Get your team fluent in the frameworks that run the business.
Cyber, GRC and AI governance certifications, taught by a working CISO. Live cohorts on confirmed dates, self-paced any time, in-house when it makes sense.
0+
Professionals trained
0
Accredited training ecosystems
0+
Cohorts completed
Why Cyber Academy
Trainers who run what they teach.
Cyber Academy is led by active GRC practitioners, including a working CISO. Trainer experience and course ownership are shown for the relevant programme. Three commitments guide our delivery:
- Practitioner-led delivery, with trainer experience shown for each confirmed programme.
- Published standard-course prices shown up front; tailored scopes are quoted.
- We map you to the path that fits, not the one that sells


Why Cyber Academy
Practitioner-led delivery, with trainer experience shown for each confirmed programme.
Current GRC priorities
What teams
are training on right now.
Six topics where regulators, auditors and boards are putting pressure today. Pick the one your audit is landing on; there's a certification path waiting.
NIS 2
Risk treatment, incident reporting and supply-chain duties under NIS 2, with scope and national implementation varying by jurisdiction.
See coursesDORA
Operational resilience for financial entities: third-party registers, ICT risk and threat-led testing, mapped where useful to ISO 27001.
See coursesAI Act
Risk classification, ISO 42001 management system, transparency duties for general-purpose AI. Practical, not abstract.
See coursesISO 27001
The reference standard for ISMS. Compare Foundation, Lead Implementer, Lead Auditor and ISO 27005 risk-management paths.
See coursesGDPR & privacy
Records of processing, DPIA, lawful basis, AI Act interaction, CDPSE preparation. What changed since 2018, what auditors check now.
See coursesISO 31000
Enterprise risk management. Foundation, Risk Manager, Lead Risk Manager. Complements ISO 27005 and EBIOS RM.
See courses
Lead trainer
Christophe Mazzola
Active CISO · 20+ certifications
10+
years in the field
Your trainers
A small team. One bar.
Cyber Academy was founded by Christophe Mazzola, an active CISO and author of Être en Cybersécurité. He continues to lead delivery with a small team, matching trainers to subjects they actively practise and naming the trainer when confirmed.
- Active practitioners
- Audit-ready exercises
- Real findings, not slides
1,000+ professionals certified.
From these companies and many more, in person and online, across Europe.
Testimonials
What clients say after they pass.
Field notes
Latest from the GRC trenches.

27 Jul 2026
The Rise of the Digital Compliance Officer: New Role for 2026
A new role is emerging across Europe: the Digital Compliance Officer. Here’s why the job is rising, what it actually involves, and how GRC leaders can prepare for it before 2026.

25 Jul 2026
ISO 27001: I Read the Standard Five Times. Then I Tried to Implement It.
What happens when the standard tells you what but never tells you how, and how to close that gap in 5 days. August 17 to 21, online.

24 Jul 2026
ISO 27001: I Nodded Through Six Months of Meetings Before I Understood a Word
What nobody tells you about starting out in ISO 27001, and how to stop faking it in 2 days. August 31 to September 1, online.
The GRC Brief
Five links, one short take. Monday at 8am.
What landed in regulation last week, the audit finding worth remembering, the template you can lift today. Written by our practitioners. Three-minute read. No fluff, no AI summaries.

Six honest answers,
before you commit.
Recognition, picking the right path, what happens if you fail, how to invoice, audit pressure, prices. The same questions every learner sends us. Read them, then book the cohort that fits.
Yes. We deliver official PECB and ISACA training tracks used internationally. The credential is issued by the relevant certification body, not by Cyber Academy.
Each course page lists prerequisites, target audience, and a 'when NOT to take it' section. If you're still unsure, book a free 20-minute discovery call: we'll match you to the path that fits your role, deadline and budget. We'd rather lose the sale than place you in the wrong cohort.
PECB and ISACA re-sit conditions vary by programme. We explain the applicable exam policy before purchase and provide targeted preparation when a re-sit is needed.
Yes. We invoice companies directly with VAT-compliant documents (or VAT-free for our Gran Canaria registration, depending on your tax rules). Bulk seats for teams of 4+ get a discount; we run dedicated in-house cohorts for groups of 6+. Just send us the requirement at [email protected].
We run live cohorts every month and can confirm a private session for your team within 2 to 3 weeks if dates are tight. For a hard deadline (DORA Article 28, NIS 2 transposition, etc.), tell us in the first email and we'll prioritise scheduling and content tailored to your audit scope.
Yes. Current standard live and self-paced prices are published in EUR where a course can be booked directly. In-house, multi-seat and custom scopes receive an itemised quote because format, dates and headcount vary.
Pick a path.
Book a date.
Confirmed cohorts on real calendars. Prices on the page. Exam and re-sit terms shown before purchase.
