Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CISO Training: Build an Information Security Program
New
100 students

CISO Training: Build an Information Security Program

Build a cyber risk register, security policies, ISO 27001 or SOC 2 gap analysis, incident response plan and board report
Last updated 9/2026
English

What you'll learn

  • Build a 90-day CISO plan with five first-week meetings and a one-page report for the CEO on day 90
  • Price your top cyber risks in dollars with the expected annual loss formula and set a risk acceptance threshold
  • Write seven one-page security policies, from the master policy to remote work, and get them signed by the CEO
  • Pick ISO 27001, SOC 2 or CIS Controls for your business and run a gap analysis with a four-quarter closing plan
  • Roll out MFA in 90 days, starting with admins and executive email, and build an access matrix by role
  • Run your first phishing drill within a week and track click rate and report rate on a 12-month calendar
  • Check vendors with a 20-question security questionnaire and score them by three levels of data access
  • Lead the first hour of an incident with four roles, four severity levels and ready texts of the first messages
  • Build a security budget across six lines, a dashboard of eight metrics and a five-slide report to the board
  • Learn with Mike Pritula, the #1 HR instructor on Udemy, alongside 2,000,000+ of his Udemy students

Course content

5 sections • 10 lectures • 7h 23m total length
  • The CISO Role and the First 90 Days: A 90-Day Plan for a New CISO43:35
    • Three CISO roles: risk manager, translator for the business and owner of the rules

    • Who the CISO reports to: the CIO, the CEO, or the CFO or COO

    • First month: listen and collect lists of assets, people, contracts and past incidents

    • Second month: assess top ten risks, quick wins and a maturity scale; third month: show the plan

    • Five first-week meetings and what the CEO expects to see on day 90

  • Risk Register and the Price of Risk: Cyber Risk Assessment in Dollars43:50
    • The price-of-risk formula: expected annual loss from one event and its frequency

    • A ransomware calculation on real numbers

    • Probability and impact scales 1–5 and a 5 × 5 risk matrix with three zones

    • A risk register in seven columns and a risk acceptance threshold approved by the CEO

    • Four decisions on a risk: reduce, transfer, avoid or accept


Requirements

  • Hands-on experience running or administering IT infrastructure, or leading an IT team
  • Access to your company’s admins, system lists and contracts, so the assignments are done on real data
  • Excel or Google Sheets for the risk register, the gap analysis, the vendor register and the budget
  • No CISSP, CISM or other security certification is needed
  • No security team or security budget is needed to start

Description

This course contains the use of artificial intelligence

Security was added to your job. The budget and the team were not. And the CEO already wants to know onething: “Are we protected?”

That is how most first CISOs start in a company of 100 to 2,000 people. You know the infrastructure and youhave closed incidents with your own hands, but nobody showed you how to price a risk in dollars, write apolicy people actually read or get ready for an audit. So you patch whatever shouts loudest, buy one more tooland hope the next client security questionnaire does not arrive this month. Without a risk register there isnothing to compare, without a plan there is nothing to show the CEO, and every request for money sounds likefear instead of a business decision.

After this course you run information security as a management system, not as a queue of fires. Every majorrisk sits in one register with a price in dollars, an owner and a decision. Seven short policies are signed by theCEO and known to employees. You know which standard your clients will ask for and where your gaps arebefore an auditor finds them. MFA covers admins and executives first, phishing drills turn clicks into reports,vendors are checked before the contract is signed, and the first hour of an incident follows a playbook insteadof panic. Your budget points at rows of the risk register, and your quarterly report to the board fits into fiveslides and ten minutes.

The course is built and taught by Mike Pritula:

  • Founder of Pritula Academy, where 170,000+ students have trained, and #1 HR instructor on Udemy, with2,000,000+ students on Udemy

  • 20 years of leadership in HR at Wargaming, Preply, iDeals, Starlightmedia and Alfa-Bank

  • At iDeals, a virtual data room company, a client made an ISO 27001 and COBIT audit a condition of one ofthe largest contracts in the company’s history; at Preply and iDeals he scored every system provideragainst his own criteria checklist

  • At Wargaming he worked with a business continuity plan for evacuating an office for several days and withevacuation drills in a 16-floor office of 2,000 employees, each followed by a debrief by the numbers

First you take the role: a 90-day plan, five first meetings and a risk register priced in dollars. Then you write therules: a pack of seven policies and a gap analysis against ISO 27001, SOC 2 or CIS Controls. Next you closethe most common doors: MFA and privileged accounts, phishing drills and security awareness training. Afterthat you control what comes from outside, with vendor checks and an incident response playbook. Finally youbuild the security budget, the metrics dashboard and the report to the board. Each lesson stands on its own,so if you need an incident playbook by Monday, you can open lesson eight tonight.

What’s included:

  • Lifetime access to all materials

  • Active instructor support in Q&A

  • Udemy Certificate of Completion

  • A practical assignment for your own company in every lesson

  • Ready-to-use templates: a 90-day plan, a risk register, seven policy templates, a gap analysis sheet, anaccess matrix, a phishing drill calendar, a vendor questionnaire, an incident playbook, a budget andmetrics sheet and a board report

  • A section with additional courses, tools and resources

Every month without a register, a playbook and a plan is another month in which a client questionnaire, anaudit request or an incident can arrive before you are ready. The security leads who speak to the CEO indollars get the budget and the seat at the table, and the rest keep defending another tool purchase. Your nextboard question is already on its way.

Enroll now and start your first lesson today.

Who this course is for:

  • IT managers and heads of IT who were handed information security on top of their current role
  • Security leads and newly appointed CISOs in companies of 100 to 2,000 people with no dedicated security team
  • System administrators and infrastructure engineers moving from hands-on security work into security management
  • CTOs, COOs and founders who own cybersecurity until the company hires a CISO
  • IT and compliance managers preparing the company for an ISO 27001 or SOC 2 audit