Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Cyber incidents now disrupt operations, expose customer data and draw regulatory attention, and executives expect their security leaders to explain risk in business terms. Technical knowledge alone is not enough. Leaders must build a management system, prioritise limited resources, measure whether controls work and keep a team engaged under constant pressure.
The programme combines ISO 27001 management system requirements with leadership and performance management. In the early days participants analyse organisational context, define scope, secure management commitment and build the policy framework. They carry out risk assessment and treatment, select and justify controls from Annex A, and produce a Statement of Applicability. The middle days deal with operational themes: access, cryptography, supplier and cloud security, secure development, logging and monitoring, and the human element. Performance sessions cover security metrics, maturity models, assurance and internal audit, reporting to boards and audit committees, and continual improvement. Final days concentrate on incident and crisis leadership, continuity, team capability and certification readiness.
Learning is interactive and scenario-based. Participants work with sample ISMS documentation, run a risk workshop, conduct an audit exercise and rehearse a ransomware tabletop, finishing with a security leadership plan for their own organisation.
By the end of the programme, participants will be able to:
The programme is for professionals who direct or are preparing to direct security programmes, including:
Participants take away:
Delivery blends management practice with technical depth for senior learners. It includes:
Delegates who complete the ten days of sessions and the practical exercises receive a Certificate of Completion from Vision Reach Global Consultancy, accredited for CPD. This is a training certificate and is not an ISO 27001 certification body credential.