Ransomware, supply chain compromise and cloud misconfiguration have moved information security from an IT concern to a board agenda item. Defenders who simply add tools to a growing pile still lose ground. This 10-day programme teaches leaders to set direction first: understand the threat landscape, define risk appetite, align security to business objectives and then build a management system that can be audited. You study ISO/IEC 27001 clauses and Annex A controls, scoping, the statement of applicability, risk assessment and treatment, policies, metrics and internal audit, alongside NIST Cybersecurity Framework functions.
The second week concentrates on innovation and depth. Sessions address zero trust architecture, identity and access governance, cloud security posture, DevSecOps, security automation, threat intelligence, detection engineering, incident response, resilience testing and the security implications of AI. Labs and tabletop exercises put the ideas under pressure. The programme is meant for chief information security officers, security managers, IT directors, risk and compliance leaders, auditors and architects in banks, telecoms, government and enterprises. Afterwards you can lead an ISO 27001 implementation, brief a board on cyber risk and prioritise investment. Classroom, online and in-house delivery are available, with a CPD-accredited certificate.
Digital services now underpin payments, health records, public services and supply chains, which makes security failures immediately visible to customers and regulators. Attackers are organised and quick to exploit new technology, while security budgets remain limited. Leaders need a strategy that targets the risks that matter most and a management system that shows, credibly, that controls work.
The programme begins with threat landscape analysis and the development of a security strategy tied to business priorities, governance structures and metrics. It then covers the full ISO/IEC 27001 lifecycle: context and scope, leadership commitment, risk assessment methodology, treatment plans, the statement of applicability, control selection, documentation, awareness, monitoring, internal audit, management review and continual improvement. The second half explores modern practice and innovation, including zero trust, identity governance, cloud and container security, secure development, security operations and automation, third-party risk, privacy alignment and incident and crisis management.
Learning is practical. Participants build a risk register, draft a statement of applicability, run tabletop exercises and develop a three-year security strategy for a case organisation. They return with templates and an action plan aligned to their own environment.
After the programme, participants will be able to:
Participants take away:
The programme combines standards knowledge with realistic leadership scenarios through:
Day 1: Threat Landscape and Security Strategy
Day 2: ISO 27001 Foundations and Scoping
Day 3: Information Security Risk Assessment
Day 4: Risk Treatment and Annex A Controls
Day 5: Operation, Awareness and Performance Evaluation
Day 6: Zero Trust, Identity and Access
Day 7: Cloud, Applications and DevSecOps
Day 8: Detection, Threat Intelligence and Automation
Day 9: Incident Response, Resilience and Emerging Technology
Day 10: Certification Readiness, Board Reporting and Integrated Project
The programme is designed for those who lead, govern or audit information security, including:
Participants who complete all 10 days, the labs and the final strategy presentation are awarded a CPD-accredited Certificate of Completion by Vision Reach Global Consultancy. It recognises training only and is not an ISO 27001 auditor qualification.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) programme, you'll be able to develop a cybersecurity strategy aligned to business objectives and risk appetite, scope and plan an iso/iec 27001 information security management system, perform information security risk assessment and select appropriate treatments, and draft policies, a statement of applicability and supporting evidence for certification audits. The full breakdown of topics is covered session by session in the Course Outline tab above.
The programme is designed for those who lead, govern or audit information security, including: Chief information security officers and heads of security, Information security and IT security managers, IT directors and heads of infrastructure, Risk, compliance and data protection officers, Internal and external IT auditors, Security, cloud and enterprise architects, Security operations centre managers, Government ICT and cyber agency officers, and Consultants preparing organisations for ISO 27001 certification.
Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) starts October 19, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) Training Course is pitched at advanced professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Strategy and Innovation in Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →