Ransomware, phishing, stolen credentials and careless data handling now threaten every organisation that runs on digital systems, from banks and hospitals to schools and county offices. Technical tools alone do not solve the problem; people, processes and governance matter as much. Ten days build understanding from first principles to a working management system. The first half covers the security landscape, the CIA triad, threat actors, malware, social engineering, network and endpoint defence, cryptography, identity and access management, cloud security, secure configuration, logging and incident response.
The second half turns to ISO/IEC 27001: context and scope, leadership, risk assessment and treatment, the Statement of Applicability, Annex A controls, documented information, awareness, monitoring, internal audit, management review and corrective action. Labs and tabletop exercises reinforce each topic. IT officers, system and network administrators, security analysts, risk and compliance staff, auditors, data protection officers and managers who are new to security will benefit. Training is offered in the classroom, online or in-house, with a CPD-accredited certificate. You finish able to protect systems and contribute to an ISMS project.
Information is now among the most valuable and most exposed assets an organisation holds. Breaches interrupt services, expose customers' personal data, trigger regulatory action and damage trust that took years to build. Boards, donors and clients increasingly ask for evidence that security is managed systematically, and ISO/IEC 27001 has become the common way to provide it.
The Fundamentals of Cybersecurity & Information Security (ISO 27001) Training Course gives beginners a thorough ten-day grounding in both the technology and the management system. Early days build core knowledge: how attacks work, how networks, operating systems and applications are hardened, how encryption and authentication protect data, and how monitoring and incident response limit damage. Participants practise in a lab environment with scanning, password and access control exercises, log review and a simulated incident.
The later days follow the structure of ISO/IEC 27001. Participants define scope, identify assets and risks using a recognised method, select and justify controls from Annex A, draft key policies and procedures, and plan awareness, business continuity and supplier security. The final days cover internal audit technique, nonconformities, management review and preparation for an external certification audit. Participants complete an integrated case project that produces a risk register, a Statement of Applicability and an audit report for a fictional organisation.
By the end of the course, participants will be able to:
Participants complete the programme with:
Because the content spans technical and management topics, delivery alternates between demonstration and practice. Participants experience:
Day 1: The Information Security Landscape
Day 2: Threats, Malware and Social Engineering
Day 3: Network and Endpoint Security
Day 4: Cryptography, Identity and Access Management
Day 5: Application, Cloud and Data Security
Day 6: Monitoring, Incident Response and Resilience
Day 7: ISO/IEC 27001 and the ISMS
Day 8: Risk Assessment and Treatment
Day 9: Annex A Controls and Documentation
Day 10: Audit, Review and Certification Readiness
The course is designed for beginners and early-career professionals who need to understand or support information security, including:
Participants who attend the ten days and complete the lab work and case project receive a CPD-accredited Certificate of Completion issued by Vision Reach Global Consultancy.
The certificate confirms completion of this training programme. It is not itself an ISO 27001 auditor registration.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Fundamentals of Cybersecurity & Information Security (ISO 27001) programme, you'll be able to explain core cybersecurity concepts, common threats and attack techniques, apply layered defences to networks, endpoints, applications and cloud services, use encryption, authentication and access control to protect information, and detect and respond to security incidents following a defined process. The full breakdown of topics is covered session by session in the Course Outline tab above.
The course is designed for beginners and early-career professionals who need to understand or support information security, including: IT officers, system administrators and network engineers, Security analysts and helpdesk staff moving into security, Information security and risk managers, Compliance, privacy and data protection officers, Internal and external auditors, Business analysts and project managers on digital projects, Software developers and database administrators, and Managers in banks, telecoms, health, government and NGOs who own information assets.
Fundamentals of Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Fundamentals of Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Fundamentals of Cybersecurity & Information Security (ISO 27001) starts October 12, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Fundamentals of Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Fundamentals of Cybersecurity & Information Security (ISO 27001) Training Course is pitched at beginner professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Fundamentals of Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Fundamentals of Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →