EC02 - Cybersecurity Governance

Leading cybersecurity governance for resilient and responsible organisations.

Credits

7.5 ECTS

Semester

1 Semester

Delivery

Online

Duration

13 weeks

Language

English

About This Course

This is a firts-semester course in the MBA in Advanced Cybersecurity Technologies &
Governance
This course explores how organisations develop and manage effective cybersecurity governance, risk management, and compliance strategies in increasingly complex digital environments.
Learners will examine the role of cybersecurity within organisational leadership, including governance frameworks, risk assessment methodologies, privacy regulations, and security culture development. The course also addresses international standards such as GDPR, NIS2, ISO/IEC 27001, and NIST, preparing learners to align cybersecurity strategy with business objectives and regulatory requirements.
By combining governance, legal, operational, and strategic perspectives, this course prepares participants to support and lead enterprise cybersecurity programmes across diverse sectors.

What You Will Learn


Cybersecurity Governance & Strategy

  • Principles of cybersecurity governance and organisational security
  • Roles and responsibilities of leadership in cybersecurity management
  • Security culture and strategic decision-making frameworks


Risk Management & Compliance

  • Cyber risk assessment and threat modelling methodologies
  • GDPR, DPIA, and privacy governance requirements
  • International cybersecurity standards and regulatory frameworks


Enterprise Security Operations

  • Development and operation of Information Security Management Systems (ISMS)

  • Security controls, compliance processes, and maturity models

  • Governance approaches for third-party and supply-chain security

Your 13-Week Journey

Here’s how your learning unfolds

Week 1 – Cybersecurity Intro 

Understanding core cybersecurity principles, threat actors, malware, and attack vectors.

Week 2 – Cybersecurity landscape

Exploring cybersecurity technologies, architectures, and emerging research areas.

Week 3 – Data Protection 

Examining data protection principles, privacy frameworks, and GDPR fundamentals.

Week 4 – GDPR/DPIA

Applying GDPR and DPIA methodologies through industry and insurance use cases.

Week 5 – Cyber Governance Standards 

Understanding ISO and NIST governance frameworks for cybersecurity management.

Week 6 – ISMS Practice

Designing and operating Information Security Management Systems (ISMS).

Week 7 – Risk Management

Exploring cyber risk management standards and insurance-based mitigation strategies.

Week 8 – Risk Assessment

Applying qualitative and quantitative methods for cyber risk assessment.

Week 9 – The CISO Role  

Understanding the strategic role of CISOs in governance, compliance, and decision-making.

Week 10 – Cyber Readiness and Incident Response

Managing cyber readiness, incident response processes, and crisis scenarios.

Week 11 – Regulations  

Analysing EU cybersecurity regulations and risk-based compliance approaches.

Week 12 – Cyber Politics

This week explores personal data cyber risks, GDPR exposure, and how cyber insurance supports incident response and broader risk management.

Week 13 – Use-Cases 

Applying governance, compliance, and risk management concepts through real-world use cases.


Empty space, drag to resize

Skills You Will Gain

Cyber Risk & Governance Management

  • Conducting cybersecurity risk assessments and DPIAs
  • Designing and managing ISMS frameworks
  • Aligning cybersecurity strategy with business and regulatory requirements

Compliance & Security Leadership

  • Mapping standards such as GDPR, NIS2, ISO 27001, and NIST CSF to enterprise controls
  • Developing governance policies and security culture programmes
  • Supporting executive decision-making and board-level reporting

Strategic & Organisational Cybersecurity

  • Managing third-party and supply-chain security risks
  • Coordinating cross-functional cybersecurity governance initiatives
  • Driving continuous improvement and organisational cyber resilience