Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Information is among the most valuable assets an organisation holds, and it is under constant attack. Phishing, credential theft, ransomware and misconfigured cloud services lead to financial loss, operational shutdown and legal exposure. Many organisations respond with a collection of tools but without a clear view of which risks matter most, who owns them and whether controls are really working.
The Risk Management for Cybersecurity & Information Security (ISO 27001) Training Course gives participants a structured way to answer those questions. The first phase teaches the vocabulary and mechanics of information risk: identifying assets and owners, modelling threats, evaluating vulnerabilities, scoring risk and choosing among treat, tolerate, transfer and terminate options. Participants then see how these results feed the requirements of ISO/IEC 27001, including the Statement of Applicability, objectives, documented information and performance evaluation.
The second phase moves into implementation depth. Participants study technical and organisational controls, test them against realistic attack scenarios, assess third-party and cloud exposure, rehearse incident response and learn how to audit and improve the system. Work is lab-based and cumulative, and every participant develops a risk register, a draft Statement of Applicability and an improvement roadmap that can be adapted to their own environment.
By the end of the course, participants will be able to:
The course is designed for professionals who manage, assess or assure information security, such as:
Participants leave the course with:
Over ten days the programme alternates explanation with building real documents. Participants experience:
Participants who attend all ten days and complete the lab work and final roadmap presentation are awarded a CPD-accredited Certificate of Completion by Vision Reach Global Consultancy. The certificate recognises training completed and is not a certification under ISO/IEC 27001.