Group Purchasing
Group Purchasing
BETA

LDR539: Enterprise Risk Management for CISOs

LDR539Cybersecurity Leadership
  • 3 Days (Instructor-Led)
  • 18 Hours
Course authored by:
Ian Frist
Ian Frist
LDR539
Course authored by:
Ian Frist
Ian Frist
  • 18 CPEs

    Apply your credits to renew your certifications

  • Virtual

    Attend a live, instructor-led class remotely from anywhere

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 13 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Build the leadership skills to align cybersecurity with enterprise risk strategy, translate data into decisions, and drive consistent action across any organization.

Course Overview

Get Notified About LDR539 Training Events

Want to be the first to know when LDR539 beta registration opens? Complete the interest form to receive updates on beta registration, full release date, OnDemand availability, and more. Be among the first to learn how to align cyber risk with enterprise strategy and become the decision enabler your organization needs.

Interest Form

LDR539 teaches cybersecurity leaders how to apply cyber risk management by connecting it to the enterprise risk management (ERM) program, enabling consistent, risk-informed decision-making. The focus is not on tools or frameworks but on how cyber risk leaders operate in practice to bring context, clarity, and disciplined action to leadership decisions.

The course follows the natural progression of a leader's journey through risk management. Students start by examining the consequences of misalignment and learning how ERM operates across a range of organizations. From there, they build core risk leadership capabilities: interpreting risk appetite and tolerance, contextualizing existing risk signals, defining Key Risk Indicators (KRIs), and establishing predefined actions with leadership.

Throughout the course, students are positioned as decision enablers, not metric owners or domain experts. They learn to work with existing expertise, operate across different ERM maturity environments, and maintain discipline when organizational structures are imperfect. The course concludes by bringing these elements together into a transferable operating model.

Author Statement

Ian Frist draws on real-world experience across industries to show students how to apply those lessons directly to their own organizations. Cyber risk management is not about memorizing frameworks. It is about giving leaders what they need to make better decisions. This course is grounded in how risk management works in the enterprises students already operate in.

Ian challenges students to move past the echo chambers that shape most cyber risk programs and shows how to integrate cyber risk into larger ERM portfolios in a way that sticks. Students come away understanding why aligning their programs to business strategy matters and with practical methods to do it.

The goal is after completing this course, students are in step with their business leaders, able to speak in terms of appetite and tolerance, and finding it easier to secure investment because their program is aligned to how the business thinks about risk.

What You'll Learn

  • Identify why misaligned cyber risk programs fail to influence leadership
  • Read ERM maturity from observed behavior across ad hoc, fragmented, and institutionalized environments
  • Interpret risk appetite and tolerance signals and translate them into decision boundaries
  • Turn existing cyber risk data into decision-relevant information
  • Define KRIs as action triggers with predefined responses
  • Apply alignment, context, and predefined actions as an integrated system
  • Translate risk information into action that supports leadership decisions

Business Takeaways

  • Connect your cyber risk program to how the business makes decisions
  • Read the ERM environment you are in and adapt your approach accordingly
  • Interpret risk appetite and tolerance signals, even when nothing is formally documented
  • Turn existing data into information leadership can compare and act on
  • Define KRIs with predefined responses so decisions are consistent, not reactive
  • Treat accepted and emerging risk as active inputs, not paperwork
  • Leave with an operating model you can apply on day one

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR539: Enterprise Risk Management for CISOs.

Section 1Building Alignment: Don’t be the Sushi at the Italian Restaurant

This section establishes the foundation by reframing cyber risk leadership as decision enablement. Students examine how misalignment with enterprise risk management undermines decisions, learn how ERM operates across maturity levels, interpret risk appetite and tolerance, and begin translating cyber risk into enterprise context.

Topics covered

  • Misalignment consequences between cyber risk and enterprise strategy
  • How ERM operates across ad hoc, implied, and institutionalized environments
  • Risk appetite as leadership intent; risk tolerance as decision boundaries
  • Interpreting appetite and tolerance signals, documented or not
  • Translating cyber risk into decision-relevant enterprise context

Labs

  • Module 1 lab — Misalignment and Decision Impact
  • Module 2 lab — Integrating Within an Existing Organization
  • Module 3 lab — ERM Posture Identification
  • Module 4 lab — Appetite and Tolerance Signals

Overview

Day 1 follows the natural progression of a leader entering a new organization. The starting problem is direct: cybersecurity risk programs that generate extensive data yet fail to influence leadership because they are not aligned with enterprise strategy.

Students learn to recognize ERM as ad hoc, implied, or institutionalized based on observable behaviors, and how to adapt their approach to the environment they inherit.

Risk appetite and tolerance are introduced through scenarios across finance, venture-backed startups, and manufacturing. Appetite may be documented, implied, or entirely unwritten. Finding it is the job.

Day 1 closes with translating cyber risk into enterprise context so existing data becomes decision relevant.

Section 2Metrics Matter: Operationalizing Risk Management

This section moves from understanding to action. Students learn how frameworks support rather than define risk leadership, clarify the cyber risk leader’s role as a decision enabler, define KRIs as action triggers, and select metrics that drive leadership decisions rather than just reporting status.

Topics covered

  • Risk frameworks as tools, not destinations
  • The cyber risk leader as decision enabler, not domain owner
  • KRIs as action triggers with predefined responses
  • Selecting metrics that drive leadership decisions
  • How predefined actions enable consistent, risk-informed decisions

Labs

  • Module 5 lab — framework application in context
  • Module 6 lab — role clarity and contextualization
  • Module 7 lab — KRIs and decision triggers
  • Module 8 lab — selecting the right metrics

Overview

Day 2 shifts from foundations to operationalization. Frameworks are useful, but they are tools that support risk leadership, not define it. The cyber risk leader's role is clarified here: bring context to existing metrics, not redesign measurement systems.

Students then move into the actionable core. They define KRIs with predefined actions so that when risk approaches or breaches tolerance, the response is consistent and pre-agreed rather than reactive.

Day 2 closes with selecting the right metrics, ensuring leadership gets a coherent, decision-relevant view of cyber risk rather than a collection of disconnected signals.

Section 3Sustainment: Getting There Was Tough, Staying There Is Tougher

This section focuses on operating and sustaining cyber risk management over time. Students manage compliance risk, govern accepted risk as a portfolio, handle emerging risk without rotting registers, synthesize the full course approach, and operate across different ERM environments.

Topics covered

  • Measuring and monitoring compliance risk
  • Accepted risk as a portfolio of exposure, not isolated exceptions
  • Emerging risk lifecycle management without the rotting register
  • Pulling the full course approach together
  • Adapting behavior across ERM environments without abandoning principles

Labs

  • Module 9 lab — measuring and monitoring compliance risk
  • Module 10 lab — managing accepted risk as a portfolio
  • Module 11 lab — emerging risk without the rotting register
  • Module 12 lab — pulling it together
  • Module 13 lab — operating across different ERM environments (capstone)

Overview

Day 3 is where building the system gives way to sustaining it. Students learn to measure and monitor compliance risk, manage accepted risk as an active portfolio rather than a collection of one-time exceptions, and handle emerging risk through lifecycle management rather than accumulation on a register that loses credibility over time.

Day 3 also synthesizes the full course approach. Students apply alignment, context, normalization, and predefined actions as an integrated system. The final module examines how behavior must adapt based on the organization's ERM posture: when to take a directive stance, when influence and relationship-building matter most, and when tight alignment with established governance is required.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Processor: CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class or Apple Mac systems using the M1/M2/M3 processor.
  • Memory: 8GB of RAM or more is required.
  • Free Disk Space: 20GB of free storage space or more is required.
  • Wireless 802.11 capability: There is no wired Internet access in the classroom.
  • USB-A read / write capability: This is recommended in case students need to exchange large files during class. At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.

Mandatory Host Configuration and Software Requirements

  • Latest version of Windows 10, Windows 11, or macOS 10.15.x or newer. Fully patch your host operating system prior to the course to ensure you have the right drivers and patches installed.
  • Local Administrator Rights: Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • Endpoint Protection Software: You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Operating System Updates: Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux Workstations: Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials.
  • Microsoft Office: Microsoft Office (any currently supported version) installed on your host. Note that you can download Office Trial Software online (free for 30 days). Open Office is NOT supported for this course.
  • Web Browser: A web browser you feel comfortable using during class. Microsoft Edge, Google Chrome, or Mozilla Firefox will all be supported in class. If you choose to use a different browser on your host, you are solely responsible for configuring it to work with the course materials.

If you have additional questions about the laptop specifications, please contact customer service.

LDR539 is designed for cybersecurity leaders who are responsible for, or moving into, cyber risk management at the enterprise level. This includes CISOs, deputy CISOs, and senior security leaders who need to connect their risk programs to how the business makes decisions.

It is also well-suited for aspiring cyber risk leaders who want to move beyond framework compliance and metric reporting into a role that directly enables leadership decisions.

No formal prerequisites are required. Students should come with some experience in cybersecurity and an interest in how risk management operates at the organizational level.

  • Printed and electronic courseware

There are no formal prerequisites. This course is best suited for cybersecurity leaders and senior risk professionals who already operate in or near enterprise risk management. Students should have experience in a security leadership, GRC, or cyber risk role and a working familiarity with how their organization makes risk-related decisions.

This is not an entry-level course. Students without prior exposure to security leadership or organizational risk management will find the content difficult to apply. It is most valuable for those in mid-to-large organizations where alignment between cybersecurity and enterprise risk is an active challenge.

LDR539 is part of the SANS Cybersecurity Leadership curriculum, which develops security leaders who can operate effectively at the intersection of technical expertise and business strategy. The curriculum spans security management, governance, risk, and executive leadership, building the skills needed to lead programs, influence decisions, and drive outcomes at the organizational level.

Enterprise risk management (ERM) is the discipline through which organizations identify, assess, and manage risk in a way that supports business strategy and leadership decision-making. For cybersecurity leaders, ERM is the operating environment where cyber risk either gets heard or gets ignored. When cyber risk is not aligned to ERM, programs can generate extensive data and still fail to influence a single leadership decision. When it is aligned, cyber risk becomes a direct input into how the business sets priorities, allocates resources, and takes action. 

Senior security leaders are increasingly expected to do more than manage technical risk. They are expected to connect it to business outcomes. LDR539 gives you a transferable operating model for doing exactly that: interpreting risk appetite, contextualizing existing data, and enabling leadership decisions across any organization regardless of ERM maturity. Whether you are a GRC leader, a deputy CISO, or stepping into your first CISO role, this course builds the judgment and discipline that separates leaders who report on risk from those who shape how the business responds to it.

Beta courses are part of the SANS course development process, bringing new training to market in collaboration with the practitioner community. LDR539 delivers fully developed content, complete labs, and expert instruction at 25% off full course cost. 

  • Work directly with the author Ian Frist in a smaller cohort before general release
  • Engage with content built from real-world ERM experience, not frameworks
  • Shape the final course through direct feedback to the author
  • Access the course at 25% off full course cost

Relevant Job Roles

Cyber Risk Officer

Cybersecurity Leadership

Lead cybersecurity risk strategy at the highest level.

Explore learning path

Senior Security Leader

Cybersecurity Leadership

Daily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.

Explore learning path

Course Schedule and Pricing

Looking for Group Purchasing Options?Contact Us

We couldn't find a match for your selection

Please try a different combination of filters and search again.

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources