Cybersecurity Governance for Chief Information Security Officers Training Course

5 days Executive Management Certificate on completion
Course codeSD-EM-033
Duration5 days
LevelIntermediate to Advanced
CategoryExecutive Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Chief Information Security Officers are expected to translate a changing threat landscape, regulatory exposure and technology risk into decisions that boards and executive teams can act on. That requires more than a security strategy or a risk register: it requires defensible governance, clear accountabilities, measurable risk appetite, credible reporting and investment cases that connect cyber controls to business outcomes. This course addresses the practical challenge of establishing security governance that can withstand board scrutiny, regulatory examination, major incidents and competing transformation priorities.

Participants learn to design and operate a cybersecurity governance model aligned to enterprise strategy. The course covers board reporting, risk appetite statements, three-lines-of-defence operating models, policy architecture, control ownership, security portfolio governance, third-party oversight, regulatory mapping and executive incident decision-making. Participants practise using NIST CSF 2.0, ISO/IEC 27001:2022 and FAIR concepts to prioritise risks, quantify exposure where appropriate, assign accountable owners and build performance indicators that distinguish control activity from risk reduction.

Teaching combines instructor-led executive briefings with CISO-level case work, governance design workshops and peer challenge sessions. Working from a realistic multinational business scenario, participants develop a Cybersecurity Governance Charter and board-ready governance pack containing a decision-rights model, risk appetite measures, committee structure, reporting dashboard, policy hierarchy and 90-day implementation roadmap. The deliverable can be adapted directly to the participant's organisation after the course.

The programme is designed for experienced security leaders who already manage security functions, major risk domains or enterprise technology services and need to influence at board, executive committee and business-unit level. It is equally valuable to newly appointed CISOs establishing their operating model and established CISOs seeking to strengthen assurance, accountability and investment governance.

Course objectives

By the end of this course, participants will be able to:

  • Design a cybersecurity governance operating model using decision rights, committee charters and accountable control ownership
  • Draft a board-approved cyber risk appetite statement with measurable thresholds, escalation triggers and treatment boundaries
  • Map NIST CSF 2.0 and ISO/IEC 27001:2022 requirements into a practical policy and control governance architecture
  • Build a board cybersecurity dashboard using key risk indicators, key performance indicators and risk trend narratives
  • Apply FAIR concepts to frame loss exposure and prioritise material cyber risk investment decisions
  • Establish third-party cyber governance processes covering tiering, contractual controls, assurance evidence and exception approvals
  • Lead executive-level incident governance through predefined decision authorities, crisis communications and post-incident accountability
  • Produce a 90-day cybersecurity governance implementation roadmap with milestones, owners, dependencies and success measures

Benefits of attending

For you

  • Gain a repeatable structure for presenting cyber risk and investment choices to boards and executive committees
  • Build credibility as a business-oriented CISO who links security decisions to financial, operational and regulatory exposure
  • Develop a governance charter and reporting pack that can accelerate a new CISO mandate or operating-model reset
  • Strengthen the ability to challenge control owners, technology leaders and suppliers using clear decision rights and evidence
  • Prepare for senior security leadership roles requiring accountability for enterprise risk, resilience and regulatory assurance

For your organisation

  • Establish clearer accountability for cyber risk acceptance, control ownership and exception approvals across business and technology teams
  • Improve board decision-making through concise reporting that shows material risk, treatment progress and investment trade-offs
  • Reduce governance gaps by aligning policy, risk, assurance and incident escalation processes to recognised standards
  • Prioritise security spending against material loss exposure rather than relying on tool-driven or compliance-only justifications
  • Create an actionable 90-day roadmap for strengthening governance without waiting for a major incident or regulatory finding

Target competencies

Board risk reportingGovernance model designRisk appetite settingControl ownershipExecutive incident leadershipSecurity investment prioritisation

Who should attend

  • Chief Information Security Officers — who must establish board-confidence governance and defend cyber investment decisions
  • Deputy and aspiring CISOs — who are preparing to assume enterprise-wide security leadership responsibilities
  • Heads of Cybersecurity and Security Operations — who need to connect operational controls to executive risk oversight
  • Directors of Information Security Risk and Compliance — who design assurance, policy and regulatory accountability structures
  • Chief Risk Officers and Enterprise Risk Leaders — who need to integrate cyber risk into enterprise risk governance
  • Chief Information Officers and Technology Directors — who share accountability for technology risk, resilience and security investment

Requirements and prerequisites

Participants should have at least three years of experience in cybersecurity management, technology risk, IT governance or a closely related leadership role. They should understand core concepts including security controls, risk registers, incident response, third-party risk and security policies, and be comfortable discussing risk with senior stakeholders. Familiarity with NIST CSF, ISO/IEC 27001 or an enterprise GRC platform is helpful but not essential. No programming, penetration-testing expertise, audit qualification or quantitative risk-modelling background is required. Participants should bring awareness of their organisation's governance challenges, reporting practices and major regulatory obligations.

Training methodology

The course uses facilitated CISO-level discussions, short instructor briefings and structured workshops rather than technical lab work. Participants analyse board papers, regulatory findings, control exceptions and incident scenarios drawn from a realistic enterprise case. Small groups construct governance artefacts including committee terms of reference, risk appetite thresholds, dashboard measures and investment decision papers, then defend them in executive simulation sessions. Each participant adapts the work to their own context and completes a 90-day implementation plan, with instructor feedback on feasibility, stakeholder sequencing and evidence of success.

Course outline

Day 1: The CISO Governance Mandate

  • Cybersecurity governance versus security management
  • Board, executive and management accountability structures
  • Three lines model for cyber risk oversight
  • Decision-rights matrices using RACI and RAPID
  • CISO mandate definition and delegation boundaries
  • Governance failure patterns from major incidents
  • Cybersecurity Governance Charter components

Workshop: Participants assess a fragmented governance scenario and produce a draft decision-rights matrix and CISO Governance Charter outline.

Day 2: Risk Appetite, Measurement and Board Reporting

  • Cyber risk taxonomy and aggregation methods
  • Risk appetite statements and tolerance thresholds
  • FAIR loss event frequency and magnitude concepts
  • Key risk indicators versus key performance indicators
  • Risk register quality and treatment accountability
  • Board dashboard design and narrative reporting
  • Escalation triggers for material cyber risk

Workshop: Participants build a board dashboard and risk appetite scorecard for a simulated organisation facing ransomware, supplier and cloud risks.

Day 3: Control, Policy and Assurance Governance

  • NIST CSF 2.0 Govern function application
  • ISO/IEC 27001:2022 leadership and governance clauses
  • Policy hierarchy from board policy to technical standard
  • Control ownership and control attestation models
  • Exception management and risk acceptance workflows
  • Internal audit, second-line and independent assurance coordination
  • Evidence-based control effectiveness reporting

Workshop: Participants design a policy hierarchy, control-owner model and exception approval workflow for a regulated digital business.

Day 4: Strategic Oversight of Suppliers, Resilience and Incidents

  • Third-party cyber risk tiering criteria
  • Contractual security requirements and assurance evidence
  • Cloud shared-responsibility governance
  • Cyber resilience governance and recovery objectives
  • Executive incident command decision authorities
  • Regulatory notification and stakeholder communication governance
  • Post-incident review and remediation accountability

Workshop: Teams run an executive incident governance simulation and produce a decision log, stakeholder escalation plan and remediation oversight structure.

Day 5: Investment Governance and Implementation

  • Cybersecurity strategy alignment to business objectives
  • Security portfolio prioritisation and investment cases
  • Cost, risk reduction and residual risk trade-offs
  • Security programme steering committee design
  • GRC platform workflow and reporting requirements
  • Maturity roadmaps and governance operating cadence
  • Ninety-day governance implementation planning

Workshop: Participants consolidate their work into a board-ready governance pack and present a prioritised 90-day implementation roadmap for peer and instructor review.

Tools & standards covered

NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, FAIR (Factor Analysis of Information Risk), ServiceNow Integrated Risk Management

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

This is an intermediate-to-advanced leadership course for people who already understand cybersecurity operations, risk or compliance. Participants should be able to discuss security controls, risk registers and incident response; they do not need to be technical specialists or auditors.

A laptop is recommended for completing the governance templates and adapting the final roadmap. Access to a live GRC platform is not required, and participants should not bring confidential risk registers, incident records or supplier data.

No. It is also suited to deputy CISOs, security directors, cyber risk leaders, CIOs and enterprise risk leaders with responsibility for governance decisions. The material assumes participants need to influence executive stakeholders rather than manage a technical security tool.

The course does not train participants to implement an ISMS clause by clause or perform technical vulnerability assessments. It focuses on the CISO's executive governance role: decision rights, risk appetite, board reporting, assurance, investment and incident accountability.

Participants leave with a draft governance charter, dashboard structure, policy hierarchy, decision-rights model and 90-day roadmap. These artefacts are designed to be tailored for executive sponsorship, committee approval or a governance improvement programme.

The course applies NIST CSF 2.0, ISO/IEC 27001:2022 and FAIR concepts as practical governance reference points. It shows how to use them to structure accountability and reporting, not merely to complete a compliance checklist.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Executive Management

5 Days Certificate

Strategic Portfolio Reporting with Microsoft Project Training Course

Senior leaders need portfolio reports that show more than a list of projects. They need reliable answers to questions about strategic alignm…

5 Days Certificate

Diligent Boards Governance Administration for Executive Teams Training Course

Executive teams depend on timely, controlled board information, yet many governance processes still rely on emailed papers, inconsistent age…

5 Days Certificate

Advanced Enterprise Portfolio Governance for Senior Executives Training Course

Enterprise portfolios fail when executives approve initiatives individually but lack a disciplined way to compare strategic value, capacity …

5 Days Certificate

Management of Portfolios MoP for Executive Investment Governance Training Course

Executive teams often approve initiatives one business case at a time, only to find that the combined change load exceeds available funding,…