True story.
A guy I trained this spring had been Head of IT Security at a logistics company for four years. Firewalls, EDR, patching, incident tickets. His kingdom, and he ran it well. Then the company got hit by NIS 2, the insurers started asking questions, and the board decided they needed a CISO. They looked around the room and picked the obvious person. Him.
New title. Same desk. A calendar that suddenly filled up with things that had nothing to do with technology.
His first board meeting, he presented forty slides on vulnerability metrics. Patch coverage. Mean time to detect. CVE counts. He had worked on it for two weeks. Six minutes in, the CFO interrupted him with one question: "So are we OK or not?"
He did not have an answer. Not because he did not know his environment. He knew it better than anyone. Because the question was not technical. The question was about risk, expressed in consequences, owned by someone willing to sign their name under a judgment call. And nothing in his fifteen-year career had ever required him to do that.
He told me the walk back to his desk after that meeting was the longest of his professional life.
If you have ever carried a security title into a room full of executives and felt the ground move under you, you know exactly what I am describing. The details change. The feeling does not.
The promotion is real. The training never happens.
Here is the thing about becoming a CISO: almost nobody arrives through the front door.
You were the strongest security engineer, so they made you the manager. You were the manager who never dropped anything, so when the regulator, the insurer, or the client questionnaire demanded a "designated security officer," your name went in the box. One day you are configuring controls. The next day you are accountable for them, in front of a board, an auditor, and if things go really wrong, a regulator with your name in the file.
And between those two days, there is no training. No handover. Nobody sits you down and says: here is how you build a security program instead of a pile of tools. Here is how you talk to people who think in euros and quarters. Here is what an auditor actually opens first. Here is how you take a risk decision you can defend two years later.
The skills that got you the title are not the skills the job needs. That is not an insult. It is the design of the career path. The technical ladder ends where the executive job begins, and the field just assumes you will figure out the difference by improvising.
Most people do improvise. For years. Some of them get away with it. The ones who do not are the ones whose name is on the incident report.
Five parts of the job nobody teaches you
I have trained a lot of security leaders, and I run this job myself. The same five gaps show up every time, not because these people are not capable, but because nobody ever taught them the executive layer of the role.
Translating security into board language.
The board does not care about CVEs. They care about whether the company can take an order, make payroll, and stay out of the newspaper. "We have 3,400 unpatched vulnerabilities" means nothing to them. "If this system goes down, we stop shipping for three days and here is what that costs" gets you a budget. The gap between those two sentences is the single biggest reason security budgets die in committee, and no technical certification on earth teaches you to close it.
Running a program, not a collection of tools.
Most security functions are archaeology: layers of tools and habits deposited by whoever was in charge at the time. A program is different. It has a scope, objectives, a risk method, controls chosen for reasons, measurement, and a loop that improves it. Auditors can smell the difference in an hour. So can regulators. If you cannot draw your program on one page, you do not have one. You have an inventory.
Making risk decisions with your name on them.
"We accept this risk" is the sentence that separates the CISO from the security engineer. Someone has to decide which risks get treated, which get accepted, and be able to defend that decision when it ages badly. Most new CISOs either avoid the decision (everything is "high", nothing gets signed) or make it informally, with nothing written down. Both versions end the same way: badly, in front of someone taking notes.
Leading incidents instead of working them.
When the incident hits, your job is no longer the terminal. It is the room. Deciding when to notify the regulator, because NIS 2 and GDPR have clocks, and they are shorter than you think. Deciding what to tell customers, and when. Keeping the CEO from either panicking or, worse, going quiet. The technical response has a runbook. The leadership response is the part everyone improvises, and it is the part that ends up in the post-incident report.
Surviving scrutiny that never stops.
Audit season used to be a season. Now it is a climate: certification audits, surveillance audits, client audits, insurer questionnaires, DORA, NIS 2, and a board that reads about breaches at breakfast. If your evidence only exists in the two panicked weeks before each audit, you do not have assurance. You have theatre. The job is building the machine that produces evidence all year, so scrutiny becomes boring. The good kind of boring.
None of this is exotic. It is the actual job. It is just that nobody teaches it, because everyone assumes you learned it before you got the title. You did not. Neither did I. Nobody does.
What five days actually give you
Let me be straight about what this course is and is not.
You will not walk out with ten years of executive scar tissue. That only comes one way. What you walk out with is the structure that took me years of audits, incidents, and board meetings to assemble, laid out in order, so you stop improvising the biggest role of your career.
You will know what a complete security program looks like, end to end, so you can see exactly what your organisation is missing. You will have a risk approach you can defend: to a board, to an auditor, to yourself at 2 a.m. You will know how compliance, architecture, controls, incidents, and measurement connect into one system instead of five parallel anxieties. You will know what the people across the table (auditors, regulators, executives) actually look for, so you can prepare instead of perform. And you will have an executive-level credential that says none of this is self-declared.
That is the difference between holding the title and doing the job.
That is what the 5 days are for
August 10 to 14. Monday to Friday. Live online, in English. A cohort capped at six people, because at seven the conversation dies and the war stories stay in my notebook.
| Day | What you learn |
|---|---|
| Monday | What the CISO role actually is, and is not. How to structure an information security program from scratch, and how to take over one you inherited. Where the role sits between the board, IT, and the regulator, and how to hold that position. |
| Tuesday | How to build a compliance program that survives NIS 2, DORA, and GDPR instead of chasing them. How to assess what you already have without lying to yourself. How to run risk management the way executives and auditors need it: decisions, owners, evidence. How to design security architecture from risk, not from vendor brochures. |
| Wednesday | How to select and operate security controls you can justify. How to lead incident management: the decisions, the notifications, the room, not just the tickets. How to manage change without security becoming the department of no. |
| Thursday | How to build awareness people do not sleep through. How to measure your program so "are we OK?" gets an answer. How to build the assurance machine that makes audits boring. How to keep the whole thing improving instead of decaying. |
| Friday | PECB certification exam. Three hours. You have been building towards it all week. |
Every line starts with "how." The "what" is in every framework document you have ever skimmed. The "how" is what you are paying for.
Who teaches this
Me. Christophe. Active CISO, founder of Cyber Academy, PECB Gold Trainer.
I do not teach this role from a textbook, because I go back to it on Monday. When I explain how to present risk to a board, it is because I have watched a board’s eyes glaze over at my slides and had to learn what actually lands. When I explain incident leadership, it is because I have been the person deciding whether the regulator gets called tonight or tomorrow morning. When someone in the course says "my board just does not care," I do not give them the exam answer. I tell them what I would say in their next board meeting, because I have had to say it in mine.
Two hundred audits. A hundred implementations. Years in the chair this course is named after. You learn the job from someone who does the job.
The guarantee
Complete the course. Sit the exam. If you do not pass, we refund your training fee.
No fine print beyond finishing the programme and taking the exam. We call it Certified or Refunded, and we mean it. The methodology works, the pass rate proves it, and if you are investing a week of your time and your company’s money, you deserve a provider betting on the same outcome you are.
The details
- Course: PECB Chief Information Security Officer, Certified
- Dates: 10 to 14 August 2026
- Format: Live online. Interactive. Not recorded.
- Language: English
- Cohort size: 3 to 6 participants
- Exam: 3-hour PECB exam on Day 5, fees included
- CPD: 31 credits
- Free retake: Within 12 months
- Price: €2,499
- Guarantee: Certified or Refunded
Your move
If you have just been handed the title and you are improvising the job, this is where the improvising stops.
If you have been doing the work for years without the credential, this is the executive-level proof that you are not self-declared.
If your board meetings feel like presenting in a foreign language, this is where you learn the translation.
And if you know an incident or an audit is coming, and one always is, this is how you meet it with a program instead of a prayer.
Reserve your seat on the August cohort.
Questions? Email me directly. No sales team. No chatbot. Just me.
