Security Strategic Planning, Policy and Leadership
Security strategy training in Toronto for leaders who already run a function and now have to set its direction. Over ten weeks you build a multi-year strategy, the policy set that supports it, and the executive narrative that gets it funded.
The work is yours, not a case study. You bring your own organization, or an anonymized version of it, and leave with a strategy document under peer and instructor review.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Security Leadership Essentials for Managers
- Class size
- Capped at 12 learners

What you will be able to do
- Translate business strategy and risk appetite into security objectives with owners
- Build a three year roadmap with sequencing, dependencies and funding phases
- Assess current capability honestly and describe the gap without alarmism
- Draft policy that is enforceable, readable and mapped to a control framework
- Present a funding case to an executive committee and answer the hard question
- Brief a board on risk posture in ten minutes without technical jargon
- Lead a transformation programme through resistance, delay and reorganization
- Set review cadences that keep the strategy alive rather than shelved
Course outline
6 modules
- Finding the business strategy and the pressures behind it
- Risk appetite: eliciting it when nobody has written it down
- Stakeholder mapping across finance, legal, operations and technology
- Regulatory and contractual drivers, including sector specific expectations
- Deciding what security is actually for in this organization
What you need before you start
- Completion of Security Leadership Essentials or equivalent management experience
- Current responsibility for a security function, programme or significant budget
- An organization, current or recent, to build the strategy against
- Around six hours a week outside class for drafting and peer review
Who this course is for
- Security managers preparing for a director or head of security role
- Directors and heads of security setting direction for the first time
- Senior risk and technology leaders who own security outcomes
- Consultants building security strategies for client organizations
Where this leads
Prepares you for
CISM
Awarded by ISACA
Strategy, governance and policy content here maps to the information security governance and programme domains of ISACA CISM. ISACA sets the exam, verifies experience and grants the certification. We provide the instruction and practice.
Questions about this course
More in security leadership and governance
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



