Professional workshop · City of London

Cybersecurity Governance Professionals WorkshopAccountability, Assurance and Decisions

A focused, practical day for professionals who must ensure that cyber risks are understood, challenged, escalated and governed effectively—without needing to become cybersecurity specialists.

DateThursday 19 November 2026
Time09:30–16:30
Investment£995 + VAT per delegate
AvailabilityLimited to 15 places

The workshop

Turn cyber evidence into sound governance decisions.

Cybersecurity governance often breaks down not because information is absent, but because technical reporting does not make the exposed business outcome, material consequence, accountable owner or decision required sufficiently clear.

Led personally by Dr John McCarthy, this full-day workshop examines how cyber risk should move through governance structures—from technical evidence and operational exposure to assurance, escalation, risk acceptance and executive decision.

Participants work with realistic governance papers, scenarios and decision exercises. The emphasis is practical: improving the questions, challenge and judgement applied in boards, committees and assurance functions.

Who should attend

For professionals carrying governance responsibility.

Governance

Company secretaries, committee secretariats, board advisers and public-sector governance representatives.

Risk and GRC

Enterprise risk, operational risk, GRC and third-party risk professionals.

Audit and assurance

Internal audit, cyber assurance and professionals responsible for evaluating evidence.

Legal and compliance

Legal, regulatory compliance, data protection and information governance teams.

Resilience

Business continuity, organisational resilience and critical-service leaders.

Board leadership

Non-executive directors and senior leaders seeking stronger cyber oversight and challenge.

What the day includes

Realistic exercises. Explicit decisions.

01

The governance responsibility

What boards and governance functions should require from cybersecurity reporting.

02

Governance architecture mapping

Committees, accountabilities, escalation routes and delegated decision authority.

03

Reporting quality review

Identify technical detail, ambiguity and missing business consequences in a sample cyber paper.

04

Translation exercise

Convert technical evidence into exposed outcomes, material consequences and governance relevance.

05

Risk-acceptance exercise

Test authority, evidence and risk-appetite context before risk is accepted or deferred.

06

Assurance mapping

Identify the evidence governance bodies need and where assurance is fragmented or absent.

07

Committee simulation

Determine what should be challenged, escalated, recorded or decided.

08

Governance improvement plan

Agree practical improvements to apply in your organisation.

Outcomes

Leave better equipped to challenge, assure and decide.

By the end of the day, participants will be able to:

Recognise whether cyber reporting is genuinely decision-ready.
Challenge technical information without becoming cybersecurity specialists.
Connect cyber evidence to business outcomes and material consequences.
Identify unclear ownership, accountability and decision authority.
Determine when cyber risk requires escalation.
Test whether risk acceptance is properly authorised and evidenced.
Distinguish operational reporting from governance assurance.
Improve the quality of board and committee discussions and decisions.

Deep expertise, expressed in governance terms.

Dr John McCarthy is a Chartered Cyber Security Professional and PhD-qualified academic specialising in cybersecurity governance, resilience and critical national infrastructure. Over more than two decades, he has advised organisations across regulated and critical sectors, helping leadership teams align technical evidence, operational exposure and executive accountability.

His work combines cyber assurance, risk management and governance frameworks—including the NCSC Cyber Assessment Framework, ISO 27001 and NIS2—with a practical understanding of how boards and committees reach defensible decisions.

Every workshop is delivered personally by Dr McCarthy. Participants receive a workbook, practical governance tools and a certificate of completion.

Coat of arms of the Worshipful Company of Information Technologists

The venue

Information Technologists’
Hall

39a Bartholomew Close
London EC1A 7JN

Home of the Worshipful Company of Information Technologists, the Hall is set among the historic streets of the City of London. It is centrally located near Barbican, St Paul’s and Farringdon stations and provides a professional setting for a focused day of learning and discussion.

View WCIT Hall information and access details →

Book your place

Complete the delegate details below. You will then continue to secure card payment through Stripe.

Oxford Integrated Systems Limited will use the information supplied to administer the booking and event. Please read our privacy notice.

Secure card payment is processed by Stripe. Your booking is confirmed when payment has completed and confirmation has been issued.