Governance
Company secretaries, committee secretariats, board advisers and public-sector governance representatives.
Professional workshop · City of London
A focused, practical day for professionals who must ensure that cyber risks are understood, challenged, escalated and governed effectively—without needing to become cybersecurity specialists.
The workshop
Cybersecurity governance often breaks down not because information is absent, but because technical reporting does not make the exposed business outcome, material consequence, accountable owner or decision required sufficiently clear.
Led personally by Dr John McCarthy, this full-day workshop examines how cyber risk should move through governance structures—from technical evidence and operational exposure to assurance, escalation, risk acceptance and executive decision.
Participants work with realistic governance papers, scenarios and decision exercises. The emphasis is practical: improving the questions, challenge and judgement applied in boards, committees and assurance functions.
Who should attend
Company secretaries, committee secretariats, board advisers and public-sector governance representatives.
Enterprise risk, operational risk, GRC and third-party risk professionals.
Internal audit, cyber assurance and professionals responsible for evaluating evidence.
Legal, regulatory compliance, data protection and information governance teams.
Business continuity, organisational resilience and critical-service leaders.
Non-executive directors and senior leaders seeking stronger cyber oversight and challenge.
What the day includes
What boards and governance functions should require from cybersecurity reporting.
Committees, accountabilities, escalation routes and delegated decision authority.
Identify technical detail, ambiguity and missing business consequences in a sample cyber paper.
Convert technical evidence into exposed outcomes, material consequences and governance relevance.
Test authority, evidence and risk-appetite context before risk is accepted or deferred.
Identify the evidence governance bodies need and where assurance is fragmented or absent.
Determine what should be challenged, escalated, recorded or decided.
Agree practical improvements to apply in your organisation.
Outcomes
By the end of the day, participants will be able to:
Dr John McCarthy is a Chartered Cyber Security Professional and PhD-qualified academic specialising in cybersecurity governance, resilience and critical national infrastructure. Over more than two decades, he has advised organisations across regulated and critical sectors, helping leadership teams align technical evidence, operational exposure and executive accountability.
His work combines cyber assurance, risk management and governance frameworks—including the NCSC Cyber Assessment Framework, ISO 27001 and NIS2—with a practical understanding of how boards and committees reach defensible decisions.
Every workshop is delivered personally by Dr McCarthy. Participants receive a workbook, practical governance tools and a certificate of completion.

The venue
Home of the Worshipful Company of Information Technologists, the Hall is set among the historic streets of the City of London. It is centrally located near Barbican, St Paul’s and Farringdon stations and provides a professional setting for a focused day of learning and discussion.
View WCIT Hall information and access details →