Cyber Risk Management & GRC: From Risk to Assurance
Cybersecurity money gets approved in risk language, not technical language. Learn to assess, quantify, register and report cyber risk in the terms executives and boards actually act on.
Cybersecurity money gets approved in risk language, not technical language. Learn to assess, quantify, register and report cyber risk in the terms executives and boards actually act on.
This course is a complete pass through governance, risk and compliance, built for the person who has to turn technical findings into a defensible risk decision. It runs the whole arc, from defining governance and accountability through assessing, analyzing and prioritizing risk, choosing a response, recording it in a register, mapping it to controls, validating through assessment, extending it to third parties, and reporting it upward. It teaches the NIST stack alongside its commercial and international parallels, so NIST SP 800-30, 800-39 and the IR 8286 series sit next to COSO, ISO 31000, ISO/IEC 27005 and the EU Digital Operational Resilience Act.
Risk quantification is the headline. The course covers the FAIR model and then applies a materiality determination under the SEC disclosure criteria, which is exactly what boards are asking their security teams about right now, and very little training at any price gets past qualitative red, amber and green. It closes with a workshop in which participants build risk register entries for a fictional organization, decide whether a scenario triggers a disclosure obligation, and defend a risk treatment recommendation. One scope note: third-party material here is enterprise-level oversight and governance, while procurement-level cyber supply chain risk management is covered separately in Cybersecurity Supply Chain Risk Management (C-SCRM).
Foundational cybersecurity knowledge.
Attend this course online as self-paced training with access to an instructor for questions. When you purchase the self-paced course, you may also attend the live course for free within one year.
Learn the concepts and skills covered in this course or your tuition is on us. See details and terms & conditions.
Work on projects proven to boost retention
Refined over many cohorts for an optimal learning experience
The teaching method at Noble Desktop is perfect and the classes provide you with infinite knowledge that makes you eager to take everything they offer. I love Noble!
—Ivonne Ackerman
Experienced educators who are driven to help you succeed
Refresh the materials for free within one year
Attend this course live online or as self-paced training. Engage with expert instructors, ask questions, and get feedback on your exercises and projects.
Unlike other providers, these are not mass open-enrollment classes. At Noble Desktop, you’ll learn in small groups (typically 8-15 students) and receive personalized attention.
Get the same interactivity and access to the instructor as in-person students. There are no extra fees and we’ll work with you to ensure your remote setup is perfect.
Learn at your own pace with pre-recorded video lessons and hands-on exercises. Work through the material on your schedule with access to course content and resources.
Upon completion of this course, you’ll receive an official certificate testifying to your mastery of the curriculum. We’ll send you a link where you can download your certificate, share it online with your friends, post it to your professional network on LinkedIn, and view all your earned certificates. Congratulations on your achievement!
Shareable on
We offer a single free retake of the class within a year.
You can also access recordings of each session in your student portal within one business day of the session’s end. Recordings are available for one month after the session.
Risk analysts, GRC and compliance staff, security officers, security managers, and anyone who has to brief cyber risk to leadership or a board. Also suitable for auditors and program staff who consume risk output and need to judge whether it is sound.
Foundational cybersecurity knowledge.
This course does not qualify for payment plans or student financing. See our Payment Plan FAQ to find related programs that qualify.
You may attend this training virtually (online) at the scheduled time the course is offered (New York, Eastern Time).
You have some options:
There are no extra fees or taxes for our courses. The price you see on this page is the maximum you’ll pay us.
We don’t currently offer discounts as we do our best to affordably prices our courses.
These related courses share skills and topics with Cyber Risk Management & GRC: From Risk to Assurance. Select up to two and tap Compare selected courses to view a side-by-side comparison.
Twelve hours live on cybersecurity supply chain risk management, built on NIST SP 800-161r1 and current to August 2026 on supply chain regulation — criticality, supplier due diligence, procurement, software supply chain, and monitoring.
Choose Cybersecurity Supply Chain Risk Management (C-SCRM) if your focus is supplier and procurement risk specifically rather than enterprise-wide governance.
Take the threat hunting and detection engineering skills you already have and build them into a defensible program, using a methodology sourced entirely from published NIST and CISA standards. Covers a repeatable hunt process, bias-reducing analytic techniques, the full detection lifecycle, and the validation and metrics that prove risk is going down.
Choose Threat Hunting and Detection Engineering (Advanced) if you want hands-on technical work rather than risk governance and reporting.
Twelve hours live on AI red teaming and assurance: running an engagement, matching technique to attack surface, building an auditable assurance case, and testing agentic systems. No lab needed.
Pair this with AI Red Teaming and Assurance if your risk register needs to account for AI-specific adversarial testing and assurance evidence.
Learn how to break into the cybersecurity industry and succeed with job search strategies, mock interviews, and explorations of different job roles. Get tips on networking, resume prep, and continuous learning for a successful career.
Choose Cybersecurity Industry & Job Prep if you're starting a cybersecurity career rather than managing risk at the leadership level.
Purchase group class vouchers at a discount for our regularly-scheduled group classes, or create a custom training program at your offices.
We’ve trained thousands of companies!
Let us create the perfect program for your team.
The first installment is due one week before the first class. Subsequent installments are spread out evenly across the duration of the course.
| Installments | |
|---|---|
| 10% non-refundable deposit | |
| $1,049.00 | Total You Pay |
See the Installment plan FAQ for more information.