True story.
A woman I trained earlier this year told me how she ended up on her company's ISO 27001 project. She didn't volunteer. Someone left, there was a gap, and her manager pointed at her in a corridor and said "you'll handle the security certification now."
Her background was project coordination. She had never opened an ISO standard in her life. In her first meeting, the external consultant spoke for forty minutes about the Statement of Applicability, Annex A controls, and the risk treatment plan. She wrote all three phrases in her notebook, spelled phonetically, and Googled every one of them on the train home.
Then she did that for six months. Every meeting. New vocabulary, quiet Googling afterwards, nodding at the right moments so nobody in the room would realise she had no idea what was actually being decided.
She wasn't bad at her job. She was good at her job. She had just been dropped into a language nobody offered to teach her.
If you've been anywhere near ISO 27001 without a security background, some version of this probably sounds familiar. Maybe you're in compliance. Maybe you're in IT and got volunteered. Maybe you're a consultant who needs to sound credible in front of a client on Monday. The details change. The feeling doesn't: everyone in the room seems fluent in something you were never taught, and admitting it out loud feels more dangerous than faking it.
This article is about that gap. Not the implementation gap. The one that comes before it. The vocabulary gap. And how to close it.
Nobody lets you learn it before you need it
Here's the thing about ISO 27001. You don't get to study it before it lands on your desk.
You get assigned to a project. Or asked a question in a meeting. Or your company decides to get certified and puts your name next to "responsible." And suddenly you're expected to have opinions about things you've never heard of. Nobody sits you down first. Nobody says "before we start, here's what an ISMS actually is, here's how the standard is built, here's what these words mean and why they matter." They just start using the words.
And there are a lot of words. Confidentiality, integrity, availability. Risk assessment, risk treatment, risk acceptance. Annex A, Statement of Applicability, control objectives, nonconformity, corrective action, continual improvement. Thirty pages of standard. Ninety-three controls. A whole working vocabulary that everyone around you seems to have absorbed by osmosis.
You didn't absorb it by osmosis. Nobody does. The people who sound fluent learned it somewhere, on purpose. They just learned it before you walked into the room.
That is the entire problem. It's not that ISO 27001 is impossibly hard. It's that the field expects you to speak the language before anyone teaches it to you.
Five things people nod at without understanding
I've trained a lot of people at the start of this journey. The same concepts trip everyone up, not because they're slow, but because nobody ever explained them properly. Here are five things people fake understanding, and shouldn't have to.
"An ISMS." Most people think it's a piece of software. Or a single document. Or that SharePoint folder. It isn't. An Information Security Management System is the whole system you use to manage security: the policies, the processes, the decisions, the people, and the way they all connect. Once that clicks, half the standard stops being mysterious. Until it clicks, none of it makes sense.
"Risk." This is the big one. People use "risk" to mean four different things in the same sentence. A threat is not a vulnerability. A vulnerability is not a risk. And "we don't have multi-factor authentication" is not a risk either, it's a missing control. A risk is a scenario: something that could happen, why it could happen, and what it would cost you. If you can't tell those apart, every risk conversation you sit in will feel like fog. Once you can, it's suddenly readable.
"The Statement of Applicability." People nod at this phrase for years without knowing what it's for. It's the document that says which of the Annex A controls apply to you, which don't, and why. It's also the first thing an auditor opens. If you don't understand what it is, you can't understand why it matters so much, and it matters more than almost anything else in the file.
"Annex A is a shopping list." It isn't. The ninety-three controls in Annex A are not a menu you buy from or a checklist you tick. They're options you justify, based on your risks. "We implemented all ninety-three" is not a good answer. "We implemented these, excluded those, and here's why" is. The distance between those two sentences is the distance between understanding the standard and performing it.
"Certified means done." Passing the certification audit is not the finish line. ISO 27001 is a management system, which means it's supposed to keep running: monitored, reviewed, improved, audited again. People who think certification is a one-time event are the ones who panic at the surveillance audit a year later. Understanding that upfront changes how you treat everything.
None of these are advanced. They're the basics. But the basics are exactly what nobody stops to teach, which is why so many capable people spend so long feeling lost.
What two days actually give you
You don't walk out of a Foundation course able to build an ISMS from scratch. That's a different course, and a longer one. What you walk out with is something more immediately useful for where you probably are right now: you can finally follow the conversation.
You'll have a mental model of what an ISMS is and why it exists, so the standard stops feeling like disconnected clauses. You'll have the vocabulary, actually understood rather than memorised, so the words in the meeting mean something. You'll understand how the standard is structured, so you can find your way around thirty pages without drowning. You'll understand the logic of risk, the real difference between a risk, a threat, and a missing control, so risk workshops stop being fog. And you'll know enough to know what you don't know, which is the thing that lets you ask the right question instead of nodding at the wrong moment.
That is the difference between sitting in the room and being in the room.
That's what the 2 days are for
August 31 and September 1. Monday and Tuesday. Live online, in English. A small cohort, built around explaining this field the way I wish someone had explained it to me.
This isn't a dramatic reading of the standard. You can read the standard yourself, that's not the hard part. This is the map that sits underneath it: what an ISMS is, how the pieces fit, what the words mean, how risk actually works, what an auditor is looking for, and where you fit into all of it. Explained in plain language, with real examples from real rooms.
Day 1. What information security actually means, past the buzzwords. What an ISMS is and why organisations build one. How ISO 27001 is structured, clause by clause, without the jargon. Context, leadership, and where the standard comes from. The regulatory picture: why GDPR, NIS2, and DORA all keep pointing at this.
Day 2. How risk assessment and risk treatment actually work. The Statement of Applicability and the Annex A controls, demystified. How an ISMS runs day to day: monitoring, review, improvement. What happens in a certification audit and what auditors want to see. Then exam preparation, and the exam itself.
By the end of Tuesday, you sit the PECB exam. Pass it, and you're certified.
Who teaches this
Me. Christophe. Active CISO, founder of Cyber Academy.
I don't teach the basics from a textbook. I teach them from the job. When I explain what a risk is, it's because I've sat in the workshops and watched people confuse risks with controls for the hundredth time. When I explain the Statement of Applicability, it's because I've handed one to an auditor and watched them go straight to it. When someone in the room says "I don't get why this matters," I don't give them the exam answer. I tell them what it looks like when it goes wrong, because I've seen it go wrong.
The advantage of learning the fundamentals from someone who actually does the work is simple: you learn what matters and what's just noise. You skip the trivia. You keep the parts you'll use the following week.
That's the difference between training and a slide deck.
The guarantee
Complete the course. Sit the exam. If you don't pass, we refund your training fee.
No fine print beyond finishing the programme and taking the exam. We call it Certified or Refunded, and we mean it. The methodology works, the pass rate proves it, and if you're investing your time and your company's money, you deserve a provider betting on the same outcome you are.
The details
Course: ISO/IEC 27001:2022 Foundation, PECB Certified
Dates: August 31 to September 1, 2026
Format: Live online. Interactive. Not recorded.
Language: English
CPD: 14 credits
Free retake: within 12 months
Price: €1,099
Your move
If you've just been handed an ISO 27001 project and you have no idea where to start, this is your starting point.
If you've been nodding through meetings for months and you're tired of Googling under the table, this is how you stop.
If you're planning to go further one day, Lead Implementer, Lead Auditor, this is the foundation the rest of it builds on. Start here and the advanced courses actually make sense.
And if you just need the credential to prove you understand the basics, this gets you certified in two days.
Reserve your spot below.
Questions? Email me directly. No sales team. No chatbot. Just me.
Christophe
