
Practical assessments bridge theory and real-world execution for information security professionals by testing vulnerability scanning, result analysis, and mitigation recommendations. They validate skills against frameworks, boost governance and compliance readiness.
Develop practical cybersecurity and GRC assessment skills through 21 hands-on tasks, with environment setup, resources, and a progression from fundamentals to advanced practicals, including PCI and related standards.
Join Richard Perry in practical cybersecurity and governance, risk, and compliance training that emphasizes hands-on experience to boost your professional development, prove value on your resume, and meet industry needs.
Develop practical skills to conduct cybersecurity and GRC assessments, and strengthen an organization's security posture through ransomware and risk assessments.
Stay current with threats and trends by conducting cybersecurity and GRC assessments. Identify and remediate gaps, verify security measures, ensure compliance, and build stakeholder trust.
Explore fundamental types of cybersecurity and GRC assessments, including vulnerability, penetration testing, risk, compliance, incident response planning, security audits, and specialized evaluations like network, data protection, and third-party security.
Discover how GRC and cybersecurity assessments categorize and overlap, including risk, compliance, governance, audit, privacy, and business continuity assessments, alongside vulnerability, threat, and incident response readiness in cybersecurity.
Move from setup to hands-on cybersecurity assessments with a realistic, team-based approach. Explore ransomware readiness, PCI DSS readiness, cyber resilience, CMC readiness, and ISO 2727 2001 compliance readiness.
Define cyber risk as potential harm from IT failures or breaches, equal to threat times vulnerability times the value of information, affecting confidentiality, integrity, and availability.
Learn general guidelines for conducting cybersecurity assessments, including planning, cooperation, execution, analysis, reporting, remediation, and review of vulnerability assessment, risk assessment, and network assessment, using agreed methods and tools.
Define the scope, gather information, develop criteria, conduct the third-party security assessment, document findings, evaluate results, mitigate risk, and follow up, while ensuring project planning and management support.
Download, install, and configure the assessment tool, set up your environment, and walk through the application to begin your first practical cybersecurity and GRC assessment.
Explore the CSA ransomware readiness assessment toolset, install and configure the environment, and leverage its resource library to conduct cybersecurity assessments and strengthen organizational resilience.
Explore a hands-on walkthrough of a cybersecurity assessment environment, covering maturity and standard models, network diagrams, and ransomware readiness to help GRC professionals evaluate organizational security posture.
Execute a ransomware risk assessment with a web-based test to identify weaknesses in defenses, including initial compromise, lateral movement, and data loss exfiltration, then improve controls.
Assess ransomware readiness for health care organizations by detailing a ransomware risk assessment, exploring initial compromise, lateral movement, data loss, and remediation steps, including backups, phishing controls, and incident response.
Assess PCI DSS readiness by evaluating current policies, controls, and the organization's environment, identify gaps, and plan remediation to achieve compliant PCI DSS reporting.
Learn how to perform a CMMC readiness assessment for a defense contractor, including initial posture review, gap analysis, remediation planning, and final reporting to reach the five-level maturity model.
Conduct a cyber resilience review using a NIST CSF–aligned self-assessment package. Use Carnegie Mellon University's guide, question sets, and documentation to identify gaps and strengthen security posture.
Conduct a HIPAA readiness compliance assessment for healthcare organizations, including telehealth expansions, by reviewing policies, risk analyses, security controls, training, and incident response to identify gaps and guide remediation.
Explore assessment in depth for cybersecurity and GRC. Use a HIPAA-focused case with the Cset tool to evaluate PHI protection and HIPAA security and privacy compliance.
Identify your HIPAA scope by listing covered entities, business associates, and phi assets. Form a cross-functional team led by privacy and security officers to drive compliance.
Explore using the CE set tool to conduct questionnaire-based assessments against NIST, ISO, and CIS controls, perform gap analysis, and produce risk-focused reports for health care organizations.
Continue the preparation phase by examining the security assurance level, its impact on question count and assessment rigor, and the Sal categories guiding HIPAA risk-based evaluation.
Assess outcomes against the EPA standard and identify gaps to reach 100% compliance, prioritizing risk assessment and access control. Compile executive summaries and site cybersecurity plans to guide management actions.
Engage in a bonus segment on practical vulnerability assessment using Nessus from Tenable, and review tools and resources that boost an organization's cybersecurity posture.
Learn the vulnerability assessment process, from asset discovery and prioritization to scanning, results analysis, and remediation, strengthening continuous security and risk-based protection.
Perform a basic vulnerability assessment using Nessus to discover assets, launch scans, and identify vulnerabilities. Generate reports for stakeholders and drive informed security decisions.
Review the key practical assessments for cybersecurity and GRC, including vulnerability, risk, and compliance assessments, plus PCI DSS readiness and cyber resilience, with tools like Nessus and the CSA tool.
Explore free security services and tools from CISA, categorized to reduce incidents, detect threats, respond to incidents, and maximize resilience, including OpenVAS, Zscaler, Caldera, and Metasploit.
Develop cybersecurity and GRC skills through practical assessments, using course resources, following setup instructions, and executing assessments in a configurable environment.
Navigate the course resources and install the required environment to complete practical assessments for cybersecurity and GRC professionals. Explore assessment options, execute tasks, and seek help if challenges arise.
Conclude practical assessments for cybersecurity and GRC professionals by applying pre-assessment steps, ransomware readiness concepts, and available resources to strengthen controls, mitigate risks, and showcase hands-on expertise on resumes.
This course is designed to provide Cybersecurity & GRC Professionals, with the confidence, skills, and tools to effectively and efficiently conduct a number of industry-established Cybersecurity & GRC Assessments (21 Assessments in total).
These assessments are done to enhance the security maturity level of an organization or business.
At the end of this course, you will gain the theoretical and practical skills required for:
>>Demonstrated by me (the instructor)
1-Conducting a Ransomware Risk assessment
2-Conducting a Ransomware Readiness Assessment
3-Conducting a PCI DSS Readiness Compliance Assessment
4-Conducting a CMMC Vendor Readiness Assessment
5-Conducting a NIST CSF - Cyber Resilience Review Assessment (CRR)
6-Conducting a Vulnerability Assessment
>>Your Assigned Practical Challenge to develop your skills (All supporting resources with steps provided for each assessment):
7-Conducting an Incident Response Planning and Simulation
8-Conducting a cloud security assessment
9-Conducting a Cybersecurity Program Assessment
10-Conducting a Data Protection and Privacy Assessment
11-Conducting a Network Security Assessment
12-Conducting a Social engineering assessment
13-Conducting a Software development life cycle
14-Conducting a Supply chain risk assessment
15-Conducting a Third-Party Security Assessment
16-Conducting an Application security assessment
17-Conducting an Endpoint security assessment
18-Conducting an Insider threat assessment
19-Conducting an External Dependency Management Assessment
20-Conducting a HIPAA Compliance Readiness Assessment
21-Conducting a NIST CSF Readiness Assessment
After completing this course, you will be able to comfortably demonstrate to prospective employers, that you possess the practical skills and theoretical knowledge to plan for and develop plans to initiate and conduct cybersecurity & GRC assessments, that can enhance the security posture of any organization.