Ransomware, phishing, supply chain compromise and insider misuse hit organisations of every size, and boards now hold security leaders to account for the result. Defending against them takes technical skill and a management system that keeps controls working. Ten days build both, with labs and a full ISO/IEC 27001 implementation track.
Early days cover threat landscape analysis, firewalls, segmentation, endpoint hardening, identity and access management, cryptography, vulnerability scanning and log monitoring. Later days move to risk assessment, the Statement of Applicability, Annex A controls, policy writing, supplier security, continuity planning, incident response, forensics basics, internal audit and certification readiness. An integrated project has you assess a simulated organisation, plan treatments and brief its leadership. IT security officers, systems and network administrators, information security managers, risk and audit professionals and ICT leads in banks, telecoms, government and NGOs will gain the most. Afterwards you can lead a risk assessment, harden core systems, respond to a breach and prepare for an ISO 27001 audit. Delivery is by classroom, online or in-house.
Attacks against organisations in East Africa and beyond have grown more frequent and more costly, while regulators, funders and customers ask for evidence of sound information security. Many institutions respond by buying tools, only to discover that unmanaged risk, untrained staff and unclear responsibilities leave them just as exposed. Lasting protection depends on technical safeguards and a management system that is planned, measured and improved.
Applied Cybersecurity & Information Security (ISO 27001) Training Course is a ten-day programme that joins the two. The first block builds technical competence in threats and attack techniques, secure network design, firewalls, endpoint protection, authentication, encryption, patching, vulnerability management and security monitoring. The second block covers the ISO/IEC 27001 framework from scoping and context through risk assessment, risk treatment, the Statement of Applicability and Annex A controls, documentation, awareness, supplier management, incident handling, continuity, internal audit and management review. The closing days apply everything to a simulated organisation.
Participants spend most of each day on practical work. Lab sessions use virtual machines and open-source tools, while case files and templates support the management system work. Each person finishes with a risk register, a set of draft policies and a readiness plan that can be taken back to their workplace.
By the end of the programme, participants will be able to:
Participants leave the programme with:
Because the subject is practical, most time is spent doing rather than listening:
Day 1: Threats, Risk and the Security Landscape
Day 2: Network Security
Day 3: Endpoint, Server and Cloud Hardening
Day 4: Identity, Access and Cryptography
Day 5: Vulnerability Management and Monitoring
Day 6: Starting the ISO/IEC 27001 Management System
Day 7: Risk Assessment and Treatment
Day 8: Operating Controls, Suppliers and Continuity
Day 9: Incident Response, Forensics, Audit and Improvement
Day 10: Integrated Project and Certification Readiness
The programme is intended for technical and management staff who protect or assure information systems, including:
On finishing the ten days with full attendance and completed labs and exercises, each participant receives a Certificate of Completion from Vision Reach Global Consultancy, accredited for CPD. The certificate records completion of this training and is not an ISO 27001 auditor or practitioner qualification.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Applied Cybersecurity & Information Security (ISO 27001) programme, you'll be able to analyse common cyber threats, attack techniques and the weaknesses they exploit, configure and test network, endpoint and access controls using recognised hardening practice, apply encryption, authentication and key management appropriately to business systems, and run vulnerability scans, prioritise findings and plan remediation. The full breakdown of topics is covered session by session in the Course Outline tab above.
The programme is intended for technical and management staff who protect or assure information systems, including: Information security officers and managers, Systems, network and database administrators, IT managers and heads of ICT, Risk, compliance and internal audit professionals, Security operations and incident response team members, Data protection officers working alongside IT, Software and cloud engineers responsible for secure delivery, Consultants preparing clients for ISO 27001 certification, and Government and banking ICT staff in regulated environments.
Applied Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Applied Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Applied Cybersecurity & Information Security (ISO 27001) starts October 19, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Applied Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Applied Cybersecurity & Information Security (ISO 27001) Training Course is pitched at advanced professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Applied Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Applied Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →