
Three CISO roles: risk manager, translator for the business and owner of the rules
Who the CISO reports to: the CIO, the CEO, or the CFO or COO
First month: listen and collect lists of assets, people, contracts and past incidents
Second month: assess top ten risks, quick wins and a maturity scale; third month: show the plan
Five first-week meetings and what the CEO expects to see on day 90
The price-of-risk formula: expected annual loss from one event and its frequency
A ransomware calculation on real numbers
Probability and impact scales 1–5 and a 5 × 5 risk matrix with three zones
A risk register in seven columns and a risk acceptance threshold approved by the CEO
Four decisions on a risk: reduce, transfer, avoid or accept
Seven policies instead of thirty: master policy, acceptable use, access, data classification, incidents,vendors, remote work
A one-page policy structure in six parts, from the reason to the owner and review date
Six steps from template to the CEO’s signature, agreed with HR and legal
Acceptable use of personal services and AI services with company data
How a policy gets read, not just signed: plain language, onboarding and a quarterly reminder
Three questions to choose the standard your clients will ask for
ISO 27001: 93 controls in four themes, Statement of Applicability and two audit stages
SOC 2: five trust criteria, Type 1 vs Type 2 reports and the observation window
CIS Controls: 18 controls and 56 safeguards of implementation group 1
A gap analysis in a week, certification cost and a four-quarter closing plan
What to switch MFA on for first: admins, executive email, VPN, financial systems, the whole company
SMS codes, push apps and passkeys: which MFA resists phishing
An access matrix by roles and systems with four values per cell
Privileged accounts, service accounts, a password manager and two accounts per admin
Grant, revoke and quarterly access review, plus a 90-day MFA rollout plan
Two metrics of a phishing drill: click rate and report rate
The first phishing simulation in a week in seven steps
Five phishing email scenarios and the signs that give each one away
What to do with an employee who clicked, without public lists of names
A 12-month awareness calendar and security training in 15 minutes a quarter
A vendor list in a day from four sources: accounting, software payments, logins and data holders
Three levels of vendor access to data and what to check at each level
A vendor security questionnaire of 20 closed questions and scoring in three zones
Five security clauses for the vendor contract: breach notification, audit, data deletion, subcontractors,liability
Vendor review once a year and offboarding a vendor who leaves
Four incident roles, each with a deputy, and a communication channel outside email
Four severity levels, from one computer to a stopped business
Six steps of incident response, from report to debrief, and the incident log
Who to notify and when: regulator within 72 hours, clients, insurer, police, employees
Texts of the first messages and a tabletop exercise twice a year with a backup restore test
A security budget built from the risk register, not from a market percentage
Six budget lines and an example budget for a company of 300 people
12 security metrics, from MFA coverage to time to contain and open red risks
Eight metrics on one monthly dashboard with color and direction
What protection saves: loss before, loss after and the price of the control
Four questions the board wants answered and what it never asks
Five slides of the board report, delivered in ten minutes
Translating technical findings into money and business risk
A bank of answers to 15 board questions and practice on six questions from the room
How to ask for budget with three options, and a quarterly reporting cadence
This course contains the use of artificial intelligence
Security was added to your job. The budget and the team were not. And the CEO already wants to know onething: “Are we protected?”
That is how most first CISOs start in a company of 100 to 2,000 people. You know the infrastructure and youhave closed incidents with your own hands, but nobody showed you how to price a risk in dollars, write apolicy people actually read or get ready for an audit. So you patch whatever shouts loudest, buy one more tooland hope the next client security questionnaire does not arrive this month. Without a risk register there isnothing to compare, without a plan there is nothing to show the CEO, and every request for money sounds likefear instead of a business decision.
After this course you run information security as a management system, not as a queue of fires. Every majorrisk sits in one register with a price in dollars, an owner and a decision. Seven short policies are signed by theCEO and known to employees. You know which standard your clients will ask for and where your gaps arebefore an auditor finds them. MFA covers admins and executives first, phishing drills turn clicks into reports,vendors are checked before the contract is signed, and the first hour of an incident follows a playbook insteadof panic. Your budget points at rows of the risk register, and your quarterly report to the board fits into fiveslides and ten minutes.
The course is built and taught by Mike Pritula:
Founder of Pritula Academy, where 170,000+ students have trained, and #1 HR instructor on Udemy, with2,000,000+ students on Udemy
20 years of leadership in HR at Wargaming, Preply, iDeals, Starlightmedia and Alfa-Bank
At iDeals, a virtual data room company, a client made an ISO 27001 and COBIT audit a condition of one ofthe largest contracts in the company’s history; at Preply and iDeals he scored every system provideragainst his own criteria checklist
At Wargaming he worked with a business continuity plan for evacuating an office for several days and withevacuation drills in a 16-floor office of 2,000 employees, each followed by a debrief by the numbers
First you take the role: a 90-day plan, five first meetings and a risk register priced in dollars. Then you write therules: a pack of seven policies and a gap analysis against ISO 27001, SOC 2 or CIS Controls. Next you closethe most common doors: MFA and privileged accounts, phishing drills and security awareness training. Afterthat you control what comes from outside, with vendor checks and an incident response playbook. Finally youbuild the security budget, the metrics dashboard and the report to the board. Each lesson stands on its own,so if you need an incident playbook by Monday, you can open lesson eight tonight.
What’s included:
Lifetime access to all materials
Active instructor support in Q&A
Udemy Certificate of Completion
A practical assignment for your own company in every lesson
Ready-to-use templates: a 90-day plan, a risk register, seven policy templates, a gap analysis sheet, anaccess matrix, a phishing drill calendar, a vendor questionnaire, an incident playbook, a budget andmetrics sheet and a board report
A section with additional courses, tools and resources
Every month without a register, a playbook and a plan is another month in which a client questionnaire, anaudit request or an incident can arrive before you are ready. The security leads who speak to the CEO indollars get the budget and the seat at the table, and the rest keep defending another tool purchase. Your nextboard question is already on its way.
Enroll now and start your first lesson today.