Group Purchasing
Group Purchasing
BETA

LDR539: Enterprise Risk Management for CISOs

LDR539Cybersecurity Leadership
  • 3 Days (Instructor-Led)
  • 18 Hours (Self-Paced)
Course authored by:
Ian Frist
Ian Frist
LDR539
Course authored by:
Ian Frist
Ian Frist
  • 18 CPEs

    Apply your credits to renew your certifications

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 13 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Build the leadership skills to align cybersecurity with enterprise risk strategy, translate data into decisions, and drive consistent action across any organization.

Course Overview

Get Notified About LDR539 Training Events

Want to be the first to know when LDR539 beta registration opens? Complete the interest form to receive updates on beta registration, full release date, OnDemand availability, and more. Be among the first to learn how to align cyber risk with enterprise strategy and become the decision enabler your organization needs.

Interest Form

What You'll Learn

  • Identify why misaligned cyber risk programs fail to influence leadership
  • Read ERM maturity from observed behavior across ad hoc, fragmented, and institutionalized environments
  • Interpret risk appetite and tolerance signals and translate them into decision boundaries
  • Turn existing cyber risk data into decision-relevant information
  • Define KRIs as action triggers with predefined responses
  • Apply alignment, context, and predefined actions as an integrated system
  • Translate risk information into action that supports leadership decisions

Business Takeaways

  • Connect your cyber risk program to how the business makes decisions
  • Read the ERM environment you are in and adapt your approach accordingly
  • Interpret risk appetite and tolerance signals, even when nothing is formally documented
  • Turn existing data into information leadership can compare and act on
  • Define KRIs with predefined responses so decisions are consistent, not reactive
  • Treat accepted and emerging risk as active inputs, not paperwork
  • Leave with an operating model you can apply on day one

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR539: Enterprise Risk Management for CISOs.

Section 1Building Alignment: Don’t be the Sushi at the Italian Restaurant

This section establishes the foundation by reframing cyber risk leadership as decision enablement. Students examine how misalignment with enterprise risk management undermines decisions, learn how ERM operates across maturity levels, interpret risk appetite and tolerance, and begin translating cyber risk into enterprise context.

Topics covered

  • Misalignment consequences between cyber risk and enterprise strategy
  • How ERM operates across ad hoc, implied, and institutionalized environments
  • Risk appetite as leadership intent; risk tolerance as decision boundaries
  • Interpreting appetite and tolerance signals, documented or not
  • Translating cyber risk into decision-relevant enterprise context

Labs

  • Module 1 lab — Misalignment and Decision Impact
  • Module 2 lab — Integrating Within an Existing Organization
  • Module 3 lab — ERM Posture Identification
  • Module 4 lab — Appetite and Tolerance Signals

Section 2Metrics Matter: Operationalizing Risk Management

This section moves from understanding to action. Students learn how frameworks support rather than define risk leadership, clarify the cyber risk leader’s role as a decision enabler, define KRIs as action triggers, and select metrics that drive leadership decisions rather than just reporting status.

Topics covered

  • Risk frameworks as tools, not destinations
  • The cyber risk leader as decision enabler, not domain owner
  • KRIs as action triggers with predefined responses
  • Selecting metrics that drive leadership decisions
  • How predefined actions enable consistent, risk-informed decisions

Labs

  • Module 5 lab — framework application in context
  • Module 6 lab — role clarity and contextualization
  • Module 7 lab — KRIs and decision triggers
  • Module 8 lab — selecting the right metrics

Section 3Sustainment: Getting There Was Tough, Staying There Is Tougher

This section focuses on operating and sustaining cyber risk management over time. Students manage compliance risk, govern accepted risk as a portfolio, handle emerging risk without rotting registers, synthesize the full course approach, and operate across different ERM environments.

Topics covered

  • Measuring and monitoring compliance risk
  • Accepted risk as a portfolio of exposure, not isolated exceptions
  • Emerging risk lifecycle management without the rotting register
  • Pulling the full course approach together
  • Adapting behavior across ERM environments without abandoning principles

Labs

  • Module 9 lab — measuring and monitoring compliance risk
  • Module 10 lab — managing accepted risk as a portfolio
  • Module 11 lab — emerging risk without the rotting register
  • Module 12 lab — pulling it together
  • Module 13 lab — operating across different ERM environments (capstone)

Things You Need To Know

Relevant Job Roles

Cyber Risk Officer

Cybersecurity Leadership

Lead cybersecurity risk strategy at the highest level.

Explore learning path

Senior Security Leader

Cybersecurity Leadership

Daily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.

Explore learning path

We're updating our course schedule - please check back later.

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources