Open for Enrolment

Live, Instructor-Led Programme

Cyber GRC

Assess risk. Design effective controls.Support meaningful compliance.

Cyber GRC professional reviewing risk and compliance work on a laptop

8 Weeks

6.5 hrs/week

across two class days

Instructor-Led, Virtual

C$999

Cyber GRC Programme

Develop Job-Ready Capabilityfor Modern Enterprise Risk Management

This eight-week, live online programme gives you the governance structures, risk methods and control practices used in real security teams. You'll learn from experienced practitioners, work through realistic scenarios, and finish with a portfolio of GRC artefacts you can take straight into the workplace.

Practical & Applied

Hands-on exercises, templates and real-world scenarios.

Proven Frameworks

NIST CSF, ISO 27001, PCI DSS and SOC 2 in practice.

Expert Instructors

Learn from practitioners working in GRC every day.

Peer Collaboration

Discuss challenges and share insights with peers.

Implementation-Ready

Leave with artefacts you can use and talk to in interviews.

Certificate of Completion

Earn a ReveCyber Certificate upon successful completion.

Cyber GRC Programme

C$999

Instructor-Led, Virtual

8 Weeks

6.5 hrs/week

across two class days

Small class size

Live sessions, not recorded

Have questions?

Our advisors are here to help.

Secure your seat today.
Places are limited.

Practical Work You Will Complete

By the end of the programme, you will build a portfolio of GRC artefacts you can apply in your organisation.

GRC Charter &GovernanceStructure

Security PolicySet

Asset Register &Classification

Control Matrix &Test Evidence

Risk Register &Treatment Plan

Vendor RiskAssessment

FrameworkMapping &Gap Analysis

CapstonePortfolio

A Structured Eight-Week Learning Journey

1
  • What governance, risk and compliance really mean in practice
  • Build a GRC charter and governance structure
  • Policy hierarchy: policies, standards, procedures and guidelines
  • Overview of compliance and regulatory drivers
2
  • Asset inventory, ownership and classification
  • Administrative, technical and physical controls
  • Preventive, detective and corrective control types
  • Control testing and collecting audit evidence
3
  • Threats, vulnerabilities and risk scenario writing
  • Likelihood and impact scoring methods
  • Inherent versus residual risk
  • Building and maintaining a risk register
4
  • Risk treatment options: mitigate, transfer, avoid, accept
  • Assigning risk owners, actions and timelines
  • Risk acceptance and exception handling
  • Reporting risk clearly to management
5
  • Vendor due diligence and assessment questionnaires
  • Tiering vendors by criticality and data access
  • Contracts, SLAs and security clauses
  • Ongoing monitoring and offboarding
6
  • NIST CSF 2.0 functions and profiles
  • ISO 27001:2022 and Annex A controls
  • Statement of Applicability essentials
  • Mapping one control set across multiple frameworks
7
  • PCI DSS scope and key requirements
  • SOC 2 trust services criteria foundations
  • Gap assessment and remediation prioritisation
  • Evidence packs and audit readiness reviews
8
  • Complete the end-to-end capstone scenario
  • Executive-ready presentation and management reporting
  • Assemble your artefact portfolio
  • Explain your work confidently in interviews

Designed for professionals moving into governance, risk and compliance roles.

Career changers, IT professionals moving into security, and aspiring GRC practitioners.