system manipulation, and general user interactions with a variety of operating system tools. This understanding will be expanded through theoretical knowledge and practical exercises in extracting information from systems, using a variety of open source and commercial forensic analysis tools, and documenting the results of such a process using consistent and thorough evidential procedures. This includes the production of event timelines, as well as the analysis of system logs, operating system state, file systems, and application data. The module will also consider the ethical and professional issues related to digital forensics.

Further information

Incident Response and Malware Analysis ( CSN11129 )

The aim of the module is to develop a deep understanding of advanced areas related to security and live/network forensics, with a strong focus on virtualised and Cloud-based environments that will allow graduates to act professionally within incident response and in malware/threat analysis. An outline of the main areas includes:• Threat Analysis. This involves an in-depth analysis of a range of current threats, such as DDoS, Botnets, trojans, and so on.• System Architectures, Services and Devices. Networked infrastructures (Servers/Firewall/IDS/ Syslog). • Network Forensics. Advanced Network Protocol Analysis, Advanced Trace Analysis, IDS Signature Detection, and Security Threat Network Traces.• Live Forensics. Code Analysis, Host/Network Analysis, Reverse Engineering. Mobile/x86 architecture, Machine Code Analysis, Vulnerability Analysis, Sandboxed Analysis.• Log Capture/Analysis, and Time-lining. Creating large-scale data infrastructure and analysis methods such as Big Data, SIEM and cross-log analysis (such as Splunk).• Malware Analysis. Static/Dynamic Analysis. Disassembly. Obfuscation. Behaviour Analysis. Encoding methods.• Data Hiding and Data Loss Detection/Prevention. Data hiding methods, detection methods, tunnelling, and disk encryption.• Host Investigation Evidence Gathering: Windows, Linux, Android and Mac OS.• Current Related Research.

Further information

Masters Dissertation ( SOC11101 )

The work for this module comprises the completion of an individual research project. Each student is assigned a personal Supervisor, and an Internal Examiner who monitors progress and feedback, inputs advice, examines the dissertation and takes the lead at the viva. There are two preliminary deliverables prior to the submission of the final dissertation: (1) Project proposal (2) Initial Report including time plan and dissertation outline

Further information

Network Security (D/L) ( CSN11118 )

The aim of this module is to develop a deep understanding and provide with hands-on implementation experience of network security concepts. A focus has been made on discussing networking fundamentals and implementation in first half of the module. Considerable content in second part of the module has been focused on Artificial Intelligence (AI) and Machine Learning (ML)-based solutions in the cybersecurity domain. Developing exemplar AI models in practical for achieving security measures allow students to professionally design, implement, and analyse AI-based cybersecurity strategies. An outline of the main areas includes:• Introduction to network security and challenges: It focuses on discussing various network threats and attacks that can compromise the network security. Discussion then diverts to network defence strategies, for example, perimeter and defence-in-depth.• Access Control and Authentication: This lecture focuses on introducing and discussing various types of traditional centre of gravity of computer security, the “Access Control”. The list of concepts in this lecture covers trust and identity, attacks, models – access control models, network device access control, AAA, Layer 2, device hardening.• Firewalls: In this part of module, a discussion around different types and existing technologies of firewall is presented. Students get an opportunity to implement and deploy the concepts, such as host-based or network-based firewall, static packet filtering, stateful packet filtering, and multilayer firewall in the lab environment. • Fundamentals of Cryptography and Remote Access VPN: Fundamentals of encryption, decryption, and authentication are touched before diving deeper in developing remote access and Virtual Private Networks (VPNs) for network security, while also covering types (L2, L3 and L4/5) and technologies (IPSec and SSL).• Artificial Intelligence and Machine Learning: Discussion here covers introduction to various learning techniques including supervised, unsupervised and reinforcement learning in terms of various application domains, i.e., classification, regression and clustering.• Introduction to machine learning models: Various AI models are introduced and implemented including neural network, linear regression, k-means clustering, support vector machine, random forest, decision tree, deep neural network.• Data-Driven Cybersecurity: Intrusion Detection Systems (IDS) vs Intrusion Detection and Prevention Systems (IDPS) are introduced in terms of types, alert monitoring and sensor tuning; behavioural analysis, in-line vs out-of-line IDS/IDPS. Practical provides an opportunity to applying AI techniques to real-world intrusion detection problems. • Relevant state-of-the-art research in the domain: Discussions around recent research advances in the fields of network security and cybersecurity.

Further information

Security Audit & Compliance ( INF11109 )

The aim of the module is to let you develop a deep understanding of the framework that information security operates in, and to give you an opportunity to express this in the form of professional written reports. Topics covered include: • The relation between governance models and frameworks including: ISACA’s COBIT and ISO Standards (ISO27000 in particular) • Overview of relevant laws and regulations: national and international, covering privacy, computer misuse and other legal issues. • The role of organisation and human factors in ensuring a secure environment• The role of the professions; difference between audit, forensics and security management. Professional ethics and codes of practice• Information security risk management and controls including, contingency and continuity planning

Further information

* These are indicative only and reflect the course structure in the current academic year. Some changes may occur between now and the time that you study.

ACCREDITED BY

This certification demonstrates the course’s high standard in structure, staffing and teaching materials. The topics studied are mapped to the Cyber Security Body of Knowledge (CyBOK), which show that the degree contains key topics and students can be assured they are choosing a course which provides them with skills needed to pursue a career in cyber security.

Our NCSC courses sit within our GOLD level NCSC Centre of Excellence for Cyber Security Education. This covers a range of contributions in cyber, including teaching excellence, cyber outreach, industry partnerships, integration into HEI cyber security and training.

Disclaimer

Study modules mentioned above are indicative only. Some changes may occur between now and the time that you study.

Full information is available in our disclaimer.

Meet your Programme Leader and Teaching Team

Throughout your studies, you'll learn from experienced professionals and industry leaders who bring valuable expertise, insight and real-world perspectives to your learning experience. Our Cyber Security teaching is delivered by an exceptionally experienced team with nearly two decades of expertise in cyber security teaching and research. Students benefit from expert senior academics in core teaching including Associate Professor Rich Macfarlane, Professor Bill Buchanan and Associate Professor Thomas Tan lead teaching on key modules.

Programme Leader: Associate Professor Rich Macfarlane.

Course tutors include: Professor Bill Buchanan OBE, Dr Thomas Tan, Robert Ludwiniak, Dr Mouad Lemoudden, Dr Sanaullah Jan, Dr Lijuan Luo.

Other Key teaching staff: Dr Gordon Russell, Dr Sean McKeown, Dr Pavlos Papadopoulos.

Associate Professor Rich Macfarlane created vSOC, our virtual Security Operations Centre and cyber range, and founded ENUSEC, our student security society. His research in offensive security has contributed to new attacks and has been presented at leading conferences including DEF CON and Black Hat. Professor Bill Buchanan is a world-leading expert in Applied Cryptography, with an extensive international research profile and a strong record of award-winning teaching and research. His expertise gives students direct exposure to contemporary developments in cryptography, security and digital trust. Associate Professor Thomas Tan is a leading researcher in Artificial Intelligence and Security, with significant research achievements and recognition. Gordon Russell is a leading academic in Security and Virtualisation Systems and leads LinuxZoo, a virtualised platform used for teaching security and digital forensics. Sean McKeown is a leading academic in Digital Forensics and is currently involved in organising DFRWS 2027 at Edinburgh Napier University, bringing one of the world's major digital forensics research communities to the University.

Students also benefit from the academic expertise and community of our Cyber Security Research group and Cyber security doctoral research students, who can provide support for MSc dissertation projects.

ENUSEC, Edinburgh Napier's Security Society

Learn. Compete. Connect. Founded in 2015, our student security society, ENUSEC, fosters community, learning and understanding, and hosts annual flagship security conference, Le Tour Du Hack.

World-class guest lectures

Meet some of the world’s leading figures in Cyber Security at our regular guest lectures on key issues and the future of the industry. Recent guests include Bruce Schneier, Whitfield Diffie, Troy Hunt, amongst others.

Entry requirements

What are the entry requirements for Cyber Security?

The entry requirement for this course is a Bachelor (Honours) Degree at a 2:2 or above in a Computing discipline e.g. Computing, Computer Science, Computer Networking, Software Engineering, or Cyber Security.  

Other similar disciplines may be considered provided 50% of the modules in the final 2 years of your degree are computing related and passed.

We may also consider lesser qualifications if you have sufficient relevant work experience.

Edinburgh Napier University welcomes applications from current and former Armed Forces personnel and offers entry based on training and education already received while in service. To assess your eligibility please contact our UK Student Recruitment team providing digital copies of your qualifications and indicating which course you would like to apply for.  

Edinburgh Napier University is a member of the MOD’s Enhanced learning Credit scheme (ELC)  

Can I get admission into Cyber Security based on my working experience in this sector?

This course has academic entry requirements which are assessed alongside relevant work experience. Full details of any relevant work experience, including references should be submitted with your application and may be considered for entry where the minimum academic entry requirements are below those required.

Usually, unrelated work experience is not considered sufficient for entry without meeting the minimum academic entry requirements. Please contact us with your specific circumstances by submitting an enquiry form above and we will be happy to discuss your options.

Can I make an appointment with an advisor to discuss further about the admission process?

If you want to get more information on the admission process, please get in touch with the postgraduate admissions team by submitting an enquiry form above.

 

If your first language isn't English, you'll normally need to undertake an approved English language test and our minimum English language requirements will apply.

This may not apply if you have completed all your school qualifications in English, or your undergraduate degree was taught and examined in English (within two years of starting your postgraduate course). Check our country pages to find out if this applies to you.

We welcome applications from students studying a wide range of international qualifications.
Entry requirements by country

Please note that international students are unable to enrol onto the following courses:
  • BM Midwifery/MM Midwifery
  • MSc Nursing courses
  • All Graduate Apprenticeship courses

See who can apply for more information on Graduate Apprenticeship courses.

We’re committed to admitting students who have the potential to succeed and benefit from our programmes of study. 

Our admissions policies will help you understand our admissions procedures, and how we use the information you provide us in your application to inform the decisions we make.

Undergraduate admissions policies
Postgraduate admissions policies

Fees & funding

The course fees you'll pay and the funding available to you will depend on a number of factors including your nationality, location, personal circumstances and the course you are studying. We also have a number of bursaries and scholarships available to our students.

Tuition fees
Students from 2026/27 2027/28
Scotland, England, Wales, Northern Ireland, and Republic of Ireland (per 20 credits) £1,220 tba
Scotland, England, Wales, Northern Ireland, and Republic of Ireland-60credit Dissertation module £725 tba
Overseas and EU (per 20 credits) £3,330 tba
Overseas and EU-60credit Dissertation £2,285 tba

Tuition fees are subject to an annual review and may increase from one year to the next. For more information on this and other tuition fee matters, please see our Fees and Funding links above.



Fees for modules are calculated according to the number of credits (multiples of 20). The rate shown in the table is for 20 credits*. The total fee you will pay is dependant upon the exit award you wish to achieve.



The University offers a 20% discount on Postgraduate Taught Masters programmes to its alumni. The discount applies to all full-time, part-time and online degrees. The discount can only be applied to year one of a full-time Postgraduate degree, any additional years are exempt from the discount. For part time Postgraduate degrees the discount will apply to years one, two and three only and any additional years will be exempt from the discount. Please read our full T&C here.



Please note that the tuition fees liable to be paid by EU nationals commencing their studies from 1 August 2021 will be the Overseas fee rate. The University offers a range of attractive Tuition Fee bursaries to students resident in specific countries. More information on these can be found here.




Careers & employability

What can you do with an MSc Cyber Security degree?

The continued growth in the current requirement for cyber security professionals means there are a wide range of careers which can be followed after graduating from the course, such as:

  • Security Consultant/Analyst
  • Penetration Tester
  • Network Security Analyst
  • Forensic Investigator
  • Audit/Compliance Consultant
  • Security Certification Engineer
  • Incident Response Analyst
  • System Admin
  • Network Engineer

The degree programme develops a range of key skills currently needed in industry, covering areas such as network security, penetration testing, security monitoring, incident response, malware analysis, operating systems, network and computer forensics, virtualisation and malware analysis. Materials from many professional courses are integrated into the curriculum, towards helping students prepare for sought after professional certification like:

  • Cisco Security Certifications
  • Certified Information Systems Security Professional (CISSP)
  • Offensive Security Certified Professional (OSCP)
  • Centre for Research and Evidence on Security Threats (CREST)

This course will help you to emerge as a highly skilled cyber security professional, ready to tackle the challenges of securing digital systems and networks. Whether you aspire to work in government, finance or technology, our MSc in Cyber Security will provide you with the knowledge and skills to succeed in a rapidly evolving threat landscape.

What does a Cyber Security Consultant do?

As a Cyber Security Consultant, your expertise in cyber security will be very crucial in safeguarding organisations against cyber threats and attacks. In this role, you will serve as a trusted advisor to clients, helping them assess their cyber security posture, identify vulnerabilities, and develop robust strategies to mitigate risks and protect sensitive information.

Your responsibilities will encompass a wide range of activities, from conducting security assessments and penetration testing to implementing security controls and incident response plans. You will often collaborate with clients to understand their unique security challenges and develop tailored solutions that align with their business objectives and regulatory requirements.

As a Cyber Security Consultant, you will keep up to speed with the latest threats and trends in cyber security, leveraging your knowledge of industry best practices and emerging technologies to stay one step ahead of cybercriminals. Whether its securing cloud environments, defending against ransomware attacks, or implementing multi-factor authentication, your expertise will be instrumental in helping clients navigate the complex landscape of cybersecurity.

Your dedication to protecting client assets and your ability to communicate complex technical concepts in a clear and concise manner will set you apart as a trusted advisor and partner.

Four men standing smiling for the camera with trophies after winning Best New Cyber Talent’ at the Scottish cyber awards in 2017