Cyber Security Risk Oversight for Board Directors Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-049
Duration5 days
LevelFoundation to Intermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Board directors are increasingly expected to challenge management on cyber security without becoming operational security specialists. They must judge whether cyber risk is being identified, funded and governed appropriately; whether a material incident could disrupt strategic objectives; and whether the organisation can demonstrate reasonable oversight to regulators, investors, customers and insurers. This requires more than receiving technical dashboards or approving annual security budgets. Directors need a disciplined way to ask for evidence, interpret risk exposure and record decisions that stand up to scrutiny.

This course equips directors to oversee cyber security as an enterprise risk. Participants work with the NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022 governance requirements, FAIR risk analysis concepts and MITRE ATT&CK threat intelligence. They learn to define cyber risk appetite, distinguish risk indicators from operational metrics, review incident escalation thresholds, assess third-party exposure, challenge investment proposals and ask focused questions of the CISO, CIO, CRO and executive team. The course also addresses board duties before, during and after a significant cyber incident.

Teaching combines instructor-led briefings with boardroom simulations, risk-dashboard reviews, case analysis and facilitated director discussions. Participants examine a realistic ransomware and data-exfiltration scenario, test the adequacy of a board reporting pack and practise decisions on notification, crisis authority, recovery priorities and remediation funding. Each participant leaves with a tailored Cyber Security Board Oversight Action Plan, including a board-question set, reporting requirements, risk appetite prompts and a 90-day governance improvement agenda.

It is designed for current and aspiring board directors, committee chairs and senior executives who report to boards. The course is suitable for organisations in regulated, critical infrastructure, financial, public sector and data-intensive environments, while remaining practical for directors of smaller enterprises and non-profit boards.

Course objectives

By the end of this course, participants will be able to:

  • Define a cyber risk appetite statement with measurable tolerance thresholds for disruption, data loss, regulatory exposure and third-party failure
  • Interpret a board-level cyber risk dashboard using key risk indicators, key performance indicators, control effectiveness measures and trend analysis
  • Apply NIST Cybersecurity Framework 2.0 Govern and Identify functions to structure board oversight responsibilities
  • Challenge a CISO investment proposal using business-case assumptions, risk-reduction evidence, residual risk and prioritisation criteria
  • Use FAIR risk analysis concepts to translate cyber scenarios into probable loss exposure and decision-relevant financial ranges
  • Evaluate incident response escalation, notification and recovery decisions through a boardroom ransomware simulation
  • Assess supplier and cloud-provider cyber exposure using due-diligence evidence, contractual controls and concentration-risk questions
  • Produce a Cyber Security Board Oversight Action Plan with reporting requirements, committee actions and a 90-day improvement schedule

Benefits of attending

For you

  • Gain a repeatable question framework for challenging cyber reports without relying on technical jargon
  • Build credibility as a director who can connect security exposure to strategy, finance, resilience and fiduciary oversight
  • Practise decision-making for ransomware, data breach and major supplier-failure scenarios in a boardroom setting
  • Learn to distinguish meaningful risk evidence from reassuring but weak operational security metrics
  • Leave with a personal board oversight action plan that can be used in committee agendas and director discussions

For your organisation

  • Improves the quality and consistency of board challenge applied to cyber strategy, budgets and residual-risk acceptance
  • Establishes clearer expectations for cyber risk dashboards, escalation triggers and management reporting
  • Reduces the likelihood of delayed or poorly governed decisions during a material cyber incident
  • Strengthens oversight of third-party, cloud and supply-chain cyber dependencies
  • Creates a practical 90-day agenda for aligning cyber governance with enterprise risk and regulatory expectations

Target competencies

Cyber risk oversightBoard challenge techniquesRisk appetite settingIncident governanceDashboard interpretationThird-party risk review

Who should attend

  • Board Directors — who must evidence informed oversight of cyber risk and management decisions
  • Non-Executive Directors — who need to challenge executive assurances without managing technical controls
  • Audit and Risk Committee Chairs — who review risk reporting, assurance findings and material control deficiencies
  • Board Technology or Cyber Committee Members — who require a structured governance lens for security investment and resilience
  • Chief Executive Officers — who sponsor cyber strategy and must communicate risk decisions to the board
  • Chief Risk Officers — who integrate cyber exposure into enterprise risk appetite and board reporting

Requirements and prerequisites

No technical cyber security qualification, coding experience or security-tool administration is required. Participants should have experience reading board papers, risk registers, management reports or investment proposals, and should understand basic business concepts such as risk appetite, financial impact, governance and accountability. Familiarity with their organisation's strategic objectives, major technology dependencies and current cyber reporting will make the exercises more valuable. Complete beginners to cyber security are welcome; they should expect a clear introduction to common threats, controls and terminology before applying them to board decisions. A laptop or tablet capable of viewing course workbooks is recommended, but no specialist software is needed.

Training methodology

The five days combine director-focused instructor sessions with evidence-based boardroom practice. Participants review anonymised cyber dashboards, audit findings, incident reports and investment cases, then identify the questions and decisions a board should make. Small groups conduct a FAIR-informed risk discussion, assess a supplier assurance pack and rehearse an executive escalation meeting during a ransomware scenario. Facilitated debriefs link each exercise to NIST CSF 2.0 and ISO/IEC 27001:2022 governance expectations. On the final day, each participant builds a prioritised action plan for their own board or committee.

Course outline

Day 1: The Board's Cyber Security Mandate

  • Board fiduciary duties and cyber security oversight accountabilities
  • Cyber risk as an enterprise risk rather than an IT issue
  • NIST Cybersecurity Framework 2.0 Govern function
  • ISO/IEC 27001:2022 leadership and governance requirements
  • Director and executive roles in the three-lines model
  • Cyber risk appetite, tolerance and risk acceptance authorities
  • Board questions that expose unsupported management assurance

Workshop: Participants review a sample board cyber report and produce a prioritised list of challenge questions, missing evidence and required decisions.

Day 2: Risk, Threat and Control Evidence

  • Cyber threat scenarios and business-impact pathways
  • MITRE ATT&CK techniques for understanding adversary behaviour
  • FAIR loss event frequency and loss magnitude concepts
  • Risk registers, scenario statements and residual-risk ratings
  • Control design, operating effectiveness and independent assurance
  • Key risk indicators versus key performance indicators
  • Board-level cyber dashboard design and metric thresholds

Workshop: Participants redesign a weak cyber dashboard into a board-ready reporting pack with risk indicators, trend commentary and escalation thresholds.

Day 3: Investment, Resilience and Third-Party Exposure

  • Evaluating cyber investment business cases and benefit claims
  • Security programme prioritisation using risk-reduction evidence
  • Cyber resilience, recovery time objectives and service dependencies
  • Cloud shared-responsibility models and board accountability
  • Supplier due diligence, assurance reports and contract controls
  • Third-party concentration risk and critical-service mapping
  • Cyber insurance, exclusions and evidence of reasonable controls

Workshop: Groups assess a proposed security investment and supplier assurance pack, then prepare a board recommendation on funding, conditions and residual risk.

Day 4: Incident Governance and Crisis Decisions

  • Materiality thresholds and board incident escalation criteria
  • Ransomware, data exfiltration and business interruption scenarios
  • Crisis governance structures and delegated decision authorities
  • Regulatory, customer and stakeholder notification decisions
  • Legal privilege, forensic evidence and decision documentation
  • Communications oversight during a cyber crisis
  • Post-incident lessons, remediation tracking and assurance

Workshop: Participants complete a boardroom ransomware simulation and produce an incident decision log covering escalation, communications, recovery priorities and remediation oversight.

Day 5: Embedding Effective Board Oversight

  • Cyber committee charters and annual board workplans
  • CISO reporting cadence and minimum board information requirements
  • Integrating cyber exposure into enterprise risk reporting
  • Reviewing internal audit and external assurance findings
  • Documenting risk acceptance and board challenge
  • Measuring governance maturity and improvement progress
  • Ninety-day cyber oversight implementation planning

Workshop: Participants produce and peer-review a Cyber Security Board Oversight Action Plan for their organisation, including reporting changes, committee actions and 90-day priorities.

Tools & standards covered

NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, FAIR, MITRE ATT&CK

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course is designed for directors and senior decision-makers rather than security practitioners. It explains essential threats, controls and terminology before applying them to governance, risk appetite and board challenge.

A laptop or tablet is recommended for reviewing workbooks and completing the action plan. You will not need access to security platforms, internal networks or confidential organisational data.

It is most suitable for board directors, non-executive directors, audit and risk committee members, CEOs and CROs. CISOs and CIOs may also attend when they need to improve the quality of board engagement and reporting.

This course does not teach participants to configure controls, investigate malware or operate a security operations centre. It focuses on the board's decisions: risk appetite, assurance, investment challenge, incident authority and evidence of effective oversight.

Participants receive practical prompts for reviewing dashboards, investment cases, incident reports and supplier risk papers. The final action plan can be adapted into committee agenda items, reporting requirements and a 90-day governance programme.

Each participant leaves with a completed Cyber Security Board Oversight Action Plan, a board-question framework and examples of effective dashboard and incident-governance requirements. These materials are designed for direct adaptation to the participant's governance context.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Operational Technology Cyber Security for Energy Utilities Training Course

Energy utilities operate control environments where a cyber incident can interrupt generation, transmission, distribution, water processing,…

5 Days Certificate

Okta Identity Engine Access Management Security Training Course

Okta administrators and identity security teams are often expected to strengthen access controls without creating sign-in friction, breaking…

5 Days Certificate

Tenable Nessus Professional Vulnerability Assessment Training Course

Vulnerability assessment programmes often fail not because organisations lack a scanner, but because scan scope is incomplete, credentials a…

5 Days Certificate

Network and Endpoint Security Foundations Training Course

Network and endpoint security failures rarely begin with a single dramatic breach. They emerge through exposed services, unmanaged laptops, …