Ransomware, phishing and insider misuse now threaten banks, hospitals, government systems and small businesses alike, and customers and regulators expect proof that information is protected. Ten days give security practitioners both the management system and the technical depth. The first week covers cyber threats, the CIA triad, governance, ISO/IEC 27001 clauses, scoping, asset registers, risk assessment and treatment, the Statement of Applicability and the Annex A controls, with NIST CSF and ISO 27005 as companions.
The second week moves into technical and operational practice: network and endpoint hardening, identity and access management, encryption, vulnerability scanning and penetration testing basics, secure configuration, cloud security, logging with SIEM, incident response, digital forensics fundamentals, business continuity, supplier risk and internal auditing against the standard. Labs use Kali Linux, Wireshark, Nmap and open-source monitoring tools. The programme is written for IT managers, security officers, system and network administrators, auditors, risk and compliance staff and data protection officers in banks, telecoms, government and enterprises. Delivery is classroom, online or in-house with a CPD-accredited certificate. Afterwards you can lead an ISO 27001 implementation and run a first internal audit.
Information is among the most valuable and most exposed assets that any organisation holds. Attackers target payment systems, personal records and operational technology, while staff mistakes and weak supplier controls cause as many breaches as hostile actors. Boards want assurance, customers ask about certification, and data protection obligations make poor security an expensive legal risk as well as an operational one.
This ten-day programme provides a complete route through information security. It starts with threats, governance and risk, and takes participants through the structure of ISO/IEC 27001, the building of an information security management system and the selection of controls. It then drops into the technical layers: networks, hosts, applications, identities, data and cloud services. Participants learn how to detect, contain and learn from incidents, test their own defences and maintain continuity when systems fail.
Throughout, management documents and technical labs run in parallel so that policy is connected to practice. Participants draft a scope statement, risk register and Statement of Applicability, then test controls in a lab network. The final days integrate everything into a simulated certification readiness review, an internal audit and a plan of improvements for their own environment.
By the end of the course, participants will be able to:
Participants leave the course with:
Ten days allow management practice and technical labs to reinforce each other. The delivery combines:
Day 1: Threat Landscape and Security Fundamentals
Day 2: Introduction to ISO/IEC 27001
Day 3: Assets and Risk Assessment
Day 4: Risk Treatment and Controls
Day 5: Documentation, Operation and Metrics
Day 6: Network and Endpoint Security
Day 7: Identity, Cryptography and Application Security
Day 8: Monitoring, Vulnerability Management and Testing
Day 9: Cloud, Suppliers, Incident Response and Continuity
Day 10: Internal Audit and Certification Readiness
The course is intended for professionals responsible for protecting information and systems, including:
Participants who attend all ten days and complete the labs, case documents and final project are awarded a CPD-accredited Certificate of Completion issued by Vision Reach Global Consultancy. This is a training certificate and does not replace an examination-based lead implementer or auditor qualification.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Professional Cybersecurity & Information Security (ISO 27001) programme, you'll be able to explain the clauses and annex a controls of iso/iec 27001 and how certification works, define the scope of an information security management system and build an asset register, carry out a risk assessment and select treatments, producing a statement of applicability, and harden networks, servers, endpoints and user accounts against common attack techniques. The full breakdown of topics is covered session by session in the Course Outline tab above.
The course is intended for professionals responsible for protecting information and systems, including: Chief information security officers and IT security managers, Systems, network and cloud administrators, Information security and risk analysts, IT auditors and internal auditors, Compliance managers and data protection officers, Software and DevOps engineers with security duties, IT managers in banks, telecoms, health and government institutions, and Consultants preparing clients for ISO 27001 certification.
Professional Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Professional Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Professional Cybersecurity & Information Security (ISO 27001) starts November 2, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Professional Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Professional Cybersecurity & Information Security (ISO 27001) Training Course is pitched at advanced professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Professional Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Professional Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →