What is the PECB Certified Incident Responder?
The PECB Certified Incident Responder (CIR) is a 5-day, hands-on cybersecurity incident-response certification. It equips security professionals to detect, respond to, and mitigate security incidents so they can minimise impact, preserve business continuity, and strengthen an organisation's security posture. The course runs on hands-on exercises and real-world simulations across threat intelligence, malware analysis, containment strategies, and forensic investigation.
Unlike awareness-level qualifications, CIR is built to prove operational capability. By the end you should be able to plan, coordinate, and execute incident-response procedures, conduct digital forensics, collaborate with stakeholders under pressure, and build incident-response playbooks tailored to your own organisation — from the first alert through containment, eradication, recovery, and post-incident review.
Why incident-response skills matter in Australia
In Australia, incident response is no longer just good practice — it is a legal and regulatory expectation. Several drivers make a capable, well-drilled response team a board-level priority:
- The Notifiable Data Breaches (NDB) scheme — entities covered by the scheme must assess suspected eligible data breaches and notify the OAIC and affected individuals when the notification criteria are met. Forensic evidence can support that assessment; not every incident is notifiable.
- The SOCI Act — responsible entities for assets subject to mandatory reporting must report a critical cyber incident within 12 hours of awareness, or another reportable incident within 72 hours. The statutory impact and applicability tests determine the category.
- APRA CPS 234 — APRA-regulated entities must notify APRA as soon as possible, and no later than 72 hours after awareness, for information-security incidents meeting CPS 234 notification criteria.
- ASD ACSC guidance — Essential Eight and incident-response guidance can inform control and response planning. Specific legal, contractual and insurance requirements need separate confirmation.
SOC analysts and incident responders may need to preserve evidence, coordinate decisions and document the response under applicable deadlines. Course completion is one input to competence; it does not guarantee employment or an incident outcome.
Who should take this course
- Incident response team members and cybersecurity analysts managing security events
- IT security professionals enhancing their technical and strategic incident response skills
- Security operations centre (SOC) personnel involved in threat detection and response
- Professionals transitioning into specialised incident response roles
- Managers and team leaders coordinating incident response strategies and protocols
Before attending, understand the fundamentals of cybersecurity and incident response. The full credential has separate professional and project experience requirements; PECB assesses the application after the examination.
What you learn — the 5-day agenda
The course is four days of hands-on training plus the certification exam on day five:
The incident-response lifecycle and frameworks, building and coordinating the response team, and strategic incident handling with tailored response playbooks.
Ransomware attack vectors and containment, malware behaviour analysis, and remediation and recovery strategies to minimise impact and restore operations.
Threat intelligence and early detection, perimeter threat-detection tools and techniques, and the containment of external threats targeting the network edge.
Detecting and remediating advanced persistence mechanisms, digital forensics and evidence handling, and post-incident review for continual improvement.
The 3-hour PECB Certified Incident Responder exam across five competency domains, remotely proctored so you can sit it from anywhere in Australia.
Current examination requirements
Open-book, technical exam. Duration: 3 hours. 20 technical questions in the current English PECB examination record. Passing requirements: 70%. Check the current PECB examination record and assigned examination before booking.
- Fundamental concepts of incident response
- Ransomware incident response
- Malware incident response
- Perimeter threats detection and response
- Incident response to persistent mechanisms
Credential requirements and how to enrol
Before attending, understand the fundamentals of cybersecurity and incident response. The full credential has separate professional and project experience requirements; PECB assesses the application after the examination.
After passing, apply to PECB for the Incident Responder credential supported by your experience. The current course page and candidate handbook differ: the page lists two years of incident-response or cybersecurity experience and no project-hours requirement; the handbook lists two years overall with one relevant year, 200 project hours and a Provisional pathway. Obtain written confirmation from PECB of the applicable scheme before relying on an experience or project-hours threshold. PECB decides the award and requires its Code of Ethics. Passing the examination and receiving a credential are separate: PECB must approve the application. Maintenance depends on the credential awarded; Provisional credentials and Foundation certificates are exempt from CPD and maintenance fees. Check the current PECB policy for other credentials.
Cost, inclusions and access
Self-Study: A$ 1,165.00 excluding GST (A$ 1,281.50 including Australian GST). Published inclusions (subject to the credential and retake clarification immediately below): 450+ pages of comprehensive training materials; Hands-on exercises, real-world simulations, and quizzes; 12 months access via myPECB; Official PECB CIR exam voucher; 3-hour exam, remotely proctored; Two attempts (initial + one free resit within 12 months); PECB digital certificate on pass; 31 CPD credits on completion; Incident response playbooks and forensic techniques; Aegentra Academy support inbox. Clarification: references to a credential or certificate on pass do not mean automatic award. The eligible PECB credential requires an application and PECB approval, including applicable experience and ethics requirements. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply. A retained inclusion referring to the initial examination date does not extend or restart this policy cycle. Australian GST follows the billing address. Check the course page for the full inclusions and current booking options.
This course publishes 12 months of material access. Course-material access, examination and retake deadlines, and any certificate-application deadline are separate. Confirm the material-access start date in your booking confirmation and check the deadlines recorded in myPECB before scheduling your examination. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply.
Credential requirements and how to enrol
Before attending, understand the fundamentals of cybersecurity and incident response. The full credential has separate professional and project experience requirements; PECB assesses the application after the examination.
After passing, apply to PECB for the Incident Responder credential supported by your experience. The current course page and candidate handbook differ: the page lists two years of incident-response or cybersecurity experience and no project-hours requirement; the handbook lists two years overall with one relevant year, 200 project hours and a Provisional pathway. Obtain written confirmation from PECB of the applicable scheme before relying on an experience or project-hours threshold. PECB decides the award and requires its Code of Ethics. Passing the examination and receiving a credential are separate: PECB must approve the application. Maintenance depends on the credential awarded; Provisional credentials and Foundation certificates are exempt from CPD and maintenance fees. Check the current PECB policy for other credentials.
Primary references and applicability
These sources explain the requirements and scope distinctions discussed above. Check their applicability to the organisation or credential.
FAQs
What is the PECB Certified Incident Responder (CIR)?
CIR is a 5-day, hands-on cybersecurity incident-response certification from PECB. It teaches you to detect, respond to, and mitigate security incidents across the modern threat landscape — ransomware, malware, perimeter threats, and advanced persistence mechanisms — plus digital forensics, containment strategies, and building incident-response playbooks. The credential assesses relevant knowledge and experience; effective operational response also requires appropriate authority, tools, practice and team arrangements.
Is the Certified Incident Responder exam practical or multiple-choice?
Open-book, technical exam. Duration: 3 hours. 20 technical questions in the current English PECB examination record. Passing requirements: 70%. Check the current PECB examination record and assigned examination before booking.
Do I need prior experience to take the course?
Before attending, understand the fundamentals of cybersecurity and incident response. The full credential has separate professional and project experience requirements; PECB assesses the application after the examination.
What is the difference between the Provisional and full credential?
After passing, apply to PECB for the Incident Responder credential supported by your experience. The current course page and candidate handbook differ: the page lists two years of incident-response or cybersecurity experience and no project-hours requirement; the handbook lists two years overall with one relevant year, 200 project hours and a Provisional pathway. Obtain written confirmation from PECB of the applicable scheme before relying on an experience or project-hours threshold. PECB decides the award and requires its Code of Ethics. Passing the examination and receiving a credential are separate: PECB must approve the application. Maintenance depends on the credential awarded; Provisional credentials and Foundation certificates are exempt from CPD and maintenance fees. Check the current PECB policy for other credentials.
How much does the Certified Incident Responder course cost in Australia?
Self-Study: A$ 1,165.00 excluding GST (A$ 1,281.50 including Australian GST). Published inclusions (subject to the credential and retake clarification immediately below): 450+ pages of comprehensive training materials; Hands-on exercises, real-world simulations, and quizzes; 12 months access via myPECB; Official PECB CIR exam voucher; 3-hour exam, remotely proctored; Two attempts (initial + one free resit within 12 months); PECB digital certificate on pass; 31 CPD credits on completion; Incident response playbooks and forensic techniques; Aegentra Academy support inbox. Clarification: references to a credential or certificate on pass do not mean automatic award. The eligible PECB credential requires an application and PECB approval, including applicable experience and ethics requirements. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply. A retained inclusion referring to the initial examination date does not extend or restart this policy cycle. Australian GST follows the billing address. Check the course page for the full inclusions and current booking options.
Is the credential recognised in Australia and internationally?
Accreditation varies by credential. PECB publishes personnel-certification accreditation under applicable ISO/IEC 17024 scopes and ANAB certificate-program accreditation under ANSI/ASTM E2659-24 for specified programs. Verify the applicable published PECB scope.
How long is the course, and how is it delivered?
It is a 5-day course — four days of hands-on training across incident-response fundamentals, ransomware and malware response, perimeter threat detection, and persistence and forensics, followed by the certification exam on day five. Aegentra delivers it online and self-paced through myPECB, with 12 months of access, with any other online delivery arrangement requiring confirmation on the course page.
What CPD credits and career roles does CIR support?
You earn 31 CPD credits on completion. CIR supports roles such as incident responder, SOC analyst, blue-team operator, cybersecurity analyst, and security operations lead. In Australia, demand is driven by the Notifiable Data Breaches scheme, SOCI Act cyber-incident reporting to ASD and the ACSC, and APRA CPS 234 incident notification.