Skip to main content
CISO life

Certified CISO by PECB

Certified CISO by PECB. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBExpert5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Professionals actively involved in managing information security programs
  • IT managers responsible for overseeing information security operations
  • Security professionals such as security architects, analysts, and auditors seeking to move into leadership roles
  • Professionals managing information security risk and compliance within their organizations
  • Experienced CISOs who want to refresh their knowledge and keep pace with current trends
  • Executives including CIOs, CEOs, and COOs who make decisions affecting information security strategy
  • Professionals pursuing executive-level roles within the information security field

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no background in information security will likely find the content moves too quickly without prior foundational study
  • Technical specialists seeking advanced hands-on security engineering or penetration testing skills will find the focus is on leadership and governance rather than technical exploitation
  • Those looking only for a brief awareness session rather than a structured five-day programme will find this course more in-depth than they need

What you'll be able to do

  • 1Explain the fundamental principles and concepts of information security in organizational contexts
  • 2Describe the roles, responsibilities, and ethical considerations associated with the CISO position
  • 3Design an effective information security program tailored to an organization's specific needs
  • 4Interpret and apply relevant information security frameworks, laws, and regulations
  • 5Communicate and implement security policies to achieve organizational compliance
  • 6Identify, analyze, evaluate, and treat information security risks using a systematic approach
  • 7Manage security controls, incident response, and change management processes
  • 8Build an information security awareness culture and use monitoring and measurement to drive continual improvement

Day by day

Day 1Fundamentals of Information Security and the Role of a CISO
  • Information Security Core Concepts

    This module establishes the foundational principles of information security, providing participants with the conceptual grounding needed to operate effectively at an executive level.

  • The CISO Role, Responsibilities, and Ethics

    Participants examine what the CISO position entails in practice, including its ethical dimensions, the challenges commonly faced, and how the role interacts with broader organizational leadership.

By end of day

  • Articulate the core principles of information security and link them to organizational risk
  • Describe the ethical responsibilities and practical challenges inherent to the CISO role
Day 2Information Security Compliance, Risk Management, and Security Architecture and Design
  • Compliance Program Development

    This module covers how to select, implement, and communicate an information security compliance program aligned with applicable laws, regulations, and frameworks.

  • Information Security Risk Management

    Participants learn a systematic approach to identifying, analyzing, evaluating, and treating information security risks within an organizational context.

  • Security Architecture and Design

    This module introduces the principles underpinning effective security architecture, including how design decisions affect the resilience and security posture of an organization.

By end of day

  • Build a compliance program that reflects relevant legal and regulatory obligations
  • Apply a structured risk management process to information security scenarios
  • Connect security architecture principles to organizational design decisions
Day 3Security Controls, Incident Management, and Change Management
  • Operational Security Controls

    Participants explore the selection and implementation of security controls across technical, administrative, and physical domains to protect organizational assets.

  • Incident Management

    This module addresses how to prepare for, detect, respond to, and recover from information security incidents in a structured and effective way.

  • Change Management in a Security Context

    Participants learn how to manage change processes so that security considerations are embedded into organizational changes rather than addressed as an afterthought.

By end of day

  • Select and apply security controls appropriate to specific organizational risk scenarios
  • Design an incident response process that covers detection through to post-incident review
  • Integrate security requirements into organizational change management workflows
Day 4Information Security Awareness, Monitoring, Measurement, and Continual Improvement
  • Building an Information Security Awareness Culture

    This module examines how to design and deliver awareness programs that foster security-conscious behavior across all levels of an organization.

  • Monitoring and Measurement

    Participants learn how to establish metrics and monitoring mechanisms that provide leadership with timely, meaningful data on the performance of the information security program.

  • Continual Improvement of the Security Program

    This module covers how to use measurement outcomes, audit findings, and incident learnings to drive ongoing enhancements to the information security program.

By end of day

  • Design an awareness program that influences security behavior across the organization
  • Define and track meaningful metrics that reflect information security program performance
  • Use performance data and lessons learned to structure a continual improvement cycle
Day 5Consolidation and Exam Preparation
  • Competency Domain Review

    This session revisits all five competency domains addressed during the week, helping participants consolidate understanding and identify areas for further study before assessment.

  • Exam Orientation and Q&A

    Participants receive an overview of the PECB Chief Information Security Officer exam structure and have the opportunity to resolve any outstanding questions before sitting the assessment.

By end of day

  • Identify personal knowledge gaps across the five CISO exam domains
  • Approach the certification exam with a clear understanding of its scope and expectations

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental concepts of information security
  • Domain 2: The role of CISO in an information security program
  • Domain 3: Selecting a security compliance program, risk management, and security architecture and design
  • Domain 4: Operational aspects of information security controls, incident management, and change management
  • Domain 5: Fostering an information security culture, monitoring, measuring, and improving an information security program
  • Developing security business and communication practices
  • Establishing information security objectives and metrics
  • Ensuring that the organization complies with relevant information security laws and regulations
  • Enforcing adherence to information security practices and building a security culture
  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

What is CISO?

PECB Chief Information Security Officer

Educational approach

  • The training course incorporates interactive elements, such as essay-type exercises and multiple-choice quizzes, some of which are scenario-based.
  • Participants are strongly encouraged to communicate and engage in discussions.
  • The quizzes are designed in a manner that closely resembles the format of the certification exam.

Building Digital Trust through Effective Information Security Leadership

digital trust

Buyers always ask

What is the difference between completing this training course and holding the PECB CISO certification?+

Attending and completing the five-day training course means you have engaged with all the instructional content. It does not grant the PECB Chief Information Security Officer certification. To earn the credential, you must separately sit and pass the PECB CISO exam and then apply to PECB for the credential by demonstrating that you meet the relevant professional experience requirements.

Cyber Academy delivers the training. The exam and certification processes are administered by PECB independently, and candidates should contact PECB directly for current requirements.

Is this course appropriate for someone who is already a practicing CISO?+

Yes. The course explicitly targets experienced CISOs who want to refresh and update their knowledge, in addition to professionals aspiring to reach that level. The curriculum covers contemporary compliance frameworks, risk management approaches, and governance practices that remain relevant even for seasoned practitioners.

Experienced professionals typically benefit most from Days 2 through 4, which address operational and strategic dimensions of the role in depth.

What competency domains does the PECB CISO exam cover?+

According to PECB, the exam spans five domains: fundamental concepts of information security; the role of the CISO in an information security program; selecting a security compliance program, risk management, and security architecture and design; operational aspects of security controls, incident management, and change management; and fostering an information security culture through monitoring, measuring, and improving the program.

For details on exam format, available languages, and sitting logistics, candidates should consult the official PECB List of Exams and Examination Rules and Policies.

Does the course cover specific regulatory frameworks or is it framework-agnostic?+

The programme teaches participants how to adopt applicable frameworks, laws, and regulations relevant to information security compliance. Rather than focusing exclusively on one standard, it equips participants to evaluate and apply the frameworks most relevant to their organizational and jurisdictional context.

This approach is particularly valuable for CISOs who operate in multi-regulatory environments or who advise organizations across different sectors.

How does the course address the human dimension of information security?+

Day 4 is dedicated in part to building an information security awareness culture. The course treats people as a critical element of the security program, covering how to design awareness initiatives, foster security-conscious behavior, and ensure that training reaches all organizational levels.

This reflects the CISO's responsibility not only for technical and governance controls but also for embedding security values throughout the organization.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.

Certified CISO by PECB · PECB · Cyber Academy