PECB Certified Lead Cybersecurity Manager

The Lead Cybersecurity Manager training course enables participants to obtain the necessary competencies to effectively implement, manage, and continually improve a cybersecurity program.

Organizations nowadays are affected by the ever-evolving digital landscape and constantly face new threats and complex and sophisticated cyberattacks. There is a pressing need for skilled individuals capable of effectively managing and implementing robust cybersecurity programs to counter these threats. Our Lead Cybersecurity Manager training course has been developed to address this need.

By attending the PECB Certified Lead Cybersecurity Manager, participants will learn the fundamental cybersecurity concepts, strategies, methodologies, and techniques utilized to effectively establish and manage a cybersecurity program based on the guidance of international standards and industry best practices for cybersecurity. Additionally, this training course empowers participants to enhance their organization’s readiness and resilience against cyber threats. Participants will be well-prepared to support their organization’s ongoing cybersecurity efforts and make valuable contributions in today’s ever-evolving cybersecurity landscape. 

Course objectives:

Upon successfully completing the training course, participants will be able to:

  • Explain the fundamental concepts, strategies, methodologies, and techniques employed to implement and manage a cybersecurity program
  • Explain the relationship between ISO/IEC 27032, NIST Cybersecurity Framework, and other relevant standards and framework
  • Comprehend the operation of a cybersecurity program and its components
  • Support an organization in operating, maintaining, and continually improving their cybersecurity program

Audience:

This training course is intended for:

  • Managers and leaders involved in cybersecurity management
    Individuals tasked with the practical implementation of cybersecurity strategies and measures
  • IT and security professionals seeking to advance their careers and contribute more effectively to cybersecurity efforts
  • Professionals responsible for managing cybersecurity risk and compliance within organizations
  • C-suite executives playing a crucial role in decision-making processes related to cybersecurity

Prerequisites:

To fully benefit from this training course, participants should have a fundamental understanding of cybersecurity concepts and management.
 
 

Day 1 – Introduction to cybersecurity and initiation of a cybersecurity program implementation

The course begins with an overview of the training objectives and structure, ensuring participants understand the learning journey and certification pathway.

Participants are introduced to relevant standards and regulatory frameworks that influence cybersecurity governance and compliance. This provides context for how cybersecurity programmes align with legal, regulatory and industry expectations.

The day continues with fundamental cybersecurity concepts, establishing a shared understanding of terminology, threat landscapes and defensive strategies.

Participants explore what constitutes a cybersecurity program, including its core components, objectives and integration into organisational strategy.

The organisation and its context are analysed to understand how internal and external factors influence cybersecurity requirements.

The session concludes with a focus on cybersecurity governance, including leadership involvement, strategic oversight and accountability structures required to build a resilient cybersecurity posture.

Day 2 – Cybersecurity roles and responsibilities, risk management and attack mechanisms

This day focuses on defining cybersecurity roles and responsibilities within an organisation, clarifying accountability and operational ownership across functions.

Participants examine asset management principles, including identifying, classifying and protecting critical information assets.

Risk management is explored in depth, covering identification, analysis and prioritisation of cyber risks in alignment with organisational objectives.

The day also addresses common attack mechanisms, helping participants understand threat actors, techniques and vulnerabilities in order to better design defensive and preventive strategies.

Day 3 – Cybersecurity controls, communication, awareness and training

Participants explore the design and implementation of cybersecurity controls that mitigate identified risks and strengthen resilience.

The importance of structured cybersecurity communication is emphasised, including reporting lines, escalation procedures and stakeholder engagement.

Awareness and training programmes are examined as essential elements of organisational cybersecurity maturity, ensuring employees understand their responsibilities and actively contribute to risk reduction.

Day 4 – Cybersecurity incident management, monitoring and continual improvement

This day begins with ICT readiness in business continuity, exploring how cybersecurity integrates into resilience planning and operational continuity strategies.

Participants examine cybersecurity incident management processes, including detection, response, containment and recovery.

Testing practices in cybersecurity are reviewed to ensure preparedness and validate control effectiveness.

The course also covers measuring and reporting cybersecurity performance through metrics and key performance indicators.

Finally, continual improvement mechanisms are discussed, emphasising monitoring, evaluation and structured enhancement of cybersecurity programmes.

The training course concludes with a formal wrap-up of the learning objectives and key takeaways.

Day 5 – Certification Exam

The final day is dedicated to the certification examination. Participants complete the exam in accordance with the certification body’s procedures.

After successfully completing the exam, you can apply for the credentials shown on the table below. You will receive a certificate once you comply with all the requirements related to the selected credential. For more information about the  certifications and the PECB certification process, please refer to the Certification Rules and Policies.

PECB Certified Cybersecurity Manager.png

Exam

The exam is will take place at the end of the course on onsite classroom courses

For Virtual courses we will send out a voucher that gives you access to an online exam. This can be booked and taken home monitored by a proctor via camera. More information about the exam rules will be send from PECB.

Exam details:

Test details:

  • The exam duration is three (3) hours. Non-native speakers receive an additional half an hour.
  • The exam contains essay type questions. 

As the exam is an Multiple Choice, candidates are authorized to use:

  • Training course materials (accessed through the PECB Exams app and/or printed)
  • Any personal notes taken during the training course (accessed through the PECB Exams app and/or printed) 
  • A hard copy dictionary


Exam-preparation-guides

Examination rules and policies

RECEIVE YOUR EXAM RESULTS

Results will be communicated by email in a period of 6 to 8 weeks, after taking the exam. The results will not include the exact grade of the candidate, only a mention of pass or fail.

Candidates who successfully complete the examination will be able to apply for a certified scheme which is explained in the course description.

In the case of a failure, the results will be accompanied with the list of domains in which the candidate had failed to provide guidance for exams’ retake preparation.

Candidates, who disagree with the exam results, may file a complaint by writing to examination@pecb.com or through PECB ticketing system.

EXAM RETAKE POLICY

There is no limit on the number of times a candidate may retake an exam. However, there are some limitations in terms of allowed time-frame in between exam retakes, such as:

  • Students, who have completed the full training but failed the written exam, are eligible to retake the exam once for free within a 12 month period from the initial date of the exam.
  • If a candidate does not pass the exam on the second attempt, he/she must wait 3 months (from the initial date of the exam) for the next attempt (2nd retake). Retake fee applies.
  • If a candidate does not pass the exam on the third attempt, he/she must wait 6 months (from the initial date of the exam) for the next attempt (3rd retake). Retake fee applies.

After the fourth attempt, a waiting period of 12 months from the last session date is required, in order for candidate to sit again for the same exam. Regular fee applies.

For the candidates that fail the exam in the 2nd retake, PECB recommends to attend an official training in order to be better prepared for the exam.

To arrange exam retakes (date, time, place, costs), the candidate needs to contact Glasspaper.

Practical information

Duration: 5 days
Price: 27 900
Language: English
Format: Open course and corporate training
Credits: An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to participants who have attended the training course.

FAQ

Hva lærer jeg på dette kurset?
Du lærer hvordan du leder og styrer cybersecurity-strategier, fra rammeverk og risikostyring til governance, respons og kontinuerlig forbedring.

Hva kreves for å delta?
Det er ingen formelle krav, men det er en fordel med erfaring eller grunnleggende kunnskap om cybersecurity, IT-styring eller risikostyring.

Hvordan gjennomføres eksamen?
Eksamen gjennomføres enten fysisk på kursstedet eller som online prøve med voucher og online eksamensvakt.

Hva skjer hvis jeg ikke består første eksamen?
Du får som regel ett nytt eksamensforsøk som gjennomføres online.

Får jeg ekstra tid på eksamen?
Ja, ekstra tid kan gis dersom engelsk ikke er ditt morsmål, i tråd med sertifiseringsreglene.

Hvilken sertifisering får jeg?
Etter godkjent eksamen oppnår du PECB Certified Provisional Cybersecurity Manager sertifiseringen. For å få full sertifisering kan det også stilles krav til dokumentert arbeidserfaring innen cybersecurity. Sjekk tabellen under sertifisering for mer informasjon.

Får jeg kursmateriell eller standarder?
Du får tilgang til kursmateriell og rammeverksreferanser som brukes under kurset og eksamen.

Er dette kurset relevant for ledere?
Ja, kurset er spesielt relevant for ledere, cybersecurity-ansvarlige, risk- og compliance-roller, IT-executives og rådgivere.

Kan jeg ta dette kurset som e-læring eller selvstudium?
Nei, det er ikke mulig å ta dette kurset som e-læring, men mulig med selvstudie. Send en mail til prosjekt@glassper.no for mer informasjon og bestilling.

Other relevant courses

2. March
5 days
Classroom Virtual Guaranteed to run
23. March
5 days
Classroom Virtual
13. April
5 days
Classroom Virtual
23. March
5 days
Classroom Virtual