Skip to content
BIZENIUS.

Cyber Security: Information Security & Risk Management Masterclass

Hands-on security risk management — ISO 27001 assessments, SOC and CSIRT capability, penetration testing and threat intelligence, run against live scenarios.

Format

Classroom · Live Virtual

The programme

Security functions that cannot quantify risk cannot defend a budget — and most cannot. This masterclass covers the complete, conjoined set of disciplines for planning, delivering and monitoring IT and cyber security: IT policies, the security operational run-book, security and penetration testing, ethical hacking and black hat techniques, plus WiFi and website security, human factors, cyber forensics, security team management and the Secure Operations Center (SOC) and Computer Security Incident Response Team (CSIRT) infrastructures behind them. Participants conduct a risk assessment of two different deployments against ISO 27001 to surface threats, exposures and vulnerabilities, then respond to a worked security incident and extract the practices they will apply to their own organisation and assets.

What you will do

Run an ISO 27001-based risk assessment across two live deployment scenarios, identifying direct and indirect threats, exposures and potential vulnerabilities.
Quantify security risk with qualitative and quantitative methods, and use quantitative techniques credibly when discussing networks and projects.
Articulate information security risks as business consequences, in language your executive committee acts on.
Stand up SOC and CSIRT capability, applying the CSIRT framework, tools and capabilities to protect the organisation cost-effectively.
Deploy OSINT and cyber threat intelligence — two of the most important disciplines in modern cyber-adversity.
Counter viruses, malware, active code and Advanced Persistent Threats (APT) with mitigating options you can defend.
Build and manage an effective cybersecurity team, using penetration testing, ethical hacking and NLP-informed messaging to change how employees think about security.

Who attends

  • Heads of information security and cybersecurity
  • Security operations, SOC and incident-response leads
  • IT and risk managers accountable for security delivery
  • Security professionals moving into team leadership

Cohorts bring together board members, executives and the rising leaders behind them — kept deliberately small, so every seat is a peer’s.

Programme agenda

Built for the decisions no textbook prepares you for

I.The security operating model
  • IT policies and the security operational run-book
  • Formulating and managing effective cybersecurity teams
  • Human factors — and changing how employees think about security
II.The offensive lens
  • Penetration testing and ethical hacking as tests of organisational security
  • Black hat techniques, WiFi security and website security
  • OSINT and cyber threat intelligence in practice
III.Risk assessment in practice
  • ISO 27001 risk assessment across two deployment scenarios
  • Qualitative and quantitative risk assessment methods
  • Viruses, malware, active code and APTs — threats and mitigations
IV.Detection and response
  • SOC and CSIRT infrastructures and the CSIRT framework
  • Responding to a worked security incident
  • Cyber forensics and articulating risk as business consequence

Frequently asked

Which security frameworks do the programmes work with?

The frameworks security teams are audited against — including ISO 27001, the NIST Cybersecurity Framework and GDPR obligations — plus industrial control-system security for oil, gas and utilities environments. BIZENIUS does not certify against these standards; participants leave able to run the risk assessments, write the ISMS documentation and prepare the evidence an auditor asks for.

Is there cybersecurity content for boards and non-technical executives?

Yes. Dedicated programmes address risk and cybersecurity for board members, and cyber governance, risk and compliance for executives, alongside practitioner-level depth for security teams — from emerging threats and countermeasures to fraud detection and investigation. Boards leave knowing which questions to put to their CISO, and what a satisfactory answer looks like.

How is pricing handled for cybersecurity programmes?

There is no public rate card. The fee arrives in the proposal, shaped by format, location and any tailoring — request the brochure and a senior practitioner replies within one business day with the details.

Can security training run inside our own environment?

Yes. Every programme runs in-house, tailored to your threat model, your sector and your control environment — including operational-technology settings such as process-control systems. Delivery is in English or French, on site or as a private live virtual cohort.

Share this programme

LinkedInWhatsAppFacebookEmail

Know the right person for this seat?Nominate a colleague →

In their words

Knowledge transfer, emphasised throughout

“We worked with BIZENIUS for our Fresh Graduates Programme — they are simply amazing. Knowledge transfer and practical learning were emphasised throughout.”

Kuwait Investment Authority

Teams from these institutions train with BIZENIUS

  • Citi
  • Barclays
  • ExxonMobil
  • Total
  • Gazprom
  • Standard Bank
  • QNB
  • Crédit Agricole
  • Nedbank
  • Absa
  • Raiffeisen
  • Halliburton
  • Baker Hughes
  • ConocoPhillips
  • Ooredoo
  • National Bank of Kuwait
  • Kuwait Finance House
  • Bank Muscat
  • Bank Audi
  • SABB
  • Garanti BBVA
  • Ecobank
  • Arab Bank
  • National Bank of Egypt
  • ADIB
  • Access Bank
  • Afreximbank
  • Repsol
  • QNB ALAHLI
  • Stanbic Bank
  • Equity Group Holdings
  • KCB Bank
  • Lombard Odier
  • NOV
  • Weatherford
  • Subsea 7
  • Al Baraka
  • Banque Misr
  • Burgan Bank
  • Bank ABC

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
Number of participants
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.