Cyber Security Risk Management and Compliance
Risk and compliance training in Toronto for people who have to satisfy auditors and improve security at the same time. Eight weeks on framework mapping, register discipline, and wiring compliance into operations instead of running it in parallel.
Canadian obligations run through the whole course, from PIPEDA breach reporting to sector expectations for financial institutions and critical infrastructure.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Build a risk register with named owners, treatment plans and review dates
- Crosswalk one control set to several frameworks and stop duplicating evidence
- Explain where PIPEDA mandatory breach reporting affects your incident process
- Identify which sector expectations apply to your organization and who confirms them
- Design control evidence that operations produces naturally as a by-product
- Assess third party and supply chain risk proportionate to what the vendor touches
- Report risk to an audit committee in terms of decisions rather than colours
- Prepare for an external audit without a three week evidence scramble
Course outline
6 modules
- Risk, threat, vulnerability and impact used consistently across the organization
- Risk appetite and tolerance, and how to elicit them from leadership
- Enterprise risk management and where cyber risk fits inside it
- Treatment options: mitigate, transfer, avoid, accept
- Building risk into project and change processes rather than after them
What you need before you start
- Working knowledge of common security controls and IT operations
- Some exposure to audit, risk or compliance activity in a workplace
- A real or anonymized organization to build the register against
- Around four hours a week outside class for register and crosswalk work
Who this course is for
- Governance, risk and compliance analysts and managers
- Security managers who own audit responses and risk reporting
- IT leaders preparing for ISO 27001 certification or a customer audit
- Privacy and legal staff who work alongside a security function
Where this leads
Prepares you for
CRISC
Awarded by ISACA
Course content aligns with the governance, risk response and reporting domains of ISACA CRISC. ISACA administers the exam, validates experience and issues the credential. Our role is preparation, practice and feedback on your written work.
Questions about this course
More in security leadership and governance
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



