Be the first to know when new training courses are scheduled or dates are updated.
We run this course regularly across Nairobi, Mombasa, Kampala, Dar es Salaam, Kigali, Johannesburg, Dubai, Singapore, China and many more locations. The next intake dates will be published here shortly.
Need it sooner? Reach out and we'll fast-track a session for you or your team.
Prefer email? Submit a scheduling request and we'll get back to you shortly.
The Cybersecurity Governance Executive Training Course is a comprehensive executive development programme designed to equip board members, Chief Executive Officers, directors, senior managers, policymakers, technology leaders, risk professionals, and organisational decision-makers with the strategic knowledge and leadership competencies required to govern cybersecurity effectively in an increasingly digital and interconnected operating environment. The course examines cybersecurity governance, information security governance, cyber risk management, digital risk, data protection, privacy, cyber resilience, regulatory compliance, Artificial Intelligence security, cloud security, third-party cyber risk, incident response, and executive accountability from a strategic leadership perspective. Participants develop an understanding of contemporary cyber threats including ransomware, phishing, business email compromise, data breaches, insider threats, supply chain attacks, cloud security incidents, identity compromise, social engineering, and emerging technology risks while focusing on the governance decisions required to protect organisational information, critical systems, operations, stakeholders, reputation, and long-term organisational value.
The programme provides executives with practical approaches for establishing cybersecurity governance frameworks that align cyber risk management with organisational strategy, enterprise risk management, corporate governance, digital transformation, business objectives, and regulatory requirements. Participants examine cybersecurity policies, governance structures, board oversight, executive responsibilities, cyber risk appetite, cyber risk assessment, cyber risk registers, Key Risk Indicators, security controls, cybersecurity investment, performance dashboards, third-party assurance, internal audit, compliance monitoring, and executive cyber risk reporting. Particular emphasis is placed on enabling boards and executives to ask appropriate cybersecurity questions, understand cyber risk in business terms, evaluate organisational cybersecurity maturity, establish accountability, prioritise security investments, and balance digital innovation with appropriate protection and resilience.
The Cybersecurity Governance Executive Training Course further addresses cyber incident governance, crisis leadership, business continuity, disaster recovery, data governance, privacy, cloud computing, digital transformation, Artificial Intelligence, Generative AI, Internet of Things, remote working, outsourcing, supply chain security, vendor risk, and emerging digital technologies. Participants examine how cybersecurity governance should evolve as organisations adopt new technologies and increasingly depend on interconnected systems, digital platforms, cloud services, external providers, and organisational data. The programme also covers cybersecurity culture, employee awareness, ethical leadership, regulatory compliance, cyber insurance considerations, cybersecurity metrics, information security management, identity and access governance, data classification, third-party risk management, and organisational preparedness for major cyber incidents.
By the end of the Cybersecurity Governance Executive Training Course, participants will be better prepared to provide strategic leadership and executive oversight of cybersecurity without requiring deep technical expertise. Through executive presentations, cybersecurity governance assessments, cyber risk exercises, incident simulations, facilitated discussions, boardroom scenarios, collaborative activities, and relevant general case studies, participants translate cybersecurity principles into practical organisational decisions. The programme enables participants to develop a Cybersecurity Governance Executive Action Plan integrating cyber governance priorities, strategic risks, cybersecurity policies, executive responsibilities, security investments, data protection, incident response, business continuity, third-party oversight, cybersecurity culture, performance indicators, and practical actions for strengthening organisational cyber resilience.
By the end of the Cybersecurity Governance Executive Training Course, participants will be able to:
1. Understand cybersecurity governance, information security governance, cyber risk management, digital risk, cyber resilience, and their strategic importance to modern organisations.
2. Identify and evaluate major cybersecurity threats, vulnerabilities, business exposures, emerging cyber risks, and their potential financial, operational, legal, regulatory, and reputational consequences.
3. Establish effective cybersecurity governance structures defining board, executive management, technology, risk, compliance, internal audit, security, and business-unit responsibilities.
4. Integrate cybersecurity risk management into corporate governance, enterprise risk management, strategic planning, digital transformation, investment decisions, and organisational performance management.
5. Develop cyber risk appetite, cyber risk assessment processes, risk registers, Key Risk Indicators, cybersecurity dashboards, escalation thresholds, and executive reporting mechanisms.
6. Strengthen governance of data protection, privacy, cloud computing, Artificial Intelligence, Generative AI, third-party providers, digital platforms, and emerging technologies.
7. Provide effective executive oversight of cybersecurity policies, security controls, cybersecurity investments, organisational capabilities, assurance, regulatory compliance, and security performance.
8. Develop appropriate executive approaches to cyber incident response, crisis management, business continuity, disaster recovery, stakeholder communication, and organisational resilience.
9. Strengthen organisational cybersecurity culture through executive leadership, employee awareness, accountability, training, ethical behaviour, communication, and continuous improvement.
10. Develop a practical Cybersecurity Governance Executive Action Plan aligned with organisational strategy, cyber risk exposure, governance requirements, digital transformation, regulatory obligations, and resilience priorities.
Organizations whose executives participate in this training will benefit through:
1. Stronger board and executive understanding of cybersecurity governance, cyber risk, information security, data protection, privacy, and organisational cyber resilience.
2. Improved alignment between cybersecurity strategy, organisational strategy, enterprise risk management, digital transformation, corporate governance, and business priorities.
3. Enhanced identification, assessment, prioritisation, treatment, monitoring, escalation, and executive reporting of cybersecurity and digital risks.
4. Clearer cybersecurity accountability among boards, executives, Chief Information Officers, Chief Information Security Officers, risk functions, internal audit, compliance teams, and business leaders.
5. Improved governance of cybersecurity investments, security controls, cloud services, Artificial Intelligence, digital platforms, third-party providers, and technology transformation programmes.
6. Stronger organisational preparedness for cyber incidents, ransomware, data breaches, system disruptions, technology failures, privacy incidents, and other digital crises.
7. Enhanced data protection, privacy governance, regulatory compliance, information management, internal controls, cybersecurity assurance, and stakeholder confidence.
8. Stronger cybersecurity culture through improved leadership commitment, employee awareness, accountability, cyber risk communication, security training, and responsible digital behaviour.
9. Improved cyber resilience through effective incident response, crisis management, business continuity, disaster recovery, third-party risk management, and executive preparedness.
10. Development of practical cybersecurity governance improvements that protect organisational information, operations, reputation, stakeholder trust, digital investments, and long-term organisational value.
The Cybersecurity Governance Executive Training Course is designed for Board Chairpersons, Board Members, Board Audit and Risk Committee Members, Chief Executive Officers (CEOs), Managing Directors, Executive Directors, Directors, Deputy Directors, Commissioners, Permanent Secretaries, Principal Secretaries, senior government officials, policymakers, Chief Information Officers (CIOs), Chief Technology Officers (CTOs), Chief Information Security Officers (CISOs), Chief Digital Officers (CDOs), Chief Risk Officers (CROs), Chief Operating Officers (COOs), Chief Financial Officers (CFOs), Chief Audit Executives, Chief Compliance Officers, Data Protection Officers, company secretaries, ICT directors, cybersecurity directors, information security managers, enterprise risk managers, internal audit managers, compliance managers, digital transformation leaders, programme directors, project directors, heads of departments, senior managers, public-sector executives, financial institution executives, NGO leaders, development-sector executives, governance professionals, technology leaders, and other senior decision-makers responsible for organisational governance, cybersecurity, information technology, digital transformation, risk management, compliance, data protection, or organisational resilience.
1. Understanding cybersecurity governance, information security governance, cyber risk management, cyber resilience, digital risk, and the strategic importance of cybersecurity to organisational performance and sustainability.
2. Examining the evolving cyber threat landscape including ransomware, phishing, business email compromise, social engineering, data breaches, insider threats, supply chain incidents, identity compromise, and emerging cyber risks.
3. Understanding the roles and responsibilities of boards, board committees, Chief Executive Officers, Chief Information Officers, Chief Information Security Officers, risk managers, internal auditors, compliance teams, and business leaders.
4. Aligning cybersecurity strategy with corporate strategy, digital transformation, enterprise risk management, organisational objectives, regulatory requirements, customer expectations, and stakeholder interests.
5. Establishing cybersecurity governance frameworks, information security policies, decision rights, accountability structures, delegated authorities, executive reporting arrangements, and oversight mechanisms.
6. Executive Case Study: Assessing an organisation where cybersecurity is treated exclusively as an IT responsibility and redesigning its governance structure to establish effective board oversight, executive accountability, business ownership, and enterprise-wide cyber risk management.
1. Identifying cyber threats, vulnerabilities, critical assets, threat actors, attack scenarios, business dependencies, information risks, technology risks, and potential organisational consequences.
2. Conducting cyber risk assessments using likelihood, impact, exposure, vulnerability, control effectiveness, business criticality, inherent risk, residual risk, and organisational risk-prioritisation criteria.
3. Developing cybersecurity risk registers, cyber risk profiles, risk heat maps, risk matrices, risk treatment plans, risk ownership structures, escalation requirements, and executive monitoring arrangements.
4. Establishing cyber risk appetite, risk tolerance, cybersecurity thresholds, Key Risk Indicators, control indicators, executive dashboards, reporting requirements, and board-level risk communication.
5. Applying risk-based approaches to cybersecurity investments, technology projects, cloud adoption, outsourcing, digital transformation, acquisitions, third-party relationships, and major organisational decisions.
6. Executive Case Study: Prioritising cybersecurity investments for an organisation facing ransomware exposure, outdated technology, limited cybersecurity resources, increasing regulatory expectations, cloud migration, and competing strategic investments.
1. Understanding data governance, data protection, privacy, information classification, data ownership, access governance, retention, confidentiality, integrity, availability, and executive accountability for organisational information.
2. Governing cloud computing risks including cloud strategy, shared responsibility, access management, data location, vendor dependency, configuration risk, business continuity, contractual requirements, and cloud security assurance.
3. Understanding Artificial Intelligence and Generative AI security risks including confidential data exposure, inaccurate outputs, malicious use, model risks, intellectual property, privacy, cybersecurity, accountability, and human oversight.
4. Governing Internet of Things, mobile technologies, remote working, digital platforms, interconnected systems, operational technologies, application ecosystems, and other emerging technology environments.
5. Strengthening identity and access governance through authentication, privileged-access management, role-based access, access reviews, segregation of duties, employee lifecycle management, and executive oversight.
6. Executive Case Study: Governing an organisation's rapid adoption of cloud services and Generative AI while addressing confidential information, third-party dependency, access control, privacy, cybersecurity, employee use, and regulatory compliance.
1. Understanding cybersecurity control frameworks and the executive role in establishing appropriate preventive, detective, corrective, administrative, physical, and technological security controls.
2. Governing third-party and supply chain cyber risk through vendor due diligence, security requirements, contractual controls, service-level agreements, access restrictions, assurance, monitoring, and exit planning.
3. Strengthening regulatory compliance, cybersecurity policies, data protection obligations, information security standards, documentation, management accountability, and evidence of governance effectiveness.
4. Understanding the roles of internal audit, external audit, risk management, compliance, security assessments, penetration testing, vulnerability management, assurance reviews, and independent cybersecurity evaluations.
5. Evaluating cybersecurity investments using risk reduction, business criticality, organisational priorities, regulatory requirements, resilience benefits, implementation costs, performance indicators, and strategic value.
6. Executive Case Study: Responding to a serious security incident originating from a third-party service provider where weak vendor due diligence, inadequate contractual requirements, excessive system access, and limited monitoring increased organisational exposure.
1. Understanding cyber incident management, incident classification, escalation, executive responsibilities, technical response, investigation, containment, recovery, stakeholder communication, and post-incident review.
2. Establishing cyber crisis management structures covering executive crisis teams, incident command, decision-making authority, communication protocols, legal considerations, regulatory reporting, stakeholder engagement, and accountability.
3. Integrating cybersecurity incident response with business continuity management, disaster recovery, operational resilience, emergency management, crisis communication, and organisational recovery planning.
4. Preparing for ransomware, major data breaches, system outages, cloud service disruptions, compromised accounts, third-party incidents, insider threats, and other high-impact cybersecurity events.
5. Testing cyber resilience through executive tabletop exercises, crisis simulations, incident-response exercises, business continuity testing, disaster recovery exercises, lessons-learned reviews, and corrective action planning.
6. Executive Case Study: Managing a major cyber incident that disrupts critical organisational systems and requires executives to make rapid decisions concerning operational continuity, stakeholder communication, regulatory reporting, financial exposure, recovery priorities, and organisational reputation.
1. Building an organisation-wide cybersecurity culture through executive leadership, employee awareness, security education, accountability, ethical behaviour, communication, incentives, and continuous reinforcement.
2. Addressing human-related cybersecurity risks including phishing, social engineering, password practices, inappropriate information sharing, remote working, insider threats, policy violations, and employee security behaviour.
3. Developing cybersecurity performance indicators, Key Risk Indicators, executive dashboards, maturity measures, incident trends, vulnerability metrics, control effectiveness measures, audit findings, and compliance indicators.
4. Strengthening board and executive cybersecurity reporting by translating technical security information into business risk, financial exposure, operational consequences, strategic implications, and actionable governance decisions.
5. Conducting cybersecurity maturity assessments and developing continuous improvement priorities covering governance, people, processes, technology, data, third parties, incident preparedness, resilience, and organisational learning.
6. Executive Case Study and Capstone Exercise: Developing and presenting a Cybersecurity Governance Executive Action Plan integrating cyber governance, priority risks, risk appetite, cybersecurity investments, data protection, cloud and AI governance, third-party oversight, incident response, business continuity, cybersecurity culture, performance indicators, and a 90-day implementation roadmap.
1. Customized Training: All our courses can be tailored to meet the specific needs of participants.
2. Language Proficiency: Participants should have a good command of the English language.
3. Comprehensive Learning: Our training includes well-structured presentations, practical exercises, web-based tutorials, and collaborative group work. Our facilitators are seasoned experts with over a decade of experience.
4. Certification: Upon successful completion of training, participants will receive a certificate from Foscore Development Center (FDC-K).
5. Training Locations: Training sessions are conducted at Foscore Development Center (FDC-K) centers. We also offer options for in-house and online training, customized to the client's schedule.
6. Flexible Duration: Course durations are adaptable, and content can be adjusted to fit the required number of days.
7. Onsite Training Inclusions: The course fee for onsite training covers facilitation, training materials, two coffee breaks, a buffet lunch, and a Certificate of Successful Completion. Participants are responsible for their travel expenses, airport transfers, visa applications, dinners, health/accident insurance, and personal expenses.
8. Additional Services: Accommodation, pickup services, flight booking, and visa processing arrangements are available upon request at discounted rates.
9. Equipment: Tablets and laptops can be provided to participants at an additional cost.
10. Post-Training Support: We offer one year of free consultation and coaching after the course.
11. Group Discounts: Register as a group of more than two and enjoy a discount ranging from 10% to 50%.
12. Payment Terms: Payment should be made before the commencement of the training or as mutually agreed upon, to the Foscore Development Center account. This ensures better preparation for your training.
13. Contact Us: For any inquiries, please reach out to us at training@fdc-k.org or call us at +254712260031.
14. Website: Visit our website at www.fdc-k.org for more information.