Ransomware, phishing, insider misuse and supplier breaches hit organisations of every size, and boards, regulators, banks and donors now ask for proof that information risk is managed systematically. An ISO 27001 management system gives that proof, but only if the underlying risk assessment is sound. Ten days take you from first principles to a working, auditable programme.
The first week builds the foundations: information assets and classification, threat and vulnerability analysis, risk methods in ISO 27005 and NIST SP 800-30, likelihood and impact scoring, the Statement of Applicability and the risk treatment plan. You also study the ISO 27001 clauses on context, leadership, planning, support and operation. The second week goes deeper, with Annex A control families, access management, cryptography, secure development, cloud and supplier risk, incident response, business continuity, vulnerability management, security monitoring, internal audit, management review and certification preparation. Practical labs use sample organisations and tools such as risk registers, MITRE ATT&CK mapping and tabletop exercises. The course is designed for information security officers, IT managers, risk and compliance professionals, auditors, consultants and system owners. It is offered in classroom, online and in-house formats, with a CPD-accredited certificate and a drafted risk assessment for your own organisation.
Information is among the most valuable assets an organisation holds, and it is under constant attack. Phishing, credential theft, ransomware and misconfigured cloud services lead to financial loss, operational shutdown and legal exposure. Many organisations respond with a collection of tools but without a clear view of which risks matter most, who owns them and whether controls are really working.
The Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course gives participants a structured way to answer those questions. The first phase teaches the vocabulary and mechanics of information risk: identifying assets and owners, modelling threats, evaluating vulnerabilities, scoring risk and choosing among treat, tolerate, transfer and terminate options. Participants then see how these results feed the requirements of ISO/IEC 27001, including the Statement of Applicability, objectives, documented information and performance evaluation.
The second phase moves into implementation depth. Participants study technical and organisational controls, test them against realistic attack scenarios, assess third-party and cloud exposure, rehearse incident response and learn how to audit and improve the system. Work is lab-based and cumulative, and every participant develops a risk register, a draft Statement of Applicability and an improvement roadmap that can be adapted to their own environment.
By the end of the course, participants will be able to:
Participants leave the course with:
Over ten days the programme alternates explanation with building real documents. Participants experience:
Day 1: Information Risk and the Threat Landscape
Day 2: ISO 27001 Requirements and Scoping
Day 3: Asset Identification and Classification
Day 4: Risk Assessment Methods
Day 5: Risk Treatment and the Statement of Applicability
Day 6: Organisational and People Controls
Day 7: Technological Controls
Day 8: Cloud, Third-Party and Physical Security Risk
Day 9: Incident Response and Resilience
Day 10: Audit, Improvement and Certification Readiness
The course is designed for professionals who manage, assess or assure information security, such as:
Participants who attend all ten days and complete the lab work and final roadmap presentation are awarded a CPD-accredited Certificate of Completion by Vision Reach Global Consultancy. The certificate recognises training completed and is not a certification under ISO/IEC 27001.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Risk Management for Cybersecurity & Information Security (ISO 27001) programme, you'll be able to explain the structure and requirements of iso/iec 27001 and its relationship to iso 27002 and iso 27005, define the isms scope and build an asset inventory with classification, owners and dependencies, identify threats and vulnerabilities and score risks consistently, and prepare a risk treatment plan and a statement of applicability. The full breakdown of topics is covered session by session in the Course Outline tab above.
The course is designed for professionals who manage, assess or assure information security, such as: Information security officers and managers, IT managers and systems administrators, Risk and compliance officers, Internal and IT auditors, Data protection officers, Cloud and network engineers moving into governance roles, Security consultants and implementers of management systems, and System owners in banks, telecoms, government and NGOs.
Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Risk Management for Cybersecurity & Information Security (ISO 27001) starts October 19, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course is pitched at advanced professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →