Cyber Risk for Non-Technical Managers for Small and Medium Enterprises
3 days|Delivered on request
Cyber Risk for Non-Technical Managers for Small and Medium Enterprises takes the discipline and works it through the constraints of this operating context, including risk reporting to the board, regulatory reporting and the compliance obligations that come with it. The sector framing is necessary because compliance obligations have multiplied faster than compliance capacity, and generic training rarely survives contact with the local rules. Delegates leave able to work confidently with operational risk, control design and combined assurance in their own organisation.
What delegates leave able to do
- Take ownership of operational risk rather than escalating it, measured against the three lines model
- Spot where control design is failing before it becomes a finding
- Explain combined assurance to someone who does not do the work
- Improve risk appetite and tolerance within their own organisation
What the course covers
- Risk reporting to the board
- Regulatory reporting
- Operational risk
- Control design
- Combined assurance
- Risk appetite and tolerance
- Scenario analysis
Who should attend
- audit and risk committee members
- business continuity coordinators
- governance and assurance practitioners
- risk champions in operating units

