Cyber Incident Management
Cyber incident management training for the person who has to run the room, not the forensic image. Eight weeks on command and coordination, decision making under partial information, and the communications that follow a serious incident.
You practise the parts that are hardest to rehearse: briefing an executive with incomplete facts, working with legal counsel and insurers, and meeting notification obligations under Canadian privacy law.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Take incident command and run a bridge with defined roles and a decision log
- Classify severity consistently and trigger escalation without hesitation
- Decide on containment when the information is incomplete and the clock is running
- Brief an executive team with what is known, unknown and needed from them
- Work with legal counsel, privilege considerations, insurers and external responders
- Identify when PIPEDA breach notification obligations are likely engaged and who decides
- Run a post-incident review that changes the programme instead of assigning blame
- Prepare a written incident report suitable for a board or an audit committee
Course outline
6 modules
- Plan structure: what belongs in the plan and what belongs in a playbook
- Roles: commander, technical lead, communications lead and scribe
- Severity classification and escalation triggers
- Retainers, external responders and pre-agreed contracts
- Out of band communication and the assumption that email is compromised
What you need before you start
- Experience of at least one real incident, in any role
- A leadership, management or coordination responsibility during incidents
- Willingness to take command during live tabletop exercises
- About four hours a week outside class for plan development and debriefs
Who this course is for
- Security managers and directors who own incident response
- Incident response leads moving from technical work to coordination
- IT leaders who take command when systems go down
- Risk, legal and communications staff who join the incident bridge
- Executives who want to understand their role before it is needed
Where this leads
Prepares you for
CISM
Awarded by ISACA
This course maps closely to the incident management domain of ISACA CISM. The examination, the experience requirement and the credential itself are all administered by ISACA. We prepare you for the work and for that syllabus.
Questions about this course
More in security leadership and governance
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



