Skip to main content
Home: Central London for Capacity Building
Digital Transformation, AI & Technology

Cyber Risk Management

A practical professional programme focused on cyber risk management, designed to strengthen digital capability, technology adoption and data-informed performance.

Type
Specialist
Level
Advanced
Duration
5 days
Delivery
In person, Live online, In-house
Languages
English, Arabic

Cyber Risk Management develops the capability to identify, assess, prioritise and treat cybersecurity risks within an organisational risk-management framework.

The programme examines cyber assets, threats, vulnerabilities, likelihood, impact, risk appetite, controls, treatment plans, third-party risk, reporting and continuous monitoring.

Participants learn how to translate technical cyber issues into structured business risks that can be prioritised, governed and communicated effectively.

Objectives

  • Understand the principles of cyber risk management.

  • Identify assets, threats, vulnerabilities and business impacts.

  • Assess and prioritise cyber risks systematically.

  • Develop proportionate risk-treatment and control plans.

  • Improve cyber-risk reporting and governance.

Learning outcomes

  • Develop structured cyber-risk statements.

  • Assess likelihood and business impact.

  • Prioritise cyber risks according to defined criteria.

  • Select appropriate risk-treatment options.

  • Prepare clear cyber-risk reports for management.

Who it is for

  • Cybersecurity professionals.

  • Risk-management professionals.

  • Information-security managers.

  • Technology managers.

  • Governance, risk and compliance professionals.

Programme modules

1. Cyber Risk Foundations
  • Cyber risk concepts

  • Assets

  • Threats and vulnerabilities

  • Business impact

2. Risk Identification
  • Risk scenarios

  • Threat sources

  • Vulnerability information

  • Risk statements

3. Risk Assessment
  • Likelihood

  • Impact

  • Inherent risk

  • Residual risk

4. Risk Appetite and Prioritisation
  • Risk appetite

  • Tolerance

  • Risk matrices

  • Prioritisation

5. Risk Treatment and Controls
  • Avoid, reduce, transfer and accept

  • Control selection

  • Treatment plans

  • Control effectiveness

6. Cyber Risk Governance and Reporting
  • Risk ownership

  • Third-party risk

  • Risk reporting

  • Continuous monitoring

Methodology

The programme combines cyber-risk frameworks, risk scenarios, assessment exercises and treatment-planning cases. Participants translate technical issues into business-oriented risk statements and management actions.

Assessment

Assessment includes cyber-risk identification and assessment exercises and a final applied task requiring participants to develop a cyber-risk register and treatment plan for a defined organisational scenario.

Certificate

Certificate of Completion

For your organisation

This programme can be delivered for a single organisation, team or institution, and adapted to your context, participants and objectives.

Organisational delivery is scoped and priced individually, and is not booked from this page.

Discuss this programme

Upcoming sessions

No dates are scheduled at present.

Training & Professional Development

Structured professional learning that develops practical, role-relevant knowledge and capability.

Capacity Building & Institutional Development

Strengthening institutional systems, structures, people and organisational capability for sustainable performance.

Consulting & Advisory

Structured advisory support for strategy, governance, performance, transformation and organisational decision-making.

Discuss your challenge

Discuss your challenge