ED-IN-03 – Maximize your chances of success with Data-Driven Cyber and Technology Risk Governance - Module for executives

Duration: 1 hour
Training format: Synchronous (on-site or remote)
CPE credits: 1

Pricing

  • €495 excl. VAT per person (public session) - ED-IN-03.1
  • Private session pricing: upon request, depending on context and number of participants

Capacity: Minimum 1 – Maximum 8 executives per session

Dates:
ED-IN-03
From Regulation to Decision: Defensible Cyber Risk Governance for Executives
EN
21 Sep 2026
-
21 Sep 2026
1 day
The Memoir Club, 12 Upper Woburn Place Euston London WC1H 0HX
Description:

This short module is specifically designed for executives and executive committee members who are responsible for making decisions that impact the organization’s exposure to cyber and technology risk.

In one hour, the session highlights the limitations of qualitative risk management approaches and demonstrates how data-driven governance, supported by the FAIR™ Standard, provides quantified, comparable, and defensible inputs for cybersecurity investment decisions.

The training illustrates how cyber risk quantification integrates into recognized governance frameworks (ISO 31000, COSO ERM, the Three Lines Model, NIS2, DORA, etc.) and strengthens alignment between executive leadership, risk teams, and technical functions.

The format is intentionally decision- and governance-oriented: minimal technical detail, clear key messages, concrete examples, and actionable recommendations to move toward data-driven cyber risk management.

Description:
Pricing

€495 excl. VAT per person (public session) - ED-IN-03.1
Private session pricing: upon request, depending on context and number of participants

Duration

1 hour

Training format

Synchronous (on-site or remote)

CPE credits

1

Learning Objectives:

By the end of the session, participants will be able to:

  • Identify the limitations of qualitative risk analyses currently used within organizations
  • Understand how cyber risk quantification using the FAIR™ Standard can improve strategic decision-making
  • Position cyber risk management within governance frameworks and regulatory requirements (standards, NIS2, DORA, etc.)
  • Identify the first practical steps to deploy or strengthen a data-driven cyber risk management program
Target Audience:

Who Should Attend

Executives, executive committee members, cyber program sponsors, and leaders of key support functions (CIO, CFO, CHRO, Chief Risk Officer, General Counsel, business unit leaders, etc.).

Prerequisites

None. This module is designed for participants without a technical background in cybersecurity or FAIR™.

Course Content:

Introduction to Risk Management for Executives

  • Risk management as a decision-making discipline
  • Risk chains and resource allocation
  • Risk capacity and risk tolerance

Executives at the Core of Risk Governance

  • Roles and responsibilities of leadership within reference frameworks (ISO 31000, COSO ERM, Three Lines Model)
  • NIS2, DORA, and other regulatory requirements related to cyber risk governance
  • The cross-functional role of executive leaders (CIO, CFO, CHRO, business leadership, etc.)

Limitations of Qualitative Cyber Risk Approaches

  • Subjectivity, inconsistencies, and prioritization challenges associated with risk matrices
  • Communication difficulties with boards and non-technical stakeholders

What Is Data-Driven Cyber & Technology Risk Management?

  • Principles of risk quantification using the FAIR™ Standard
  • Use cases: project prioritization, budget justification, third-party risk management, cyber insurance
  • Observed benefits in organizations adopting quantification (improved understanding, prioritization, alignment)
Instructional Team:

A C-Risk trainer experienced in advising executive committees on cyber risk governance.

Monitoring of implementation and evaluation of results:
  • Continuous interaction with participants through Q&A
  • Live polls and rapid feedback questions to validate understanding of key messages
Technical and educational resources:
  • Concise, decision-oriented presentation materials provided to participants
  • Risk governance diagrams and examples of quantitative dashboards
C-Risk

Advance Your Career with Cyber Risk Management Training

E-learning platform and instructor-led courses in quantification, cyber risk frameworks, and data-driven decision-making.
C-Risk Education equips you with the skills to analyze and manage cyber risk effectively. Our training covers multiple methodologies and frameworks: cyber risk quantification, EBIOS RM, third-party risk management, and advanced threat and control assessment techniques. 
Learn practical, immediately applicable skills across the full spectrum of modern cyber risk management.

In-person
Introduction to Data-Driven Cyber Risk Management with the FAIR™ Standard

Learn data-driven cyber risk management with FAIR standard. 3-hour instructor-led course on quantifying cyber risk in financial terms.

Half-day (3 hours)
Learn more
E-learning
Introduction to Data-Driven Cyber Risk Management with the FAIR™ Standard - e-Learning

Learn FAIR™ cyber risk quantification at your own pace. 3-hour e-learning covering risk management fundamentals and financial risk analysis.

3 hours of e-Learning content (unlimited access for 3 months)
Learn more
In-person
Data-Driven Cyber Risk Management with the FAIR™ Standard for Practitioners

Master FAIR™ methodology in 12 hours. Learn quantitative cyber risk analysis, overcome qualitative limits, and make data-driven security decisions.

12 hours
Learn more
E-learning
Data-Driven Cyber Risk Management with the FAIR™ Standard for Practitioners - e-Learning

Master FAIR™ cyber risk quantification with 12 hours of e-learning. Model risk scenarios, estimate loss factors, prepare for Open FAIR™ 2 certification.

Approximately 12 hours of e-Learning content (unlimited access for 3 months)
Learn more
In-person
From Regulation to Decision: Defensible Cyber Risk Governance for Executives under NIS2, DORA and the EU AI Act

Meet your board's cyber risk oversight obligations under NIS2, DORA, and the EU AI Act, and learn to govern cyber risk with the same rigor as financial risk. Full-day executive program for management bodies and senior leaders.

Full day (7 hours), on-site or remote
Learn more
In-person
Turning Controls into Measurable Risk Reduction with FAIR-CAM

Learn to quantify security control effectiveness using FAIR-CAM™. Model risk reduction, analyze attack chains, and integrate controls into FAIR™ analyses.

4 hours
Learn more
E-learning
Turning Controls into Measurable Risk Reduction with FAIR-CAM – e-Learning

Master FAIR-CAM™ to quantify security control effectiveness. 10-hour e-learning for FAIR practitioners.

Approximately 10 hours of e-learning content (unlimited access for 3 months)
Learn more
E-learning
Building a Data-Driven Third-Party Risk Management (TPRM) Program with FAIR™ – e-Learning

Learn to quantify third-party cyber risks using FAIR™. 10-hour e-learning course covering TPRM lifecycle, risk scenarios, and financial quantification.

Approximately 10 hours of e-Learning content (unlimited access for 3 months)
Learn more
E-learning
Risk & Digital Resilience for Executives : DORA & NIS2 Obligations — e-Learning

Fulfil your DORA and NIS2 training obligations and learn why cybersecurity is a governance issue, and how to oversee it effectively. 5-hour e-learning for executives and board members.

Approximately 5 hours of e-Learning content (unlimited access for 6 months)
Learn more