Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Digital services now underpin payments, health records, public services and supply chains, which makes security failures immediately visible to customers and regulators. Attackers are organised and quick to exploit new technology, while security budgets remain limited. Leaders need a strategy that targets the risks that matter most and a management system that shows, credibly, that controls work.
The programme begins with threat landscape analysis and the development of a security strategy tied to business priorities, governance structures and metrics. It then covers the full ISO/IEC 27001 lifecycle: context and scope, leadership commitment, risk assessment methodology, treatment plans, the statement of applicability, control selection, documentation, awareness, monitoring, internal audit, management review and continual improvement. The second half explores modern practice and innovation, including zero trust, identity governance, cloud and container security, secure development, security operations and automation, third-party risk, privacy alignment and incident and crisis management.
Learning is practical. Participants build a risk register, draft a statement of applicability, run tabletop exercises and develop a three-year security strategy for a case organisation. They return with templates and an action plan aligned to their own environment.
After the programme, participants will be able to:
The programme is designed for those who lead, govern or audit information security, including:
Participants take away:
The programme combines standards knowledge with realistic leadership scenarios through:
Participants who complete all 10 days, the labs and the final strategy presentation are awarded a CPD-accredited Certificate of Completion by Vision Reach Global Consultancy. It recognises training only and is not an ISO 27001 auditor qualification.