A working method for writing a security strategy as a single page that people read, cite and argue with, rather than a document nobody opens. It separates a strategy from a roadmap, a plan and a list of projects, builds an honest current state assessment without a maturity score, establishes the few numbers the argument needs, chooses three bets and writes them so an outsider can judge them true or false, and takes seriously the hardest section of the page, which is what you will explicitly not do. It then sequences the work against money, people and organisational patience, keeps the page useful through an incident and a reorganisation, and reviews it quarterly without rewriting it quarterly. Three worked one page strategies are included: a company of thirty, a regulated enterprise, and a vendor blocked by customer security reviews.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.