Cyber Security Governance for Government and Public Sector Teams Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-054
Duration5 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while working within statutory duties, budget controls, procurement rules and political scrutiny. Cyber security leaders need more than technical controls: they must establish accountable decision rights, convert risk evidence into defensible priorities, govern suppliers and cloud services, and demonstrate that security investment supports mission delivery. This course addresses the gap between cyber operations and the governance structures that senior responsible owners, audit committees, regulators and service leaders expect to see.

Participants learn to design and operate a practical cyber security governance model for a public body. The course covers governance roles and committees, risk appetite and tolerance statements, NIST Cybersecurity Framework 2.0 and NIST RMF application, ISO/IEC 27001 control governance, information asset ownership, third-party assurance, incident escalation, metrics and board reporting. Participants practise building a risk register, defining risk treatment decisions, creating a control assurance plan, and presenting cyber priorities in language suited to executives and non-technical oversight bodies.

Delivery combines instructor-led analysis with government-style case material, including a citizen-services platform, a critical supplier and a reportable security incident. Throughout the week, participants develop a Cyber Security Governance Pack for a realistic public sector organisation. The pack includes a governance operating model, RACI, risk appetite statements, priority risk register, assurance calendar, dashboard design and a 90-day implementation plan that can be adapted for use in their own department, agency, local authority or public service provider.

The course is designed for intermediate to advanced professionals who influence security decisions, assurance or service delivery. It is particularly valuable where cyber governance must work across shared services, legacy estates, regulated information, outsourced providers and multiple accountable stakeholders.

Course objectives

By the end of this course, participants will be able to:

  • Design a public sector cyber security governance operating model with accountable roles, forums and escalation routes
  • Apply NIST Cybersecurity Framework 2.0 and NIST RMF to structure mission-led cyber risk decisions
  • Draft risk appetite and tolerance statements for citizen data, critical services and third-party dependencies
  • Build a prioritised cyber risk register using likelihood, impact, control effectiveness and treatment ownership
  • Create a RACI matrix for information asset ownership, security control operation and incident decision-making
  • Develop a control assurance plan aligned to ISO/IEC 27001:2022 evidence requirements and internal audit needs
  • Produce board-level cyber metrics and dashboard narratives that distinguish risk exposure from operational activity
  • Construct a 90-day cyber governance implementation roadmap with milestones, dependencies and decision points

Benefits of attending

For you

  • Gain a repeatable method for converting technical security concerns into governance decisions senior leaders can approve
  • Build credibility when briefing audit committees, senior responsible owners and service directors on cyber risk
  • Learn to define accountable ownership across security, digital delivery, data governance and supplier management teams
  • Create evidence-led assurance plans that support internal audit, external scrutiny and regulatory enquiries
  • Leave with a reusable governance pack and implementation roadmap for a current or future leadership role

For your organisation

  • Establish clearer ownership and escalation routes for cyber risks affecting public services and citizen information
  • Improve the quality and consistency of cyber risk reporting presented to boards, audit committees and accountable officers
  • Reduce unmanaged supplier and cloud risk through defined assurance requirements, contract checkpoints and exception handling
  • Create an auditable link between security controls, risk treatment decisions, investment priorities and service outcomes
  • Accelerate governance improvements through a participant-produced 90-day plan tailored to organisational constraints

Target competencies

Cyber governance designRisk appetite settingControl assurance planningBoard risk reportingSupplier risk oversightIncident escalation governance

Who should attend

  • Cyber Security Managers — who must establish clear accountability and report risk to senior public sector leaders
  • Information Security Officers — who translate security policies and technical controls into auditable governance practices
  • Digital and IT Service Managers — who own services that must meet security, resilience and assurance obligations
  • Risk and Assurance Managers — who need to integrate cyber risk into enterprise risk, audit and committee processes
  • Data Protection and Information Governance Leads — who coordinate security responsibilities around sensitive and citizen information
  • Procurement and Supplier Management Leaders — who must govern cyber risk across outsourced, cloud and managed service contracts

Requirements and prerequisites

Participants should already understand core cyber security concepts, including assets, threats, vulnerabilities, controls, incidents, access management and risk treatment. Experience working in an IT, digital, risk, audit, information governance or security role is expected, ideally within a government, local authority, health, education, transport or regulated public service environment. Familiarity with risk registers, policy documents and basic reporting to management will be useful. Participants do not need to be penetration testers, security architects, auditors or ISO lead auditors, and no coding, SIEM administration or prior certification in NIST or ISO/IEC 27001 is required.

Training methodology

The programme uses short instructor-led briefings followed by structured application to a public sector scenario. Participants map accountable roles for a citizen-facing service, assess a supplier dependency, score and treat risks, review assurance evidence, and rehearse an executive cyber risk briefing. Group work compares governance choices across central government, local authority and public service contexts without assuming a single operating model. Facilitated peer critique is used to strengthen each participant’s governance pack. The final session converts course outputs into a prioritised 90-day application plan for the participant’s own organisation.

Course outline

Day 1: Public sector cyber governance foundations

  • Public accountability, essential service continuity and citizen trust obligations
  • Three-lines model and the distinction between management, oversight and assurance
  • Cyber governance operating models for departments, agencies and shared-service environments
  • Accountable officer, senior responsible owner and information asset owner responsibilities
  • Governance forums, terms of reference and decision-rights design
  • NIST Cybersecurity Framework 2.0 Govern function and organisational profiles
  • Cyber policy hierarchy, standards, exceptions and documented risk acceptance

Workshop: Participants create a governance RACI and committee escalation map for a fictional public benefits platform.

Day 2: Risk, appetite and treatment decisions

  • Mission impact analysis for citizen services, sensitive information and critical operations
  • NIST Risk Management Framework steps and system authorisation logic
  • Risk identification across assets, data flows, people, suppliers and legacy technology
  • Likelihood, impact, inherent risk and residual risk scoring methods
  • Risk appetite, tolerance thresholds and risk acceptance authority
  • Risk treatment options, control selection and investment prioritisation
  • Risk register design, ownership fields and decision audit trails

Workshop: Participants produce a prioritised cyber risk register and draft risk appetite statements for the scenario organisation.

Day 3: Control assurance and information governance

  • ISO/IEC 27001:2022 governance requirements and Annex A control structure
  • Control objectives, control owners and evidence of operating effectiveness
  • Information asset inventories, data classification and ownership assignment
  • Control assurance plans, testing frequencies and evidence repositories
  • Internal audit coordination and management response tracking
  • Security exceptions, compensating controls and expiry-based review
  • Microsoft Purview use cases for data classification and compliance evidence

Workshop: Participants build a control assurance calendar with named owners, evidence sources, testing methods and remediation checkpoints.

Day 4: Third parties, incidents and oversight reporting

  • Supplier segmentation based on service criticality, data access and substitutability
  • Security requirements in procurement specifications, contracts and service level agreements
  • Third-party due diligence, assurance artefacts and continuous monitoring triggers
  • Cloud shared-responsibility governance and service owner accountability
  • Incident classification, escalation thresholds and executive decision logs
  • Post-incident review governance, lessons learned and corrective action tracking
  • ServiceNow GRC workflows for issues, risk treatment and assurance actions

Workshop: Participants assess a managed-service supplier and produce an escalation brief following a simulated data-security incident.

Day 5: Board reporting and governance implementation

  • Board-level cyber metrics versus operational security metrics
  • Key risk indicators, key control indicators and risk trend interpretation
  • Dashboard design for exposure, resilience, control assurance and supplier risk
  • Writing executive narratives that explain decisions, uncertainty and residual risk
  • Budget cases linking control investment to service and mission outcomes
  • Ninety-day governance implementation planning and dependency mapping
  • Governance pack review against NIST CSF 2.0 and ISO/IEC 27001:2022

Workshop: Participants present their Cyber Security Governance Pack to a simulated audit committee and finalise a 90-day implementation roadmap.

Tools & standards covered

NIST Cybersecurity Framework 2.0, NIST Risk Management Framework (SP 800-37 Rev. 2), ISO/IEC 27001:2022, ServiceNow GRC

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand basic security concepts such as threats, vulnerabilities, controls, incidents and risk registers. The course focuses on governance and decision-making rather than technical configuration, so penetration testing or coding experience is not required.

A laptop is recommended for completing templates, reviewing case material and developing your governance pack. No access to live organisational systems, security consoles or confidential records is needed; exercises use provided scenario data.

Yes, provided they already work with digital, risk, assurance, data or service-delivery decisions. It is particularly useful for leaders who need to challenge cyber risk reports, approve treatments or oversee suppliers without becoming technical security specialists.

This course does not train participants to build an information security management system from scratch or configure security technologies. It concentrates on governance structures, accountable decisions, risk appetite, assurance evidence, supplier oversight and executive reporting in public sector settings.

Participants can use the RACI, risk appetite statements, assurance calendar, dashboard outline and 90-day roadmap to improve an existing governance process. The templates are designed to support conversations with service owners, risk teams, procurement colleagues and senior oversight bodies.

You leave with a completed Cyber Security Governance Pack built during the course, including a governance model, risk register, assurance plan, board dashboard design and implementation roadmap. You also receive a certificate on completion.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Cyber Security Leadership for Information Security Managers Training Course

Information security managers are expected to turn technical risk into decisions that executives, auditors, business owners and operational …

5 Days Certificate

Splunk Enterprise Security SIEM Operations Training Course

Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…

5 Days Certificate

Advanced Cyber Threat Hunting and Incident Response Training Course

Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…

5 Days Certificate

Cyber Security Risk Oversight for Board Directors Training Course

Board directors are increasingly expected to challenge management on cyber security without becoming operational security specialists. They …