Cyber Security Leadership for Information Security Managers Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-008
Duration5 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Information security managers are expected to turn technical risk into decisions that executives, auditors, business owners and operational teams can act on. That means setting priorities across a crowded control agenda, defending security investment, responding credibly to incidents and proving that governance arrangements work in practice. This course addresses the management gap between knowing cyber security concepts and leading an information security function that can make risk-based, evidence-led decisions.

Over five days, participants build a practical leadership toolkit for governing cyber risk, designing security programmes and communicating with senior stakeholders. The course applies NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022 and FAIR risk analysis to asset priorities, threat scenarios, control selection, supplier assurance, incident oversight and security metrics. Participants learn to establish risk appetite statements, develop a multi-year security roadmap, assess control effectiveness, lead cyber incident decision-making and present a board-ready view of exposure, investment and residual risk.

Teaching combines instructor-led briefings with management simulations, risk workshops, control-design exercises and peer review. Participants work through a running case involving a regulated organisation facing ransomware, cloud concentration risk and third-party exposure. Each participant leaves with a tailored Cyber Security Leadership Action Plan containing a risk register, executive dashboard, control improvement roadmap, incident governance model and 90-day implementation priorities that can be adapted for their own organisation.

The course is designed for experienced security practitioners moving into management, and for current information security managers who need a more disciplined operating model for governance, assurance and executive engagement.

Course objectives

By the end of this course, participants will be able to:

  • Translate business objectives into a documented cyber risk appetite and security governance model
  • Apply NIST Cybersecurity Framework 2.0 profiles to prioritise security capability improvements
  • Conduct FAIR-based risk analyses that quantify loss exposure and support investment decisions
  • Design an ISO/IEC 27001:2022-aligned information security management system improvement plan
  • Build a risk-based security roadmap with owners, milestones, dependencies and measurable outcomes
  • Create board-level cyber security dashboards using KRIs, KPIs, control evidence and residual-risk statements
  • Lead incident governance decisions through escalation thresholds, executive communications and post-incident reviews
  • Produce a 90-day Cyber Security Leadership Action Plan for implementation in the participant's organisation

Benefits of attending

For you

  • Gain a repeatable method for converting technical security concerns into executive risk and investment decisions
  • Build credibility in board and leadership meetings through clear risk appetite, residual-risk and assurance reporting
  • Learn to challenge control owners, suppliers and technical teams using evidence-based governance questions
  • Develop a portfolio-quality Cyber Security Leadership Action Plan for use in management or CISO-track roles
  • Strengthen decision-making during cyber incidents by practising executive escalation and communications scenarios

For your organisation

  • Establish a more consistent process for prioritising security spend against business-critical risk scenarios
  • Improve executive oversight through concise dashboards that distinguish control activity from actual risk reduction
  • Reduce unmanaged residual risk by defining ownership, treatment deadlines and formal risk acceptance criteria
  • Strengthen incident readiness with clearer decision rights, escalation thresholds and post-incident improvement actions
  • Create an actionable security roadmap aligned to NIST CSF 2.0, ISO/IEC 27001:2022 and organisational objectives

Target competencies

Cyber risk governanceFAIR risk analysisExecutive security reportingSecurity roadmap designIncident leadershipControl assurance

Who should attend

  • Information Security Managers — who must govern risk, controls, assurance activity and security investment
  • Cyber Security Managers — who lead operational security teams and need to connect technical priorities to business risk
  • Heads of Information Security — who need an accountable operating model for executive reporting and programme delivery
  • IT Risk Managers — who coordinate technology risk assessments, treatment plans and risk acceptance decisions
  • Security Programme Managers — who manage cross-functional control improvements and security transformation roadmaps
  • Aspiring CISOs — who need practical experience of board communication, governance design and security leadership decisions

Requirements and prerequisites

Participants should have practical experience in information security, IT risk, security operations, audit, compliance or technology management. They should already understand common security concepts such as assets, threats, vulnerabilities, controls, risk treatment, incident response and access management. Familiarity with a risk register, security policies or ISO/IEC 27001 is helpful, and participants should be comfortable reviewing spreadsheets and management reports. No programming, penetration-testing expertise, SIEM administration or formal audit qualification is required. The course explains the use of NIST CSF, FAIR and ISO/IEC 27001 in leadership decisions rather than assuming specialist certification knowledge.

Training methodology

The course uses short instructor-led briefings to introduce leadership methods, followed by workshops that apply them to a realistic organisation case. Participants create risk scenarios, score control evidence, map NIST CSF 2.0 profiles, use FAIR concepts to compare loss exposure and rehearse executive incident decisions. Small-group review sessions test the clarity of dashboards, roadmaps and risk treatment proposals against competing business priorities. On day five, each participant converts the case work into a focused action plan for their own security function, with peer and instructor feedback.

Course outline

Day 1: Security leadership, governance and risk appetite

  • Information security manager accountabilities and decision rights
  • Business service mapping and critical asset identification
  • Threat scenario formulation using loss-event narratives
  • Cyber risk appetite, tolerance and escalation thresholds
  • Three-lines assurance models for information security
  • NIST Cybersecurity Framework 2.0 Govern function
  • Risk register design with inherent and residual risk fields

Workshop: Participants create a cyber risk appetite statement and prioritised risk register for the case organisation's critical business services.

Day 2: Risk analysis and investment prioritisation

  • FAIR factors: loss event frequency and loss magnitude
  • Control effectiveness assessment and evidence collection
  • Risk treatment options: mitigate, transfer, avoid and accept
  • Cost-of-control versus probable loss exposure analysis
  • Security investment business cases and benefits assumptions
  • Third-party and cloud-service risk evaluation
  • Risk acceptance authorities and exception management

Workshop: Participants analyse two competing ransomware risk treatments using FAIR-informed estimates and produce an investment recommendation.

Day 3: Security programme design and assurance

  • ISO/IEC 27001:2022 ISMS leadership and planning clauses
  • Statement of Applicability and control selection logic
  • NIST CSF 2.0 current and target profile mapping
  • Security roadmap sequencing, dependencies and ownership
  • Control testing plans and assurance evidence
  • Supplier security assurance and contractual control requirements
  • Policy hierarchy, standards and exception processes

Workshop: Participants build a 12-month security improvement roadmap with target controls, accountable owners, dependencies and assurance measures.

Day 4: Incident leadership and executive communication

  • Incident command roles and executive decision authorities
  • Ransomware response decisions and business continuity trade-offs
  • Legal, regulatory and customer notification decision points
  • Crisis communications messages for executives and stakeholders
  • Security metrics: KPIs, KRIs and key control indicators
  • Board dashboard design for exposure and programme performance
  • Blameless post-incident review and corrective-action tracking

Workshop: Participants lead a timed ransomware executive briefing and produce a one-page board dashboard with decisions, risks and next actions.

Day 5: Leading the security function

  • Security operating model design and service ownership
  • Capability maturity assessment and improvement baselines
  • Security team skills planning and operating capacity
  • Stakeholder mapping for technology and business executives
  • Influencing risk owners and resolving control delivery conflicts
  • Ninety-day implementation planning and success measures
  • Presenting a defensible cyber security leadership narrative

Workshop: Participants present their Cyber Security Leadership Action Plan and receive structured feedback on priorities, governance and executive messaging.

Tools & standards covered

NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, FAIR, Microsoft Sentinel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

Yes. It is particularly useful for practitioners who understand security operations or controls but now need to make risk, governance, investment and stakeholder decisions. You should already be familiar with core security terminology and operational processes.

No formal certification is required. The course uses ISO/IEC 27001:2022 and NIST CSF 2.0 as management frameworks, explaining how to use them for governance, roadmaps and assurance rather than teaching lead-auditor techniques.

A laptop is recommended for workshop templates, spreadsheet exercises and action-plan development. No access to a live SIEM, vulnerability scanner or production security environment is required; case materials and templates are provided.

This course focuses on leading the information security function rather than configuring tools or investigating alerts. It concentrates on risk appetite, investment choices, assurance, executive reporting, incident governance and programme delivery.

You will leave with working templates and a tailored 90-day action plan covering risk governance, reporting, roadmap priorities and incident decision rights. These can be adapted for your existing risk register, ISMS, board pack or security programme.

The final deliverable is a Cyber Security Leadership Action Plan developed throughout the week. It includes a prioritised risk view, target capability improvements, a control assurance approach, executive dashboard measures and implementation actions.

Upcoming sessions

  • 21 – 25 Sep 2026
    Kigali · USD 3,500
    Book
  • 28 Sep – 02 Oct 2026
    Nairobi · USD 3,000
    Book
  • 28 Sep – 02 Oct 2026
    Mombasa · USD 3,200
    Book
  • 05 – 09 Oct 2026
    Mombasa · USD 3,200
    Book
  • 12 – 16 Oct 2026
    Nairobi · USD 3,000
    Book
  • 26 – 30 Oct 2026
    Nairobi · USD 3,000
    Book
  • 26 – 30 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Kigali · USD 3,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Cyber Security Fundamentals for IT Professionals Training Course

IT professionals are routinely asked to deploy systems, support users, manage cloud services and respond to incidents, yet security controls…

5 Days Certificate

Third Party Cyber Risk Management for Procurement Professionals Training Course

Procurement teams increasingly make award, renewal and sourcing decisions that introduce cyber exposure long before a supplier connects to s…

5 Days Certificate

OWASP Application Security Verification Standard Implementation Training Course

Application teams often have security requirements scattered across user stories, penetration-test findings, supplier questionnaires and pol…

5 Days Certificate

Cyber Security Governance for Government and Public Sector Teams Training Course

Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while work…