Skip to content
BIZENIUS

Cyber Security: Information Security & Risk Management Masterclass

Hands-on security risk management — ISO 27001 assessments, SOC and CSIRT capability, penetration testing and threat intelligence, run against live scenarios.

The programme

Security functions that cannot quantify risk cannot defend a budget — and most cannot. This masterclass covers the complete, conjoined set of disciplines for planning, delivering and monitoring IT and cyber security: IT policies, the security operational run-book, security and penetration testing, ethical hacking and black hat techniques, plus WiFi and website security, human factors, cyber forensics, security team management and the Secure Operations Center (SOC) and Computer Security Incident Response Team (CSIRT) infrastructures behind them. Participants conduct a risk assessment of two different deployments against ISO 27001 to surface threats, exposures and vulnerabilities, then respond to a worked security incident and extract the practices they will apply to their own organisation and assets.

What you will do

Run an ISO 27001-based risk assessment across two live deployment scenarios, identifying direct and indirect threats, exposures and potential vulnerabilities.
Quantify security risk with qualitative and quantitative methods, and use quantitative techniques credibly when discussing networks and projects.
Articulate information security risks as business consequences, in language your executive committee acts on.
Stand up SOC and CSIRT capability, applying the CSIRT framework, tools and capabilities to protect the organisation cost-effectively.
Deploy OSINT and cyber threat intelligence — two of the most important disciplines in modern cyber-adversity.
Counter viruses, malware, active code and Advanced Persistent Threats (APT) with mitigating options you can defend.
Build and manage an effective cybersecurity team, using penetration testing, ethical hacking and NLP-informed messaging to change how employees think about security.

Who attends

  • Heads of information security and cybersecurity
  • Security operations, SOC and incident-response leads
  • IT and risk managers accountable for security delivery
  • Security professionals moving into team leadership

Cohorts bring together board members, executives and the rising leaders behind them — kept deliberately small, so every seat is a peer’s.

Programme agenda

Built for the decisions no textbook prepares you for

I.The security operating model
  • IT policies and the security operational run-book
  • Formulating and managing effective cybersecurity teams
  • Human factors — and changing how employees think about security
II.The offensive lens
  • Penetration testing and ethical hacking as tests of organisational security
  • Black hat techniques, WiFi security and website security
  • OSINT and cyber threat intelligence in practice
III.Risk assessment in practice
  • ISO 27001 risk assessment across two deployment scenarios
  • Qualitative and quantitative risk assessment methods
  • Viruses, malware, active code and APTs — threats and mitigations
IV.Detection and response
  • SOC and CSIRT infrastructures and the CSIRT framework
  • Responding to a worked security incident
  • Cyber forensics and articulating risk as business consequence

Frequently asked

How hands-on is the information security masterclass?

Deliberately so. Participants conduct a risk assessment of two different deployments against ISO 27001 to surface threats, exposures and vulnerabilities, then respond to a worked security incident in session. The programme also covers penetration testing, ethical hacking and black hat techniques, OSINT and cyber threat intelligence, and the SOC and CSIRT infrastructures that carry detection and response.

Who should attend this security risk management training?

Heads of information security and cybersecurity, security operations, SOC and incident-response leads, IT and risk managers accountable for security delivery, and security professionals moving into team leadership. It suits functions that must quantify risk credibly enough to defend a budget and articulate security risks as business consequences.

Is the masterclass available in-house and in French?

Yes. BIZENIUS delivers it in English and French, and an in-house edition can be tailored to your organisation’s assets, deployments and security maturity. Sessions run on a rolling calendar with dates confirmed on request; fees and quotations are provided on enquiry.

Who teaches this

Practitioners, not presenters.

Led by risk and cybersecurity practitioners who have owned security and technology-risk accountability in regulated institutions and advised boards through incidents, alongside data-privacy specialists who have implemented the regimes they teach. The emphasis is governance and decision-making, taught by people who have had to make the call.

What the bench brings

  • Information security governance and risk assessment
  • Security management systems, audit and certification
  • Data protection and privacy compliance
  • Cloud, network and industrial-control security
  • Security architecture and third-party assessment
  • Cyber-risk briefings for boards and executives

Where they have practised

Current and former practitioners — people who hold the seat today alongside those who have held it.

Sectors: Technology & fintech · Banking & financial services · Government & public sector · Insurance

Regions: Africa · the Middle East · Europe · Asia · the Americas

How they teach

  • Incident and breach scenario exercises
  • Hands-on labs and control walk-throughs
  • Board-briefing role plays
  • Exam-style knowledge checks and quizzes
  • A personal action plan

Cohorts are kept small so every exercise is worked on the participants’ own situations — in person or live virtual.

The faculty profile for your cohort is sent with the full agenda and the next dates when you enquire.Request brochure →

Share this programme

LinkedInWhatsAppFacebookEmail

Know the right person for this seat?Nominate a colleague →

In their words

Knowledge transfer, emphasised throughout

“We worked with BIZENIUS for our Fresh Graduates Programme — they are simply amazing. Knowledge transfer and practical learning were emphasised throughout.”

Kuwait Investment Authority

Teams from these institutions train with BIZENIUS

  • Citi
  • Barclays
  • ExxonMobil
  • Total
  • Gazprom
  • Standard Bank
  • QNB
  • Crédit Agricole
  • Nedbank
  • Absa
  • Raiffeisen
  • Halliburton
  • Baker Hughes
  • ConocoPhillips
  • Ooredoo
  • National Bank of Kuwait
  • Kuwait Finance House
  • Bank Muscat
  • Bank Audi
  • SABB
  • Garanti BBVA
  • Ecobank
  • Arab Bank
  • National Bank of Egypt
  • ADIB
  • Access Bank
  • Afreximbank
  • Repsol
  • QNB ALAHLI
  • Stanbic Bank
  • Equity Group Holdings
  • KCB Bank
  • Lombard Odier
  • NOV
  • Weatherford
  • Subsea 7
  • Al Baraka
  • Banque Misr
  • Burgan Bank
  • Bank ABC

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.