Skip to main content
CISO life

Lead Cybersecurity Manager

Lead Cybersecurity Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBManager5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and leaders with responsibility for cybersecurity management
  • Individuals tasked with implementing cybersecurity strategies and operational measures
  • IT and security professionals seeking to advance into cybersecurity management roles
  • Professionals responsible for managing cybersecurity risk and compliance
  • C-suite executives involved in cybersecurity-related decision making

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals who are entirely new to cybersecurity and need foundational technical training before approaching programme management
  • Professionals seeking a hands-on offensive security or penetration testing course
  • Those looking specifically for ISO/IEC 27001 ISMS lead auditor or lead implementer certification preparation

What you'll be able to do

  • 1Explain fundamental cybersecurity concepts, strategies, and methodologies used to implement and manage a cybersecurity programme
  • 2Describe the relationship between ISO/IEC 27032, the NIST Cybersecurity Framework, and other relevant standards and frameworks
  • 3Initiate a cybersecurity programme and establish appropriate governance structures
  • 4Define cybersecurity roles and responsibilities within an organisation
  • 5Apply risk management processes to identify, analyse, and treat cybersecurity risks
  • 6Select and implement cybersecurity controls aligned with recognised frameworks
  • 7Establish cybersecurity communication and training programmes for internal and external stakeholders
  • 8Monitor cybersecurity programme performance and apply continual improvement principles

Day by day

Day 1Introduction to cybersecurity and initiation of a cybersecurity programme
  • Fundamental concepts of cybersecurity

    Participants review core cybersecurity terminology, threat landscapes, and the strategic role of a structured cybersecurity programme within an organisation.

  • Cybersecurity standards and frameworks overview

    This module examines ISO/IEC 27032, the NIST Cybersecurity Framework, and related standards, clarifying how they relate to one another and to broader information security governance.

  • Initiating the cybersecurity programme and governance

    Learners explore the steps required to scope a cybersecurity programme, secure leadership commitment, and establish governance structures that support programme objectives.

By end of day

  • Articulate the strategic purpose of a cybersecurity programme to organisational leadership
  • Map ISO/IEC 27032 and the NIST Cybersecurity Framework to organisational governance requirements
Day 2Cybersecurity roles and responsibilities, risk management, and attack mechanisms
  • Defining cybersecurity roles and responsibilities

    This module addresses how to assign, document, and communicate cybersecurity responsibilities across functions, including board-level accountability.

  • Cybersecurity risk management

    Participants learn how to identify, analyse, evaluate, and treat cybersecurity risks using structured risk management methodologies.

  • Cyber attack mechanisms and threat actors

    This module provides an overview of common attack techniques and threat actor categories so that managers can frame risk discussions with technical teams effectively.

By end of day

  • Assign cybersecurity roles and responsibilities using a structured accountability model
  • Apply a risk management process to prioritise cybersecurity threats and develop treatment plans
Day 3Cybersecurity controls, communication, and awareness and training
  • Selecting cybersecurity controls

    Learners examine how to choose controls from recognised frameworks to address identified risks, considering organisational context and resource constraints.

  • Cybersecurity communication programmes

    This module covers the design of internal and external communication strategies to keep stakeholders informed about cybersecurity risks, incidents, and programme status.

  • Cybersecurity awareness and training

    Participants learn how to develop and deliver training programmes that build security awareness and competence across different organisational roles.

By end of day

  • Select and justify cybersecurity controls aligned with framework guidance and organisational risk appetite
  • Design a cybersecurity awareness and communication programme for diverse internal audiences
Day 4Cybersecurity incident management, monitoring, and continual improvement
  • Integrating cybersecurity with business continuity and incident management

    This module examines how cybersecurity incident management processes connect with broader business continuity plans to minimise operational disruption during a cyber event.

  • Monitoring and measuring cybersecurity programme performance

    Participants learn how to define key performance indicators, conduct reviews, and use measurement data to demonstrate programme effectiveness.

  • Continual improvement of the cybersecurity programme

    This module covers how to use audit findings, incident lessons learned, and performance data to drive ongoing improvements to the cybersecurity programme.

By end of day

  • Develop a cybersecurity incident response process integrated with business continuity management
  • Establish performance metrics and a review cycle to sustain cybersecurity programme improvement
Day 5Certification exam
  • PECB Certified Lead Cybersecurity Manager exam

    The exam assesses seven competency domains spanning cybersecurity fundamentals, programme governance, roles and risk management, control selection, communication and training, incident management, and performance measurement, as defined by the PECB Examination and Certification Program.

By end of day

  • Consolidate knowledge across all programme domains in preparation for the PECB Certified Lead Cybersecurity Manager exam

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental concepts of cybersecurity
  • Domain 2: Initiating the cybersecurity program and cybersecurity governance
  • Domain 3: Defining cybersecurity roles and responsibilities and managing risks
  • Domain 4: Selecting cybersecurity controls
  • Domain 5: Establishing cybersecurity communication and training programs
  • Domain 6: Integrating the cybersecurity program in business continuity management and incident management
  • Domain 7: Measuring the performance of and continually improving the cybersecurity program
  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Educational approach

  • The training course covers theoretical concepts and practical examples in cybersecurity, enabling participants to grasp the effective application of cybersecurity strategies and technologies.
  • The training course includes various assessments, including essay-type exercises, and multiple-choice quizzes, some of which are scenario-based.
  • The participants are encouraged to interact and have meaningful discussions with each other while working on quizzes and exercises, creating a collaborative learning environment.
  • The quiz structure within the course closely mirrors that of the certification exam, ensuring participants are well-prepared for the exam.

Buyers always ask

What is the distinction between completing this training, passing the exam, and earning a PECB credential?+

Training completion means you have attended and engaged with all course content delivered by Cyber Academy. Passing the PECB exam demonstrates that you have met the knowledge standards defined in PECB's Examination and Certification Program across seven competency domains.

Obtaining a PECB credential involves passing the exam and fulfilling any professional-experience requirements specified by PECB. Cyber Academy does not administer the exam or issue certifications; those steps are managed directly through PECB.

How does ISO/IEC 27032 relate to the NIST Cybersecurity Framework in this programme?+

ISO/IEC 27032 provides internationally recognised guidelines specifically focused on cybersecurity in cyberspace, addressing the gaps between information security, network security, and internet security. The NIST Cybersecurity Framework offers a risk-based structure for organising cybersecurity activities across five functions.

This programme examines both, helping participants understand how they complement each other and how organisations can draw on both to build a comprehensive cybersecurity programme.

Which competency domains does the PECB Lead Cybersecurity Manager exam cover?+

According to PECB, the exam covers seven domains: fundamental cybersecurity concepts, programme initiation and governance, roles and responsibilities with risk management, control selection, communication and training programmes, integration with business continuity and incident management, and performance measurement with continual improvement.

Consult the PECB List of Exams and Examination Rules and Policies for current details on exam format, duration, and available languages.

Is this programme appropriate for a C-suite executive with limited hands-on security experience?+

The programme is designed in part for executives involved in cybersecurity decision making. The content emphasises governance, risk management, programme oversight, and communication rather than technical implementation, making it accessible to leaders who work with security teams rather than configure systems directly.

A fundamental understanding of cybersecurity concepts is still recommended so that discussions of risk treatment and control selection are meaningful within your leadership context.

How does Day 4 content on incident management connect to business continuity?+

Day 4 specifically addresses the integration of cybersecurity incident management with business continuity management, recognising that a significant cyber event can have direct operational consequences. Participants examine how incident response plans should align with business continuity and disaster recovery plans to minimise disruption.

This integrated perspective is reflected in PECB's exam domain structure, which explicitly links these two disciplines within a single competency area.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.