Ransomware, phishing, stolen credentials and misconfigured cloud services hit organisations of every size, and clients, regulators and donors increasingly ask for proof of control. A security programme must combine technical defences that actually work with a management system that keeps them working. Over ten days, IT and security staff gain both, with the emphasis on doing rather than reading slides.
The first week covers threats and attack methods, network and endpoint hardening, firewalls, identity and access management, multi-factor authentication, encryption, patching, logging and vulnerability scanning with tools such as Nmap and Wireshark in a lab environment. The second week turns to ISO/IEC 27001: scoping, context and leadership, risk assessment and treatment, the Statement of Applicability, Annex A controls, policies, supplier and cloud security, business continuity, incident response, internal audit and preparation for certification. A final exercise brings technical and management work together in a simulated attack and response. The programme is for system and network administrators, security officers, IT managers, auditors, risk and compliance staff and developers in banks, telecoms, government and NGOs. It runs in classroom, online and in-house formats. You leave with a risk register, draft policies, a hardened lab environment, an incident playbook and a CPD-accredited certificate.
Every organisation now depends on information systems, and every one is a target. Attacks no longer need sophistication to succeed; weak passwords, unpatched servers, over-privileged accounts and untrained staff provide plenty of openings. Security that is limited to a few tools tends to decay, which is why standards-based management matters alongside technical skill.
This ten-day course is split deliberately between practice and management. The opening days establish the threat landscape and the fundamentals of securing networks, operating systems, applications and cloud services, with laboratory exercises in scanning, hardening, access control, encryption and log analysis. Participants learn how to detect problems, prioritise vulnerabilities and contain an incident. The second part introduces ISO/IEC 27001 and shows how to build an information security management system around real risks: defining scope, assessing and treating risk, selecting controls, writing policies and procedures, training staff and measuring performance.
The last days address supplier and cloud risk, business continuity, internal audit and certification readiness. Delegates finish with a documented set of risk and control artefacts for their own organisation, and a team simulation that tests detection, response and reporting under time pressure.
By the end of the course, participants will be able to:
Participants leave the course with:
This is a laboratory-based programme in which concepts are always followed by practice:
Day 1: Threat Landscape and Security Fundamentals
Day 2: Network Security
Day 3: Endpoint and Server Hardening
Day 4: Identity, Access and Cryptography
Day 5: Application, Cloud and Mobile Security
Day 6: Monitoring, Detection and Incident Response
Day 7: ISO 27001 and the ISMS
Day 8: Risk Assessment and Treatment
Day 9: Operating the ISMS
Day 10: Certification Readiness and Simulation
The course is meant for people who secure, manage or assure information systems, including:
Participants who attend the ten days and complete the labs and workshops receive a CPD-accredited Certificate of Completion from Vision Reach Global Consultancy. It confirms training completed and is not an ISO 27001 auditor qualification.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Practical Cybersecurity & Information Security (ISO 27001) programme, you'll be able to describe common attack techniques and how defenders detect and block them, harden servers, workstations, network devices and cloud accounts, configure access control, multi-factor authentication and encryption, and scan for vulnerabilities and analyse logs to spot suspicious behaviour. The full breakdown of topics is covered session by session in the Course Outline tab above.
The course is meant for people who secure, manage or assure information systems, including: System, network and database administrators, Information security officers and analysts, IT managers and heads of ICT, Internal and IT auditors, Risk, compliance and data protection officers, Software developers and DevOps engineers, Security staff in banks, telecoms, government and NGOs, and Consultants preparing clients for ISO 27001 certification.
Practical Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Practical Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Practical Cybersecurity & Information Security (ISO 27001) starts October 19, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Practical Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Practical Cybersecurity & Information Security (ISO 27001) Training Course is pitched at intermediate professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Practical Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Practical Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →