IT and Cybersecurity Risk Management Training Course

Govern IT and cyber risk end to end using COBIT, ISO 27001 and the NIST framework, from assessment to incident response and resilience.

19 dates in 13 cities · Oct 2026 – Jul 2027

Budapest

Fees: 9900
From:
To:

Cairo

Fees: 8900
From:
To:

Dubai

Fees: 8900
From:
To:

Barcelona

Fees: 9900
From:
To:

Amman

Fees: 8900
From:
To:

Singapore

Fees: 9900
From:
To:

London

Fees: 9900
From:
To:

Manama

Fees: 8900
From:
To:

Brussels

Fees: 9900
From:
To:
See all 19 dates & locations
13 cities · filter by city or month

Course overview

Enterprise technology risk no longer sits with a single security team; it spans board oversight, regulatory exposure, third-party dependencies and the day-to-day operation of critical systems. This course treats IT and cybersecurity risk as a governance discipline, connecting the decisions leaders make about appetite and investment to the controls, registers and reporting that keep an organization defensible. Delegates learn to align COBIT governance objectives with ISO/IEC 27001 management-system requirements and the NIST Cybersecurity Framework functions of Identify, Protect, Detect, Respond and Recover, so that risk treatment is traceable from policy to operational control.

Rather than treating security as a checklist, the curriculum builds a coherent operating model: a maintained risk register informed by ISO/IEC 27005, structured threat modeling, control selection mapped to Annex A, and metrics that give executives a defensible view of residual exposure. The approach draws on documented breaches, regulatory findings and published guidance so that every technique is grounded in how real organizations succeed or fail. For teams building the underlying certification and control foundation, this course complements formal work on ISO 27001 Information Security Risk Management and positions IT risk as a measurable, governable function.

Why this matters

Regulators and boards now expect demonstrable risk governance, not assurances. Frameworks such as the EU's NIS2 Directive, the SEC cyber-disclosure rules, DORA for financial entities and the GDPR's breach-notification obligations have moved cyber risk from an IT concern to a matter of fiduciary and legal accountability. At the same time, the cost and frequency of ransomware, supply-chain compromise and cloud misconfiguration continue to rise, while attack surfaces expand through remote work, SaaS sprawl and connected operational technology.

In that environment, organizations that can evidence a working risk-management system, quantify exposure and respond in a coordinated way retain the confidence of customers, insurers and regulators. The gap is rarely a lack of tools; it is the absence of governance that ties threat intelligence, control assurance and continuity planning into one accountable picture. This course targets exactly that gap for the professionals expected to own it.

Course objectives

By the end of the course, participants will be able to:

  • Train the organization to recognize and report cyber risk
  • Govern IT risk so every decision has a named owner
  • Assess how well controls trace from policy to daily operation
  • Isolate the threats most likely to reach critical assets
  • Segment networks and monitor them continuously for intrusion
  • Contain a live incident and coordinate escalation under pressure
  • Encrypt personal data and document its lawful handling
  • Harden artificial intelligence and connected devices against misuse
  • Restore operations within agreed recovery-time objectives
  • Classify technology decisions by environmental and social impact
  • Secure consistent control standards across a global estate
  • Rehearse a breach until the response needs no improvisation

Course outline

Unit 1: Introduction to IT and Cybersecurity Risk Management

  • Threat, vulnerability and asset value in IT risk
  • How cloud and remote access expand the attack surface
  • Equifax and Colonial Pipeline as governance failure cases
  • The role of risk awareness in accountable action

Unit 2: IT Governance and Compliance

  • IT governance frameworks and COBIT 2019 objectives
  • Linking governance to risk appetite and control ownership
  • Regulatory and supervisory requirements for IT security
  • Governance design and the three lines of accountability

Unit 3: Cybersecurity Frameworks and Standards

  • The Govern addition and what it asks a board to do
  • ISO/IEC 27001, Annex A and ISO/IEC 27005 risk guidance
  • Building one control baseline from overlapping standards
  • One documented mapping of NIST outcomes onto ISO controls

Unit 4: IT Risk Identification and Assessment

  • Techniques for asset discovery and vulnerability scanning
  • Threat modeling with STRIDE and attack-tree reasoning
  • Findings rated by how likely and how damaging they are
  • Risk register entries from a documented assessment

Unit 5: Risk Mitigation and Control Strategies

  • Preventive and detective controls for access and encryption
  • Risk transfer through cyber insurance and coverage gaps
  • Designing defense in depth so one control is not the last
  • A documented case where mitigation cut residual risk

Unit 6: Incident Response and Crisis Management

  • Detection and response in the NIST incident lifecycle
  • Crisis planning, escalation paths and regulator briefing
  • Recovery, forensic preservation and lessons-learned review
  • Guided analysis of a documented breach response

Unit 7: Data Protection and Privacy Compliance

  • The GDPR duties an IT team actually carries
  • Designing data security through mapping and minimization
  • Managing cloud risk and shared-responsibility boundaries
  • Records of processing and data-protection impact assessment

Unit 8: Emerging Technologies and Cyber Risks

  • Vulnerabilities introduced by artificial intelligence
  • How digital transformation outpaces control coverage
  • Adversarial machine learning and quantum-era cryptography
  • New technology as an entry point nobody has mapped

Unit 9: Digital Resilience and Business Continuity

  • Building resilience through redundancy and backup integrity
  • Linking continuity and disaster recovery to ISO 22301
  • A documented case of critical services restored on plan
  • Recovery plans tested against today's dependencies

Unit 10: ESG and Sustainability in Cybersecurity

  • Folding social and environmental exposure into IT risk
  • Sustainability-driven digital governance of data lifecycles
  • Telling the board what cyber costs the environment
  • Cyber risk folded into wider corporate accountability

Unit 11: Global Best Practices in Cybersecurity Risk

  • Benchmarking global leaders against NIST framework tiers
  • Lessons on centralized policy with locally adapted controls
  • Sustaining assurance under regulatory and resource limits
  • Recurring factors behind a security function that holds

Unit 12: Capstone analysis of a documented cyber-risk case

  • Examining the cyber-risk framework and where it failed
  • Reconstructing what was known when the choice was made
  • Evaluating whether reporting showed true residual exposure
  • Running the incident end to end against the documented case

How the course is delivered

Teaching combines instructor-led explanation of governance and control frameworks with structured examination of documented breaches and recovery efforts. Delegates study how organizations assessed, treated, and monitored their exposure, then discuss applying the same logic to their own context. The material is educational and does not certify systems or serve as a compliance assessment or legal advice.

Who should attend

Designed for professionals accountable for governing technology risk, this course suits those who set policy, maintain the register and answer to boards and regulators for cyber exposure. It assumes working familiarity with IT operations and is aimed at people translating security activity into governed, reportable risk. Typical delegates include:

  • IT risk and cybersecurity managers responsible for the control environment
  • GRC officers and technology governance leads maintaining frameworks and registers
  • Information-security officers and CISO office staff overseeing assurance
  • Compliance and audit professionals evaluating IT and privacy controls
  • Business-continuity and resilience leads coordinating with security teams

About EuroQuest International Training

With headquarters in the Slovak capital of Bratislava, the institute has been delivering professional development since 2015. Its portfolio spans upwards of 1,000 course titles, and its faculty has worked with over 15,000 practitioners worldwide. Sessions are hosted at centers in Geneva, London, Istanbul, Dubai, Barcelona, Vienna, and Paris.

Frequently asked questions

Will this course award a formal information-security qualification on completion?

No. Delegates receive a certificate of completion recognizing their attendance and engagement, not a formal information-security qualification issued by a certification body. The course builds the knowledge that supports certifications such as ISO/IEC 27001 Lead Implementer or CISM, but it does not itself confer that status.

Do I need a technical background to benefit from this course?

A working understanding of IT operations helps, but the course is designed for governance and risk professionals rather than engineers. The emphasis is on how risk is identified, treated, governed and reported, so managers and GRC officers without a deep technical role gain as much as security specialists.

Which frameworks and regulations does the course cover?

It works across COBIT, ISO/IEC 27001, ISO/IEC 27005 and the NIST Cybersecurity Framework, and references regulatory obligations including the GDPR, NIS2 and DORA. The aim is to show how these fit together into one governable risk-management approach instead of a set of disconnected requirements.

Related courses

Delegates strengthening their IT and cyber-risk governance often continue with these related courses:

Register for this course

Take the next step in strengthening how your organization governs cyber risk. Get in touch with EuroQuest International Training to check the schedule and confirm your place.

All Course Dates & Locations

19 dates · 13 cities · Oct 2026 – Jul 2027

September - 2026
October - 2026
November - 2026
December - 2026
January - 2027
February - 2027
March - 2027
April - 2027
May - 2027
June - 2027
July - 2027
August - 2027
Amman
Barcelona
Brussels
Budapest
Cairo
Dubai
Istanbul
Jakarta
London
Manama
Paris
Singapore
Vienna
Showing 19 of 19 dates

Budapest

Fees: 9900
From:
To:

Cairo

Fees: 8900
From:
To:

Dubai

Fees: 8900
From:
To:

Barcelona

Fees: 9900
From:
To:

Amman

Fees: 8900
From:
To:

Singapore

Fees: 9900
From:
To:

London

Fees: 9900
From:
To:

Manama

Fees: 8900
From:
To:

Brussels

Fees: 9900
From:
To:

Cairo

Fees: 8900
From:
To:

Dubai

Fees: 8900
From:
To:

Brussels

Fees: 9900
From:
To:

Paris

Fees: 9900
From:
To:

Vienna

Fees: 9900
From:
To:

Istanbul

Fees: 8900
From:
To:

London

Fees: 9900
From:
To:

Jakarta

Fees: 9900
From:
To:

Paris

Fees: 9900
From:
To:

Barcelona

Fees: 9900
From:
To: