ED-IN-03 – From Regulation to Decision: Defensible Cyber Risk Governance for Executives: Meeting your oversight obligations under NIS2, DORA and the EU AI Act

Duration: 7 hours
Training format: Synchronous (on-site or remote)
CPE credits: 6

Pricing

  • £795 / €930 excl. VAT per person
  • Private session pricing: upon request, depending on context and number of participants

Capacity: up to 15 executives per session

Dates:
ED-IN-03
From Regulation to Decision: Defensible Cyber Risk Governance for Executives
EN
21 Sep 2026
-
21 Sep 2026
1 day
London
Description:

Cybersecurity risk is an enterprise risk. It should be understood, measured, and governed in defensible business terms, with the same rigor applied to financial and operational risk.

This full-day executive program equips you to meet their cyber risk oversight and training obligations under NIS2, DORA, and the EU AI Act. Participants learn to provide defensible oversight and build an effective cybersecurity governance strategy, grounded in the idea that cyber risk can be quantified, prioritized and governed more objectively.

Description:
Pricing

£795 / €930 excl. VAT per person  
Private session pricing: upon request, depending on context and number of participants

Duration

7 hours

Training format

Synchronous (on-site or remote)

CPE credits

1

Learning Objectives:

By the end of the session, participants will be able to:

  • Explain the board's personal obligations for cyber risk oversight under NIS2, DORA, and the EU AI Act
  • Define a complete risk scenario (asset, threat, vector, effect) with quantified impact
  • Distinguish first-party and third-party risk exposure and identify their organization's role in each
  • Ask the right questions of internal teams and external vendors, and evidence informed oversight
Target Audience:

Who Should Attend

Management bodies, executive committees, and leaders with oversight responsibility under NIS2 or DORA (CISOs, CROs, CFOs, General Counsel, business unit leaders).

Prerequisites

None.

Course Content:

Why You Are Here: The Mandate

  • Executive training is a legal obligation under NIS2, DORA, and the EU AI Act
  • Why "my CISO handles that" is no longer a sufficient governance posture, and what "sufficient knowledge" means in practice

Defining Risk in Business Terms

  • Risk = a loss event with a likelihood and a financial consequence
  • The four components of a complete risk: asset, threat, vector, effect + quantified impact
  • Introduction to FAIR as a quantification method

Third-Party Risk as First-Party Liability

  • Risk and regulatory responsibility can't be outsourced
  • Understanding your organization's seat: first party, third party, or both

Identifying and Classifying Risk

  • Interactive exercise: spotting real risks vs. isolated risk components
  • Assembling components into a coherent, quantifiable scenario

Accountability and Enforcement

  • Key obligations and penalties under NIS2, DORA, and the EU AI Act
  • Board minutes, training records, and reporting as evidence of oversight

Risk Tolerance and Organizational Readiness

  • Why tolerance must be defined before risk can be measured
  • Setting risk appetite as a board-owned responsibility

Aggregation and Board-Level Reporting

  • From individual scenarios to aggregate portfolio exposure
  • Using a quantified approach to challenge vendor and advisory assessments

Instructional Team:

Senior C-Risk cyber risk experts with experience training executive teams on cyber risk governance and other cybersecurity topics.

Monitoring of implementation and evaluation of results:
  • Q&A
  • Live polls to test understanding of key concepts
Technical and educational resources:
  • Certificate of completion with CPEs
  • Concise, decision-oriented presentation materials provided to participants

C-Risk

Advance Your Career with Cyber Risk Management Training

E-learning platform and instructor-led courses in quantification, cyber risk frameworks, and data-driven decision-making.
C-Risk Education equips you with the skills to analyze and manage cyber risk effectively. Our training covers multiple methodologies and frameworks: cyber risk quantification, EBIOS RM, third-party risk management, and advanced threat and control assessment techniques. 
Learn practical, immediately applicable skills across the full spectrum of modern cyber risk management.

In-person
Introduction to Data-Driven Cyber Risk Management with the FAIR™ Standard

Learn data-driven cyber risk management with FAIR standard. 3-hour instructor-led course on quantifying cyber risk in financial terms. No prerequisites.

Half-day (3 hours)
Learn more
E-learning
Introduction to Data-Driven Cyber Risk Management with the FAIR™ Standard - e-Learning

Learn FAIR™ cyber risk quantification at your own pace. 3-hour e-learning covering risk management fundamentals and financial risk analysis.

3 hours of e-Learning content (unlimited access for 3 months)
Learn more
In-person
Data-Driven Cyber Risk Management with the FAIR™ Standard for Practitioners

Master FAIR™ methodology in 12 hours. Learn quantitative cyber risk analysis, overcome qualitative limits, and make data-driven security decisions.

12 hours
Learn more
E-learning
Data-Driven Cyber Risk Management with the FAIR™ Standard for Practitioners - e-Learning

Master FAIR™ cyber risk quantification with 12 hours of e-learning. Model risk scenarios, estimate loss factors, prepare for Open FAIR™ 2 certification.

Approximately 12 hours of e-Learning content (unlimited access for 3 months)
Learn more
In-person
From Regulation to Decision: Defensible Cyber Risk Governance for Executives under NIS2, DORA and the EU AI Act

Meet your board's cyber risk oversight obligations under NIS2, DORA, and the EU AI Act, and learn to govern cyber risk with the same rigor as financial risk. Full-day executive program for management bodies and senior leaders. €930 per person. 6 CPE credits included.

Full day (7 hours), on-site or remote
Learn more
In-person
Turning Controls into Measurable Risk Reduction with FAIR-CAM

Learn to quantify security control effectiveness using FAIR-CAM™. Model risk reduction, analyze attack chains, and integrate controls into FAIR™ analyses.

4 hours
Learn more
E-learning
Turning Controls into Measurable Risk Reduction with FAIR-CAM – e-Learning

Master FAIR-CAM™ to quantify security control effectiveness. 10-hour e-learning for FAIR practitioners. €695 per person. 10 CPE credits included.

Approximately 10 hours of e-learning content (unlimited access for 3 months)
Learn more
E-learning
Building a Data-Driven Third-Party Risk Management (TPRM) Program with FAIR™ – e-Learning

Learn to quantify third-party cyber risks using FAIR™. 10-hour e-learning course covering TPRM lifecycle, risk scenarios, and financial quantification.

Approximately 10 hours of e-Learning content (unlimited access for 3 months)
Learn more
E-learning
Risk & Digital Resilience for Executives : DORA & NIS2 Obligations — E-learning

Fulfil your DORA and NIS2 training obligations and learn why cybersecurity is a governance issue, and how to oversee it effectively. 5-hour e-learning for executives and board members. €895 per person. 5 CPE credits included.

Approximately 5 hours of e-Learning content (unlimited access for 6 months)
Learn more