What it is
A focused, full-day workshop for professionals responsible for governing, assuring or supporting organisational cybersecurity risk. Dr John McCarthy works with participants to examine how cyber risk should move through governance structures—from technical evidence and operational exposure to assurance, escalation, risk acceptance and executive decision.
Participants work with realistic governance papers, scenarios and decision exercises to identify weak accountability, test the quality of cyber reporting and improve the questions placed before boards and governance committees. This is not technical cybersecurity training. It is a practical governance workshop for professionals who must ensure that cyber risks are understood, challenged, escalated and governed effectively.
Who should attend
- Company secretaries, governance professionals and committee secretariats
- Enterprise risk, operational risk and GRC professionals
- Internal audit, assurance, legal and regulatory compliance teams
- Data protection, information governance and cyber assurance professionals
- Business continuity, organisational resilience and third-party risk leaders
- Board advisers, non-executive directors and public-sector governance representatives
Participants do not require technical cybersecurity expertise. The recommended group size is 6 people.
What the day includes
- The governance responsibility: What boards and governance functions should require from cybersecurity reporting
- Governance architecture mapping: Examining committees, accountabilities, escalation routes and delegated decision authority
- Reporting quality review: Identifying technical detail, ambiguity and missing business consequences in a sample cyber paper
- Translation exercise: Converting technical evidence into exposed outcomes, material consequences and governance relevance
- Risk-acceptance exercise: Testing authority, evidence and risk-appetite context before risk is accepted or deferred
- Assurance mapping: Identifying the evidence governance bodies need and where assurance is fragmented, duplicated or absent
- Committee simulation: Determining what should be challenged, escalated, recorded or decided in a realistic cyber scenario
- Governance improvement plan: Agreeing practical improvements participants can apply in their organisations
What you get
- A full-day workshop delivered personally by Dr John McCarthy
- Practical application of the Five-Layer Cyber Strategy Translation Framework
- Governance scenarios, reporting reviews and decision exercises
- A model for evaluating the quality of cyber papers
- A structured set of questions for boards and governance committees
- Practical principles for cyber-risk escalation and acceptance
- A participant workbook and certificate of completion
Outcomes
By the end of the day, participants will be able to:
- Recognise whether cyber reporting is genuinely decision-ready
- Challenge technical information without becoming cybersecurity specialists
- Connect cyber evidence to business outcomes and material consequences
- Identify unclear ownership, accountability and decision authority
- Determine when cyber risk requires escalation
- Test whether risk acceptance is properly authorised and evidenced
- Distinguish operational reporting from governance assurance
- Improve the quality of board and committee discussions and decisions
Right for you if
You work in governance, risk, audit, assurance, legal or compliance and are expected to provide effective oversight of cybersecurity without always receiving information in a usable form. It is particularly valuable where cyber papers are highly technical, committee responsibilities overlap, risk acceptance is poorly evidenced, assurance is fragmented, or governance professionals need greater confidence when questioning senior and technical leaders.