4-day masterclass programme
DAILY LIVE HACKING DEMONSTRATIONS
Woven throughout the four days, attendees experience five live hacking demonstrations that bring classroom theory to life with raw, unfiltered realism. From nation-state cyber operations deployed in the Iran and Ukraine conflicts, to a live website breach showing exactly how attackers steal money in real time, to a dual-perspective phishing attack seen through both the attacker's and victim's eyes — each demonstration is designed to create the kind of visceral understanding that no slide deck can replicate. A full technical walkthrough of a ransomware attack exposes every stage of the kill chain from initial access to encryption, while a final digital forensics session uses professional file carving tools to recover hidden and deleted evidence from a compromised system. Together, these demonstrations ensure that every CISO leaves not just informed, but genuinely changed in how they think about the threats facing their organisation.
DAY ONE
SECURING ENTERPRISE CYBER RESILIENCE: STRATEGIC FOUNDATIONS AND REGULATORY LANDSCAPE
09:00 - 09:30 | Registration & Networking
09:30 - 10:45 | SESSION 1: The Modern Threat Landscape & Strategic Risk Management
-
Evolution of cyber threats facing medium and large corporations
-
Understanding Advanced Persistent Threats (APTs) and state-sponsored attacks
-
The convergence of IT and OT security risks
-
Board-level cyber risk communication strategies
-
Quantifying cyber risk in financial terms
Key Takeaways:
-
Board-ready risk assessment frameworks
-
Threat intelligence integration strategies
-
Strategic planning templates
Leave with battle-tested frameworks to present cyber risk as a business priority to boards and senior leadership. This session equips CISOs with the strategic vocabulary and analytical tools to reframe cyber risk in language that resonates at board level. By understanding the evolving threat landscape — from APTs to state-sponsored campaigns — and learning how to quantify risk in financial terms, attendees gain immediate credibility in boardroom conversations. Leaders leave with practical frameworks for threat intelligence integration and a strategic planning toolkit they can deploy within days of returning to their organisation.
10:45 - 11:00 | Morning Coffee Break
11:00 - 12:30 | SESSION 2: Global Regulatory Compliance Frameworks
-
GDPR: Comprehensive requirements for global corporations
-
ISO 27001/27002 implementation strategies
-
NIST Cybersecurity Framework
-
Industry-specific regulations: HIPAA, PCI-DSS, SOX, GLBA
-
NIS2 Directive and critical infrastructure protection
-
Cross-border data transfer mechanisms and challenges
-
Emerging regulations: AI governance, supply chain security
Key Takeaways:
-
Creating a multi-regulatory compliance matrix
-
Audit preparation checklist
-
Compliance Cyber Security questionnaire Template for 3rd parties and your supply chain.
Master multi-jurisdictional compliance and gain ready-to-use audit tools that reduce regulatory exposure across every major global framework. Navigating a patchwork of overlapping global regulations is one of the defining challenges facing CISOs today. This session cuts through the complexity by mapping GDPR, ISO 27001, NIST, NIS2, HIPAA, PCI-DSS, SOX, and emerging AI governance requirements into a single, actionable compliance matrix. Attendees return with pre-built audit checklists and supply chain questionnaire templates that compress months of compliance work into structured, repeatable processes — reducing regulatory risk and strengthening relationships with auditors and regulators.
12:30 - 13:30 | Lunch & Discussions
13:30 - 15:00 | SESSION 3: Network Security Architecture & Zero Trust Implementation
-
Network segmentation strategies for enterprise environments
-
Zero Trust architecture principles and implementation
-
Software-Defined Perimeter (SDP) deployment
-
Micro-segmentation best practices
-
Network access control (NAC) solutions
-
Securing cloud, hybrid, and multi-cloud networks
-
SD-WAN security considerations
-
Critical infrastructure network protection
-
Attack surface mapping for your network topology
Key Takeaways:
-
Zero Trust implementation roadmap
-
Creating Critical Systems boundaries
-
Segmentation strategy templates
You will gain the architectural knowledge to design and implement Zero Trust networks that dramatically shrink the attack surface of enterprise environments. Zero Trust is one of the most transformative and widely misunderstood security paradigms in modern enterprise security. This session demystifies the architecture and gives CISOs a clear, phased implementation roadmap they can take back to their teams. From micro-segmentation and Software-Defined Perimeter design to securing multi-cloud and OT environments, attendees develop the technical and strategic confidence to lead Zero Trust programmes that reduce lateral movement risk and protect critical systems from both internal and external threats.
15:00 - 15:15 | Afternoon Tea Break
15:15 - 16:15 | SESSION 4: Incident Response & Crisis Management
-
Building effective incident response teams
-
IR framework development (NIST, SANS)
-
Escalation procedures and decision trees
-
Legal and regulatory notification requirements
-
Crisis communication strategies
-
Forensics preservation best practices
-
Post-incident review and continuous improvement
Key Takeaways:
-
Customized incident response plan template
-
Crisis communication scripts
-
IR team structure and RACI matrix
Attendees will build a battle-ready incident response capability, ensuring their organisation can detect, contain, and recover from cyber incidents with speed and legal precision. A cyber incident is not a matter of if but when — and the difference between a contained breach and a catastrophic one often comes down to preparation. This session gives CISOs everything they need to build, test, and lead an effective incident response function. From NIST and SANS framework alignment to crisis communication scripts and forensics preservation protocols, attendees leave with a customised IR plan template and a clear RACI matrix to ensure every stakeholder knows their role before, during, and after an incident.
16:15 – 16:30 | Day 1 Wrap-Up & Q&A
DAY TWO
OPERATIONAL SECURITY & TECHNOLOGY CONTROLS: IMPLEMENTING ROBUST DEFENCE MECHANISMS
09:30 - 10:45 | SESSION 5: Identity & Access Management (IAM) Excellence
-
Enterprise IAM architecture design
-
Privileged Access Management (PAM) strategies
-
Single Sign-On (SSO) and federation
-
Identity governance and administration (IGA)
-
Cloud identity management: Azure AD, Okta, Ping
-
Service account and API key management
-
Biometric authentication and password-less strategies
-
Service account audit and remediation
Key Takeaways:
-
Enterprise IAM roadmap
-
Access control policy templates
-
PAM implementation guide
Build a comprehensive IAM architecture that eliminates identity-based risk — the leading entry point in the majority of enterprise breaches. Compromised credentials remain the single most common cause of enterprise data breaches, making IAM excellence a non-negotiable priority for CISOs. This session provides a deep dive into enterprise IAM architecture, with particular focus on Privileged Access Management, cloud identity platforms, and the move toward password-less and biometric authentication. Attendees gain a practical IAM roadmap and access control policy templates that strengthen identity governance across on-premises, cloud, and hybrid environments — immediately reducing the risk of credential-based attacks.
10:45 - 11:00 | Morning Coffee Break
11:00 - 12:30 | SESSION 6: Endpoint Security & Mobile Device Management
-
Endpoint Detection and Response (EDR) vs. Extended Detection and Response (XDR)
-
Next-generation antivirus (NGAV) deployment
-
Mobile Device Management (MDM) and Mobile Application Management (MAM)
-
BYOD security policies and containerization
-
USB and removable media controls
-
Application whitelisting and control
-
Patch management at scale
-
Endpoint hardening standards (CIS Benchmarks)
Key Takeaways:
-
Endpoint security stack recommendations
-
MDM/MAM policy templates
-
Hardening baselines for major OS platforms
Develop a comprehensive endpoint security strategy that protects every device in the enterprise estate, including remote, mobile, and BYOD assets. With remote work now a permanent fixture and BYOD policies widespread, the endpoint has become the frontline of enterprise defence. This session equips CISOs with the knowledge to evaluate, select, and deploy the right combination of EDR, XDR, NGAV, MDM, and application control technologies for their specific environment. Attendees gain CIS-aligned hardening baselines for all major operating systems, MDM/MAM policy templates, and a structured patch management approach - enabling you to dramatically reduce the endpoint attack surface across their entire workforce.
12:30 - 13:30 | Lunch & Discussions
13:30 - 15:00 | SESSION 7: Cloud Security & Multi-Cloud Strategy
-
Shared responsibility model (AWS, Azure, GCP)
-
Cloud Security Posture Management (CSPM)
-
Cloud Workload Protection Platforms (CWPP)
-
Container and Kubernetes security
-
Cloud access security brokers (CASB)
-
Infrastructure as Code (IaC) security
-
Cloud data encryption and key management
-
Multi-cloud security orchestration
Key Takeaways:
-
Cloud security reference architectures
-
IaC security templates
-
Cloud compliance checklist
Attendees achieve the cloud security expertise to govern multi-cloud environments confidently, eliminating misconfigurations — the leading cause of cloud data breaches. Cloud adoption has fundamentally changed the security perimeter, and misconfigurations in cloud environments now account for a significant proportion of major breaches. This session equips CISOs with a comprehensive understanding of the shared responsibility model across AWS, Azure, and GCP, and provides practical guidance on deploying CSPM, CWPP, CASB, and container security controls. Attendees leave with cloud security reference architectures and IaC security templates that enable their teams to build securely by default — transforming cloud from a liability into a controlled, auditable asset.
15:00 – 15:15 | Afternoon Tea Break
15:15 - 16:15 | SESSION 8: Data Protection & Encryption Strategies
-
Data classification frameworks and DLP implementation
-
Encryption at rest and in transit standards
-
Key management lifecycle and HSM deployment
-
Database security and encryption
-
Tokenisation and data masking strategies
-
Backup encryption and secure recovery
-
Data sovereignty and residency requirements
-
Rights management and document protection
Key Takeaways:
-
Data classification schema
-
Encryption standard operating procedures
-
DLP implementation roadmap
Gain mastery of data protection architecture, ensuring sensitive data is classified, encrypted, and governed across its entire lifecycle. Data is the asset that adversaries are ultimately targeting, and its protection requires a layered strategy that spans classification, encryption, tokenisation, and access control. This session provides CISOs with a structured approach to building and maturing a data protection programme, covering everything from HSM deployment and key lifecycle management to database encryption and data sovereignty requirements. Attendees leave with a data classification schema, encryption standard operating procedures, and a DLP implementation roadmap they can present to senior leadership as a measurable, defensible programme of work.
16:15 – 16:30 | Day 2 Wrap-Up & Q&A
DAY THREE
ADVANCED THREATS & SECURITY OPERATIONS: BUILDING PROACTIVE DEFENCE CAPABILITIES
09:30 - 10:45 | SESSION 9: Security Operations Centre (SOC) Excellence
-
Building vs. outsourcing SOC: Decision framework
-
SIEM architecture and use case development
-
Security orchestration, automation, and response (SOAR)
-
Threat hunting methodologies and programs
-
Security analytics and behavioural detection
-
Alert triage and investigation workflows
-
SOC metrics and KPIs that matter
-
Integrating threat intelligence feeds
-
24/7 operations staffing and shift management
Key Takeaways:
-
SOC operational handbook
-
SIEM use case library
-
Threat hunting playbooks
Gain the operational knowledge to build or optimise a world-class SOC that moves from reactive alerting to proactive threat detection and hunting. The Security Operations Centre is the nerve centre of an organisation’s cyber defence, yet many SOCs are overwhelmed by alert fatigue and limited by poor tooling and processes. This session gives CISOs a practical blueprint for SOC excellence — whether building in-house or evaluating managed service options. From SIEM architecture and SOAR implementation to threat hunting methodologies and meaningful SOC KPIs, attendees gain an operational handbook and use case library that transforms their SOC from a passive monitoring function into a proactive, intelligence-led defence capability.
10:45 - 11:00 | Morning Coffee Break
11:00 - 12:30 | SESSION 10: Network Defence & Perimeter Protection
-
Next-generation firewall (NGFW) deployment and management
-
Intrusion Detection and Prevention Systems (IDS/IPS)
-
Web application firewalls (WAF) and API gateways
-
DDoS mitigation strategies and services
-
DNS security and protective DNS
-
Email security gateway configuration
-
Secure web gateway (SWG) implementation
-
Network traffic analysis and anomaly detection
-
Deception technology and honeypots
Key Takeaways:
-
Network security stack architecture
-
Firewall rule baseline templates
-
DDoS response procedures
Attendees build a resilient, layered network defence architecture capable of detecting, blocking, and responding to the most sophisticated modern attacks. The network perimeter has never been more contested, with adversaries deploying sophisticated combinations of application-layer attacks, DNS exploits, and DDoS campaigns to overwhelm defences. This session equips CISOs with a comprehensive understanding of next-generation perimeter technologies — from NGFW and IDS/IPS to WAF, protective DNS, and deception technology. Attendees leave with a network security stack architecture, firewall rule baseline templates, and DDoS response procedures that give their security teams the tools to identify and neutralise threats before they reach critical systems.
12:30 - 13:30 | Lunch & Discussions
13:30 – 15:00 | SESSION 11: Vulnerability Management & Penetration Testing
-
Building a continuous vulnerability management program
-
Vulnerability scanning tools and deployment strategies
-
Prioritization frameworks: CVSS, EPSS, exploit prediction
-
Patch management processes and automation
-
Web application security testing (DAST, SAST, IAST)
-
Penetration testing methodologies and scoping
-
Red team vs. purple team exercises
-
Bug bounty program design and management
-
Security testing in DevOps (DevSecOps)
Key Takeaways:
-
Vulnerability management program framework
-
Penetration testing SOW templates
-
DevSecOps integration guide
Attendees build a proactive, continuous vulnerability management capability that ensures their organisation finds and fixes weaknesses before attackers do. Vulnerability management is no longer a quarterly scan exercise — it requires a continuous, risk-prioritised programme that spans the entire software development lifecycle. This session gives CISOs a comprehensive framework for building that programme, covering vulnerability scanning, CVSS and EPSS-based prioritisation, automated patching, and the full range of application security testing disciplines. Attendees gain penetration testing SOW templates, a DevSecOps integration guide, and a vulnerability management programme framework that enables their teams to stay ahead of the exploit curve and integrate security seamlessly into agile development practices.
15:00 – 15:15 | Afternoon Tea Break
15:15 - 16:15 | SESSION 12: Security Awareness & Human Risk Management
-
Building effective security awareness programs
-
Phishing simulation and training campaigns
-
Role-based security training development
-
Behavioural psychology in security culture
-
Measuring security culture and awareness effectiveness
-
Insider threat detection and prevention
-
Security champions program design
-
Secure development training for engineers
-
Executive security awareness
Key Takeaways:
-
Annual security awareness program plan
-
Phishing campaign templates
-
Security culture assessment tools
Transform human risk from the organisation’s greatest vulnerability into its strongest line of defence through evidence-based security culture programmes. The human element remains the most exploited vector in cyber attacks, with phishing, social engineering, and insider threats responsible for the majority of successful breaches. This session provides CISOs with the frameworks, tools, and behavioural psychology insights needed to design security awareness programmes that genuinely change behaviour — not just tick compliance boxes. Attendees leave with a complete annual awareness programme plan, phishing simulation templates, a security champions programme design, and cultural assessment tools that allow them to measure and demonstrate tangible improvements in human risk posture across their organisation.
16:15 – 16:30 | Day 1 Wrap-Up & Q&A
DAY FOUR
STRATEGIC LEADERSHIP & FUTURE-READY SECURITY: TRANSFORMING SECURITY INTO BUSINESS ENABLEMENT
09:30 - 10:45 | SESSION 13: Third-Party Risk & Supply Chain Security
-
Vendor risk assessment frameworks
-
Third-party security questionnaire design
-
Continuous vendor monitoring strategies
-
Software supply chain attacks and prevention
-
Fourth-party risk management
-
Contract security requirements and SLAs
-
Vendor breach response and liability
Key Takeaways:
-
Vendor risk assessment framework
-
Security questionnaire templates
-
Third-party monitoring strategy
Build a robust third-party risk programme that extends security governance across the entire supply chain, eliminating the blind spots that attackers exploit. Supply chain attacks have emerged as one of the most damaging and difficult-to-detect threat vectors, with adversaries increasingly targeting vendors and partners as a route into high-value organisations. This session equips CISOs with a comprehensive vendor risk management framework covering initial assessment, continuous monitoring, contractual security requirements, and breach response. Attendees gain pre-built vendor assessment frameworks, security questionnaire templates, and a third-party monitoring strategy that brings rigour and consistency to supplier relationships — significantly reducing the risk of a third-party compromise becoming an enterprise-level incident.
10:45 - 11:00 | Morning Coffee Break
11:00 - 12:30 | SESSION 14: Emerging Technologies & AI Future Threats
-
AI and machine learning in cybersecurity
-
Securing AI/ML systems and protecting models
-
Quantum computing threats and post-quantum cryptography
-
IoT and OT security convergence
-
5G security implications
-
Blockchain and Web3 security
-
Extended reality (AR/VR) security considerations
-
Autonomous systems and security
-
Emerging attack vectors and defence strategies
Key Takeaways:
-
Emerging technology security framework
-
AI/ML security checklist
-
Technology roadmap with security integration
Develop a future-ready security strategy that anticipates AI, quantum, and IoT threats — ensuring their organisations are not left exposed by tomorrow’s technologies. The pace of technological change is creating new security challenges faster than most organisations can respond. AI-powered attacks, quantum computing threats to existing cryptographic standards, and the explosive growth of IoT and OT devices are all reshaping the threat landscape at pace. This session gives CISOs a structured framework for understanding and responding to emerging technology risks, including practical guidance on post-quantum cryptography migration, AI/ML system security, and 5G security implications. Attendees leave with an emerging technology security framework, an AI/ML security checklist, and a technology roadmap with integrated security considerations that positions them as a strategic partner in their organisation’s digital transformation agenda.
12:30 - 13:30 | Lunch & Discussions
13:30 - 15:00 | SESSION 15: Security Metrics, Governance & Board Reporting
-
Defining meaningful security KPIs and KRIs
-
Security metrics frameworks (CIS, NIST)
-
Building executive dashboards and scorecards
-
Board-level reporting best practices
-
Security program maturity models
-
Benchmarking against industry peers
-
Demonstrating security ROI and value
-
Governance structures and committee design
-
Policy development and lifecycle management
Key Takeaways:
-
Security metrics catalogue
-
Board presentation templates
-
Governance framework documentation
Attendees master the art of security metrics and board communication, enabling you to demonstrate security value, secure investment, and drive governance excellence. One of the greatest challenges facing CISOs is translating complex technical risk into compelling business narratives that drive board-level decisions and budget allocation. This session provides a comprehensive toolkit for security measurement and governance, covering KPI and KRI definition, executive dashboard design, maturity model assessment, and industry benchmarking. Attendees leave with a security metrics catalogue, board presentation templates, and governance framework documentation that empowers them to demonstrate the value of their security programme with confidence, secure the resources they need, and build the governance structures that sustain long-term organisational security maturity.
15:00 – 15:15 | Afternoon Tea Break
15:15 – 16:15 | SESSION 16: Building a Security-First Culture & Change Management
-
Leading organizational security transformation
-
Change management strategies for security initiatives
-
Building and leading high-performance security teams
-
Cross-functional collaboration: IT, legal, compliance, business
-
Managing security vs. usability tensions
-
Innovation and security balance
-
Executive sponsorship and influence strategies
-
Personal resilience and avoiding CISO burnout
Key Takeaways:
-
Change management toolkit
-
Team development framework
-
Stakeholder engagement strategies
Attendees emerge as transformational security leaders, equipped to drive cultural change, build elite teams, and position security as a competitive business enabler. Technical excellence alone does not make a great CISO — the most effective security leaders are also skilled change agents, communicators, and team builders. This session addresses the human and organisational dimensions of security leadership, covering change management strategy, cross-functional collaboration, the management of security-versus-usability tensions, and the personal resilience required to sustain performance in one of the most demanding roles in the enterprise. Attendees leave with a change management toolkit, team development framework, and stakeholder engagement strategies that equip them to lead security transformation programmes with authority, credibility, and lasting organisational impact.
16:15 – 17:00 | Masterclass Final Session & Conclusions
-
Key takeaways review across all four days
-
Resource sharing and continued learning paths
-
Peer networking and contact exchange
-
Certificate of completion presentation
-
Closing remarks and feedback