# Cybersecurity Leadership for Non-Technical Executives

> Understand cyber risk well enough to set appetite, ask the right questions, fund the right controls and lead through an incident.

- **Provider:** Afriskora Training Solutions
- **Category:** Data, AI & Digital Skills
- **Duration:** 3 days
- **Formats:** classroom (cities across Africa), live virtual (Zoom/Teams), in-house for teams
- **Certificate:** Afriskora Certificate of Completion, verifiable online
- **Booking:** request dates and a quote; invoice and EFT payment
- **Web page:** https://afriskora.co.za/courses/data-ai-digital/cybersecurity-leadership-for-non-technical-executives
- **Request dates:** https://afriskora.co.za/request-training?course=cybersecurity-leadership-for-non-technical-executives

## Overview

Ransomware, business email compromise and AI-enabled fraud now reach the boardroom as business crises, not IT problems. This course equips executives and directors without a technical background to govern cyber risk: reading security reports, challenging investment proposals, meeting regulatory duties under POPIA and sector rules, and making fast decisions when an incident hits. A live tabletop exercise rehearses the first 48 hours of a ransomware attack.

## Who should attend

- Executives, directors and board members
- Heads of risk, audit and compliance
- Senior managers in finance, operations and HR
- Public-sector accounting officers

## Learning outcomes

- Describe today's main cyber threats and how attacks unfold
- Set cyber risk appetite and oversee a security programme
- Evaluate security reports, metrics and investment requests
- Meet incident-reporting duties under POPIA and sector regulators
- Lead decision-making and communication during a cyber incident

## Course outline

### Module 1: The threat landscape

- Ransomware, phishing and business email compromise
- AI-generated deepfakes and fraud
- Third-party and supply-chain risk
- Lessons from recent African incidents

### Module 2: Governing cyber risk

- Frameworks: NIST CSF 2.0, ISO 27001 and King V
- Questions boards should ask
- Meaningful security metrics
- Cyber insurance and its limits

### Module 3: Resilience and incident leadership

- Business continuity and recovery priorities
- Regulatory notification and legal privilege
- Communicating with staff, clients and media
- Tabletop exercise: the first 48 hours
