ED-IN-03 – From Regulation to Decision: Defensible Cyber Risk Governance for Executives: Meeting your oversight obligations under NIS2, DORA and the EU AI Act
Duration: 7 hours
Training format: Synchronous (on-site or remote)
CPE credits: 6
Pricing
- £795 / €930 excl. VAT per person
- Private session pricing: upon request, depending on context and number of participants
Capacity: up to 15 executives per session
Cybersecurity risk is an enterprise risk. It should be understood, measured, and governed in defensible business terms, with the same rigor applied to financial and operational risk.
This full-day executive program equips you to meet their cyber risk oversight and training obligations under NIS2, DORA, and the EU AI Act. Participants learn to provide defensible oversight and build an effective cybersecurity governance strategy, grounded in the idea that cyber risk can be quantified, prioritized and governed more objectively.
£795 / €930 excl. VAT per person
Private session pricing: upon request, depending on context and number of participants
7 hours
Synchronous (on-site or remote)
1
By the end of the session, participants will be able to:
- Explain the board's personal obligations for cyber risk oversight under NIS2, DORA, and the EU AI Act
- Define a complete risk scenario (asset, threat, vector, effect) with quantified impact
- Distinguish first-party and third-party risk exposure and identify their organization's role in each
- Ask the right questions of internal teams and external vendors, and evidence informed oversight
Who Should Attend
Management bodies, executive committees, and leaders with oversight responsibility under NIS2 or DORA (CISOs, CROs, CFOs, General Counsel, business unit leaders).
Prerequisites
None.
Why You Are Here: The Mandate
- Executive training is a legal obligation under NIS2, DORA, and the EU AI Act
- Why "my CISO handles that" is no longer a sufficient governance posture, and what "sufficient knowledge" means in practice
Defining Risk in Business Terms
- Risk = a loss event with a likelihood and a financial consequence
- The four components of a complete risk: asset, threat, vector, effect + quantified impact
- Introduction to FAIR as a quantification method
Third-Party Risk as First-Party Liability
- Risk and regulatory responsibility can't be outsourced
- Understanding your organization's seat: first party, third party, or both
Identifying and Classifying Risk
- Interactive exercise: spotting real risks vs. isolated risk components
- Assembling components into a coherent, quantifiable scenario
Accountability and Enforcement
- Key obligations and penalties under NIS2, DORA, and the EU AI Act
- Board minutes, training records, and reporting as evidence of oversight
Risk Tolerance and Organizational Readiness
- Why tolerance must be defined before risk can be measured
- Setting risk appetite as a board-owned responsibility
Aggregation and Board-Level Reporting
- From individual scenarios to aggregate portfolio exposure
- Using a quantified approach to challenge vendor and advisory assessments
Senior C-Risk cyber risk experts with experience training executive teams on cyber risk governance and other cybersecurity topics.
- Q&A
- Live polls to test understanding of key concepts
- Certificate of completion with CPEs
- Concise, decision-oriented presentation materials provided to participants
Advance Your Career with Cyber Risk Management Training
E-learning platform and instructor-led courses in quantification, cyber risk frameworks, and data-driven decision-making. C-Risk Education equips you with the skills to analyze and manage cyber risk effectively. Our training covers multiple methodologies and frameworks: cyber risk quantification, EBIOS RM, third-party risk management, and advanced threat and control assessment techniques. Learn practical, immediately applicable skills across the full spectrum of modern cyber risk management.

Learn data-driven cyber risk management with FAIR standard. 3-hour instructor-led course on quantifying cyber risk in financial terms. No prerequisites.

Learn FAIR™ cyber risk quantification at your own pace. 3-hour e-learning covering risk management fundamentals and financial risk analysis.

Master FAIR™ methodology in 12 hours. Learn quantitative cyber risk analysis, overcome qualitative limits, and make data-driven security decisions.

Master FAIR™ cyber risk quantification with 12 hours of e-learning. Model risk scenarios, estimate loss factors, prepare for Open FAIR™ 2 certification.

Meet your board's cyber risk oversight obligations under NIS2, DORA, and the EU AI Act, and learn to govern cyber risk with the same rigor as financial risk. Full-day executive program for management bodies and senior leaders. €930 per person. 6 CPE credits included.

Learn to quantify security control effectiveness using FAIR-CAM™. Model risk reduction, analyze attack chains, and integrate controls into FAIR™ analyses.
.jpg)
Master FAIR-CAM™ to quantify security control effectiveness. 10-hour e-learning for FAIR practitioners. €695 per person. 10 CPE credits included.

Learn to quantify third-party cyber risks using FAIR™. 10-hour e-learning course covering TPRM lifecycle, risk scenarios, and financial quantification.

Fulfil your DORA and NIS2 training obligations and learn why cybersecurity is a governance issue, and how to oversee it effectively. 5-hour e-learning for executives and board members. €895 per person. 5 CPE credits included.