Breaches, ransomware and regulatory penalties have moved information security from the server room to the boardroom, and the people who lead it are judged on outcomes rather than tools. Chief information security officers and their managers must align security with strategy, justify budgets, motivate teams and demonstrate control effectiveness. This ten-day programme develops that leadership capability on the foundation of ISO/IEC 27001.
The first five days cover security governance, context and stakeholder analysis, information security policy, risk assessment and treatment, the Statement of Applicability and the Annex A controls, supplier and cloud risk, and awareness. The second five days turn to performance: security operating models, key risk and performance indicators, maturity assessment, internal audit, management review, business continuity, incident response and crisis leadership, building and retaining teams, and preparing for certification audit. Exercises include a risk workshop, a board briefing and a tabletop incident. The programme is aimed at CISOs, information security managers, IT directors, risk and compliance leaders, data protection officers, internal auditors and senior engineers moving into management in banks, telecoms, government and enterprise. Classroom, online and in-house delivery lead to a CPD-accredited certificate. Afterwards you can direct an ISMS and speak credibly with executives.
Cyber incidents now disrupt operations, expose customer data and draw regulatory attention, and executives expect their security leaders to explain risk in business terms. Technical knowledge alone is not enough. Leaders must build a management system, prioritise limited resources, measure whether controls work and keep a team engaged under constant pressure.
The programme combines ISO 27001 management system requirements with leadership and performance management. In the early days participants analyse organisational context, define scope, secure management commitment and build the policy framework. They carry out risk assessment and treatment, select and justify controls from Annex A, and produce a Statement of Applicability. The middle days deal with operational themes: access, cryptography, supplier and cloud security, secure development, logging and monitoring, and the human element. Performance sessions cover security metrics, maturity models, assurance and internal audit, reporting to boards and audit committees, and continual improvement. Final days concentrate on incident and crisis leadership, continuity, team capability and certification readiness.
Learning is interactive and scenario-based. Participants work with sample ISMS documentation, run a risk workshop, conduct an audit exercise and rehearse a ransomware tabletop, finishing with a security leadership plan for their own organisation.
By the end of the programme, participants will be able to:
Participants take away:
Delivery blends management practice with technical depth for senior learners. It includes:
Day 1: Security Leadership and the ISO 27001 Framework
Day 2: Context, Scope and Governance
Day 3: Risk Assessment and Treatment
Day 4: Controls and the Statement of Applicability
Day 5: Supplier, Cloud and Human Risk
Day 6: Security Operating Model and Team Performance
Day 7: Metrics, Maturity and Board Reporting
Day 8: Monitoring, Detection and Incident Leadership
Day 9: Continuity, Resilience and Assurance
Day 10: Certification Readiness and Leadership Plan
The programme is for professionals who direct or are preparing to direct security programmes, including:
Delegates who complete the ten days of sessions and the practical exercises receive a Certificate of Completion from Vision Reach Global Consultancy, accredited for CPD. This is a training certificate and is not an ISO 27001 certification body credential.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Leadership and Performance in Cybersecurity & Information Security (ISO 27001) programme, you'll be able to explain the structure and requirements of iso/iec 27001 and how they support business goals, define isms scope and context and secure leadership commitment, conduct information security risk assessments and select treatments, and prepare a statement of applicability and justify annex a control decisions. The full breakdown of topics is covered session by session in the Course Outline tab above.
The programme is for professionals who direct or are preparing to direct security programmes, including: Chief information security officers and heads of security, Information security and IT security managers, IT directors and chief information officers, Risk, compliance and governance managers, Data protection officers and privacy leads, Internal and IT auditors, Security architects and senior engineers moving into management, Business continuity and resilience managers, and Government, banking, telecom and utility technology leaders.
Leadership and Performance in Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Leadership and Performance in Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Leadership and Performance in Cybersecurity & Information Security (ISO 27001) starts October 26, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Leadership and Performance in Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Leadership and Performance in Cybersecurity & Information Security (ISO 27001) Training Course is pitched at advanced professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Leadership and Performance in Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Leadership and Performance in Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →