Cyber Risk Management
A practical professional programme focused on cyber risk management, designed to strengthen digital capability, technology adoption and data-informed performance.
- Type
- Specialist
- Level
- Advanced
- Duration
- 5 days
- Delivery
- In person, Live online, In-house
- Languages
- English, Arabic
Cyber Risk Management develops the capability to identify, assess, prioritise and treat cybersecurity risks within an organisational risk-management framework.
The programme examines cyber assets, threats, vulnerabilities, likelihood, impact, risk appetite, controls, treatment plans, third-party risk, reporting and continuous monitoring.
Participants learn how to translate technical cyber issues into structured business risks that can be prioritised, governed and communicated effectively.
Objectives
Understand the principles of cyber risk management.
Identify assets, threats, vulnerabilities and business impacts.
Assess and prioritise cyber risks systematically.
Develop proportionate risk-treatment and control plans.
Improve cyber-risk reporting and governance.
Learning outcomes
Develop structured cyber-risk statements.
Assess likelihood and business impact.
Prioritise cyber risks according to defined criteria.
Select appropriate risk-treatment options.
Prepare clear cyber-risk reports for management.
Who it is for
Cybersecurity professionals.
Risk-management professionals.
Information-security managers.
Technology managers.
Governance, risk and compliance professionals.
Programme modules
1. Cyber Risk Foundations
Cyber risk concepts
Assets
Threats and vulnerabilities
Business impact
2. Risk Identification
Risk scenarios
Threat sources
Vulnerability information
Risk statements
3. Risk Assessment
Likelihood
Impact
Inherent risk
Residual risk
4. Risk Appetite and Prioritisation
Risk appetite
Tolerance
Risk matrices
Prioritisation
5. Risk Treatment and Controls
Avoid, reduce, transfer and accept
Control selection
Treatment plans
Control effectiveness
6. Cyber Risk Governance and Reporting
Risk ownership
Third-party risk
Risk reporting
Continuous monitoring
Methodology
The programme combines cyber-risk frameworks, risk scenarios, assessment exercises and treatment-planning cases. Participants translate technical issues into business-oriented risk statements and management actions.
Assessment
Assessment includes cyber-risk identification and assessment exercises and a final applied task requiring participants to develop a cyber-risk register and treatment plan for a defined organisational scenario.
Certificate
Certificate of Completion
For your organisation
This programme can be delivered for a single organisation, team or institution, and adapted to your context, participants and objectives.
Organisational delivery is scoped and priced individually, and is not booked from this page.
Upcoming sessions
No dates are scheduled at present.
Institutional needs addressed
Related expertise
Related capabilities
Training & Professional Development
Structured professional learning that develops practical, role-relevant knowledge and capability.
Capacity Building & Institutional Development
Strengthening institutional systems, structures, people and organisational capability for sustainable performance.
Consulting & Advisory
Structured advisory support for strategy, governance, performance, transformation and organisational decision-making.