Live, Instructor-Led Programme
Cyber GRC
Assess risk. Design effective controls.Support meaningful compliance.

8 Weeks
6.5 hrs/week
across two class days
Instructor-Led, Virtual
C$999
Cyber GRC Programme
Develop Job-Ready Capabilityfor Modern Enterprise Risk Management
This eight-week, live online programme gives you the governance structures, risk methods and control practices used in real security teams. You'll learn from experienced practitioners, work through realistic scenarios, and finish with a portfolio of GRC artefacts you can take straight into the workplace.
Practical & Applied
Hands-on exercises, templates and real-world scenarios.
Proven Frameworks
NIST CSF, ISO 27001, PCI DSS and SOC 2 in practice.
Expert Instructors
Learn from practitioners working in GRC every day.
Peer Collaboration
Discuss challenges and share insights with peers.
Implementation-Ready
Leave with artefacts you can use and talk to in interviews.
Certificate of Completion
Earn a ReveCyber Certificate upon successful completion.
Cyber GRC Programme
C$999
Instructor-Led, Virtual
8 Weeks
6.5 hrs/week
across two class days
Small class size
Live sessions, not recorded
Have questions?
Our advisors are here to help.
Secure your seat today.
Places are limited.
Practical Work You Will Complete
By the end of the programme, you will build a portfolio of GRC artefacts you can apply in your organisation.
GRC Charter &GovernanceStructure
Security PolicySet
Asset Register &Classification
Control Matrix &Test Evidence
Risk Register &Treatment Plan
Vendor RiskAssessment
FrameworkMapping &Gap Analysis
CapstonePortfolio
A Structured Eight-Week Learning Journey
- What governance, risk and compliance really mean in practice
- Build a GRC charter and governance structure
- Policy hierarchy: policies, standards, procedures and guidelines
- Overview of compliance and regulatory drivers
- Asset inventory, ownership and classification
- Administrative, technical and physical controls
- Preventive, detective and corrective control types
- Control testing and collecting audit evidence
- Threats, vulnerabilities and risk scenario writing
- Likelihood and impact scoring methods
- Inherent versus residual risk
- Building and maintaining a risk register
- Risk treatment options: mitigate, transfer, avoid, accept
- Assigning risk owners, actions and timelines
- Risk acceptance and exception handling
- Reporting risk clearly to management
- Vendor due diligence and assessment questionnaires
- Tiering vendors by criticality and data access
- Contracts, SLAs and security clauses
- Ongoing monitoring and offboarding
- NIST CSF 2.0 functions and profiles
- ISO 27001:2022 and Annex A controls
- Statement of Applicability essentials
- Mapping one control set across multiple frameworks
- PCI DSS scope and key requirements
- SOC 2 trust services criteria foundations
- Gap assessment and remediation prioritisation
- Evidence packs and audit readiness reviews
- Complete the end-to-end capstone scenario
- Executive-ready presentation and management reporting
- Assemble your artefact portfolio
- Explain your work confidently in interviews
Designed for professionals moving into governance, risk and compliance roles.
Career changers, IT professionals moving into security, and aspiring GRC practitioners.
