Cyber Security Leadership for Information Security Managers Training Course
| Course code | SD-CS-008 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Information security managers are expected to turn technical risk into decisions that executives, auditors, business owners and operational teams can act on. That means setting priorities across a crowded control agenda, defending security investment, responding credibly to incidents and proving that governance arrangements work in practice. This course addresses the management gap between knowing cyber security concepts and leading an information security function that can make risk-based, evidence-led decisions.
Over five days, participants build a practical leadership toolkit for governing cyber risk, designing security programmes and communicating with senior stakeholders. The course applies NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022 and FAIR risk analysis to asset priorities, threat scenarios, control selection, supplier assurance, incident oversight and security metrics. Participants learn to establish risk appetite statements, develop a multi-year security roadmap, assess control effectiveness, lead cyber incident decision-making and present a board-ready view of exposure, investment and residual risk.
Teaching combines instructor-led briefings with management simulations, risk workshops, control-design exercises and peer review. Participants work through a running case involving a regulated organisation facing ransomware, cloud concentration risk and third-party exposure. Each participant leaves with a tailored Cyber Security Leadership Action Plan containing a risk register, executive dashboard, control improvement roadmap, incident governance model and 90-day implementation priorities that can be adapted for their own organisation.
The course is designed for experienced security practitioners moving into management, and for current information security managers who need a more disciplined operating model for governance, assurance and executive engagement.
Course objectives
By the end of this course, participants will be able to:
- Translate business objectives into a documented cyber risk appetite and security governance model
- Apply NIST Cybersecurity Framework 2.0 profiles to prioritise security capability improvements
- Conduct FAIR-based risk analyses that quantify loss exposure and support investment decisions
- Design an ISO/IEC 27001:2022-aligned information security management system improvement plan
- Build a risk-based security roadmap with owners, milestones, dependencies and measurable outcomes
- Create board-level cyber security dashboards using KRIs, KPIs, control evidence and residual-risk statements
- Lead incident governance decisions through escalation thresholds, executive communications and post-incident reviews
- Produce a 90-day Cyber Security Leadership Action Plan for implementation in the participant's organisation
Benefits of attending
For you
- Gain a repeatable method for converting technical security concerns into executive risk and investment decisions
- Build credibility in board and leadership meetings through clear risk appetite, residual-risk and assurance reporting
- Learn to challenge control owners, suppliers and technical teams using evidence-based governance questions
- Develop a portfolio-quality Cyber Security Leadership Action Plan for use in management or CISO-track roles
- Strengthen decision-making during cyber incidents by practising executive escalation and communications scenarios
For your organisation
- Establish a more consistent process for prioritising security spend against business-critical risk scenarios
- Improve executive oversight through concise dashboards that distinguish control activity from actual risk reduction
- Reduce unmanaged residual risk by defining ownership, treatment deadlines and formal risk acceptance criteria
- Strengthen incident readiness with clearer decision rights, escalation thresholds and post-incident improvement actions
- Create an actionable security roadmap aligned to NIST CSF 2.0, ISO/IEC 27001:2022 and organisational objectives
Target competencies
Who should attend
- Information Security Managers — who must govern risk, controls, assurance activity and security investment
- Cyber Security Managers — who lead operational security teams and need to connect technical priorities to business risk
- Heads of Information Security — who need an accountable operating model for executive reporting and programme delivery
- IT Risk Managers — who coordinate technology risk assessments, treatment plans and risk acceptance decisions
- Security Programme Managers — who manage cross-functional control improvements and security transformation roadmaps
- Aspiring CISOs — who need practical experience of board communication, governance design and security leadership decisions
Requirements and prerequisites
Participants should have practical experience in information security, IT risk, security operations, audit, compliance or technology management. They should already understand common security concepts such as assets, threats, vulnerabilities, controls, risk treatment, incident response and access management. Familiarity with a risk register, security policies or ISO/IEC 27001 is helpful, and participants should be comfortable reviewing spreadsheets and management reports. No programming, penetration-testing expertise, SIEM administration or formal audit qualification is required. The course explains the use of NIST CSF, FAIR and ISO/IEC 27001 in leadership decisions rather than assuming specialist certification knowledge.
Training methodology
The course uses short instructor-led briefings to introduce leadership methods, followed by workshops that apply them to a realistic organisation case. Participants create risk scenarios, score control evidence, map NIST CSF 2.0 profiles, use FAIR concepts to compare loss exposure and rehearse executive incident decisions. Small-group review sessions test the clarity of dashboards, roadmaps and risk treatment proposals against competing business priorities. On day five, each participant converts the case work into a focused action plan for their own security function, with peer and instructor feedback.
Course outline
Day 1: Security leadership, governance and risk appetite
- Information security manager accountabilities and decision rights
- Business service mapping and critical asset identification
- Threat scenario formulation using loss-event narratives
- Cyber risk appetite, tolerance and escalation thresholds
- Three-lines assurance models for information security
- NIST Cybersecurity Framework 2.0 Govern function
- Risk register design with inherent and residual risk fields
Workshop: Participants create a cyber risk appetite statement and prioritised risk register for the case organisation's critical business services.
Day 2: Risk analysis and investment prioritisation
- FAIR factors: loss event frequency and loss magnitude
- Control effectiveness assessment and evidence collection
- Risk treatment options: mitigate, transfer, avoid and accept
- Cost-of-control versus probable loss exposure analysis
- Security investment business cases and benefits assumptions
- Third-party and cloud-service risk evaluation
- Risk acceptance authorities and exception management
Workshop: Participants analyse two competing ransomware risk treatments using FAIR-informed estimates and produce an investment recommendation.
Day 3: Security programme design and assurance
- ISO/IEC 27001:2022 ISMS leadership and planning clauses
- Statement of Applicability and control selection logic
- NIST CSF 2.0 current and target profile mapping
- Security roadmap sequencing, dependencies and ownership
- Control testing plans and assurance evidence
- Supplier security assurance and contractual control requirements
- Policy hierarchy, standards and exception processes
Workshop: Participants build a 12-month security improvement roadmap with target controls, accountable owners, dependencies and assurance measures.
Day 4: Incident leadership and executive communication
- Incident command roles and executive decision authorities
- Ransomware response decisions and business continuity trade-offs
- Legal, regulatory and customer notification decision points
- Crisis communications messages for executives and stakeholders
- Security metrics: KPIs, KRIs and key control indicators
- Board dashboard design for exposure and programme performance
- Blameless post-incident review and corrective-action tracking
Workshop: Participants lead a timed ransomware executive briefing and produce a one-page board dashboard with decisions, risks and next actions.
Day 5: Leading the security function
- Security operating model design and service ownership
- Capability maturity assessment and improvement baselines
- Security team skills planning and operating capacity
- Stakeholder mapping for technology and business executives
- Influencing risk owners and resolving control delivery conflicts
- Ninety-day implementation planning and success measures
- Presenting a defensible cyber security leadership narrative
Workshop: Participants present their Cyber Security Leadership Action Plan and receive structured feedback on priorities, governance and executive messaging.
Tools & standards covered
NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, FAIR, Microsoft Sentinel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Kigali · USD 3,500 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Mombasa · USD 3,200 -
05 – 09 Oct 2026Book
Mombasa · USD 3,200 -
12 – 16 Oct 2026Book
Nairobi · USD 3,000 -
26 – 30 Oct 2026Book
Nairobi · USD 3,000 -
26 – 30 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Kigali · USD 3,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Cyber Security Fundamentals for IT Professionals Training Course
IT professionals are routinely asked to deploy systems, support users, manage cloud services and respond to incidents, yet security controls…
Third Party Cyber Risk Management for Procurement Professionals Training Course
Procurement teams increasingly make award, renewal and sourcing decisions that introduce cyber exposure long before a supplier connects to s…
OWASP Application Security Verification Standard Implementation Training Course
Application teams often have security requirements scattered across user stories, penetration-test findings, supplier questionnaires and pol…
Cyber Security Governance for Government and Public Sector Teams Training Course
Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while work…