Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Cyber incidents now carry direct financial consequences, from ransom and recovery costs to regulatory penalties, lost trade and damaged reputation. Boards want to know how much security is enough, how spending reduces exposure and whether certification such as ISO 27001 delivers value. Too often, security teams present technical needs and finance teams see only a growing cost line, leaving decisions to instinct rather than evidence.
The Financial Management for Cybersecurity & Information Security (ISO 27001) Training Course gives both groups a shared framework. Over two weeks, participants study the ISO/IEC 27001 requirements and Annex A controls, the risk assessment and treatment cycle, and the finance fundamentals of budgeting, costing, cash flow and investment appraisal. They learn quantitative and semi-quantitative techniques for expressing risk as a loss range, set against the cost of controls, and use these to prioritise projects, justify headcount and negotiate with vendors. Later days consider cyber insurance, incident response costing, third-party and cloud economics, internal chargeback, assurance costs and reporting to audit and risk committees.
Work is applied throughout, using spreadsheet models, sample budgets and realistic scenarios. Delegates conclude with a complete financial plan for an information security programme, ready for discussion with executive management.
By the end of the course, participants will be able to:
The course brings security and finance professionals together, including:
Delegates leave the programme with:
The programme blends security and finance practice through shared exercises:
Participants who complete the ten days and the practical modelling and presentation work receive a Certificate of Completion issued by Vision Reach Global Consultancy and accredited for CPD.
The certificate recognises attendance and delivery of the final financial plan. It is not an ISO 27001 auditor or implementer qualification.