KRI NEWS
EXECUTIVE CERTIFICATE IN CYBER RISK MANAGEMENT & INFORMATION ASSURANCE
EXECUTIVE CERTIFICATE IN CYBER RISK MANAGEMENT & INFORMATION ASSURANCE
Programme Description
The Executive Certificate in Cyber Risk Management & Information Assurance equips professionals with the knowledge and practical skills required to identify, assess and manage cybersecurity risks within organisations.
The programme is particularly relevant to auditors, accountants, school proprietors, education managers, compliance officers, ICT professionals and administrators who increasingly need to understand how cybersecurity affects organisational operations, financial information, educational data and institutional decision-making.
Participants will learn how to identify cyber threats and vulnerabilities, assess their likelihood and impact, evaluate security controls and develop practical risk-mitigation strategies.
The programme also introduces AI, emerging technologies and cyber-risk challenges in educational institutions, making it particularly relevant to KRI's education-focused professional portfolio.
Programme Overview
|
Item |
Details |
|
Institution |
Kingdom Royal Institute (KRI) |
|
Programme |
Executive Certificate in Cyber Risk Management & Information Assurance |
|
Duration |
4 Weeks |
|
Sessions |
3 sessions per week |
|
Total Sessions |
12 |
|
Session Duration |
2 hours |
|
Total Contact Hours |
24 hours |
|
Mode |
Online / Blended |
|
Level |
Executive Professional Certificate |
|
Fee |
GHC1500.00 |
|
Award |
KRI Executive Certificate |
Programme Focus
Identifying cyber risks, evaluating information-security controls and developing practical strategies to protect educational and organisational information systems.
1. Programme Description
The Executive Certificate in Cyber Risk Management & Information Assurance equips professionals with the knowledge and practical skills required to identify, assess and manage cybersecurity risks within organisations.
The programme is particularly relevant to auditors, accountants, school proprietors, education managers, compliance officers, ICT professionals and administrators who increasingly need to understand how cybersecurity affects organisational operations, financial information, educational data and institutional decision-making.
Participants will learn how to identify cyber threats and vulnerabilities, assess their likelihood and impact, evaluate security controls and develop practical risk-mitigation strategies.
The programme also introduces AI, emerging technologies and cyber-risk challenges in educational institutions, making it particularly relevant to KRI's education-focused professional portfolio.
2. Programme Aim
To develop professionals who can identify, assess, communicate and manage cybersecurity risks and contribute effectively to information assurance and institutional resilience.
3. Programme Objectives
By the end of the programme, participants should be able to:
- Explain fundamental concepts of cybersecurity risk management.
- Identify cyber threats, vulnerabilities and organisational risks.
- Assess the likelihood and potential impact of cyber risks.
- Identify critical information assets requiring protection.
- Evaluate existing cybersecurity controls.
- Recommend appropriate risk-mitigation measures.
- Explain the role of information assurance in organisational governance.
- Develop basic cybersecurity risk registers.
- Communicate cyber risks to management and stakeholders.
- Explain emerging cyber risks associated with AI and digital transformation.
- Develop a cybersecurity risk-management plan for an organisation.
- Apply cyber-risk principles to educational institutions.
4. Learning Outcomes
At the end of the programme, participants should be able to:
- Identify an organisation's critical information assets.
- Distinguish between threats, vulnerabilities and risks.
- Conduct a basic cybersecurity risk assessment.
- Develop and maintain a cyber-risk register.
- Assess the effectiveness of security controls.
- Prioritise risks according to likelihood and impact.
- Recommend risk-treatment strategies.
- Explain information-assurance principles.
- Report cybersecurity risks to management.
- Develop a practical cyber-risk management framework.
- Assess cybersecurity risks affecting schools and educational institutions.
5. Target Participants
The programme is particularly suitable for:
Accounting & Audit Professionals
- Accountants
- Internal auditors
- External auditors
- Forensic accountants
- Audit managers
- Risk and compliance professionals
Education Professionals
- School proprietors
- Headteachers
- School administrators
- Education managers
- ICT coordinators
- Education officers
- University administrators
Business & Technology Professionals
- Managers
- Compliance officers
- ICT professionals
- Information-security officers
- Business owners
- Risk managers
- Consultants
6. Entry Requirements
Applicants should normally possess:
- A minimum of SHS certificate or equivalent; and
- Relevant professional, administrative, educational or work experience where applicable.
Basic computer literacy is recommended.
7. Programme Structure
MODULE 1
Cyber Risk Fundamentals
MODULE 2
Risk Identification & Assessment
MODULE 3
Security Controls & Risk Mitigation
MODULE 4
Cyber Risk Management Project
8. DETAILED COURSE OUTLINE
MODULE 1: CYBER RISK FUNDAMENTALS
Session 1: Understanding Cybersecurity Risk
Topics
- Meaning of cybersecurity
- Meaning of cyber risk
- Threats, vulnerabilities and risks
- Information security and cybersecurity
- Information assurance
- Cybersecurity and organisational objectives
- Why cyber risk matters to organisations
Educational
Context:
Cyber risks facing schools, universities and training institutions.
Practical
Activity:
Identify five cybersecurity risks affecting a typical educational institution.
Session 2: Information Assets & Cyber Threats
Topics
- Information assets
- Hardware and software assets
- Educational records
- Financial information
- Student and staff information
- Threat actors
- Malware
- Phishing
- Ransomware
- Insider threats
- Social engineering
Practical
Activity:
Develop an Information Asset Inventory for a school or organisation.
Session 3: Cyber Risk & Organisational Impact
Topics
- Financial impact
- Operational disruption
- Reputational damage
- Legal and regulatory consequences
- Loss of confidential information
- Business continuity
- Cybersecurity and organisational resilience
- Role of management in cyber-risk governance
Practical
Activity:
Analyse a simulated ransomware incident and identify its potential
organisational impacts.
MODULE 2: RISK IDENTIFICATION & ASSESSMENT
Session 4: Identifying Cyber Risks
Topics
- Risk identification process
- Asset-based risk identification
- Threat identification
- Vulnerability identification
- Risk scenarios
- Internal and external risks
- Emerging technology risks
Practical
Activity:
Develop a list of cyber-risk scenarios for a school, business or professional
organisation.
Session 5: Cyber Risk Assessment
Topics
- Likelihood
- Impact
- Risk scoring
- Qualitative risk assessment
- Quantitative risk concepts
- Risk matrices
- Risk prioritisation
Practical
Activity:
Create a 5 × 5 Cyber Risk Matrix and assess simulated risks.
Session 6: Cyber Risk Register & Reporting
Topics
- Purpose of a risk register
- Risk descriptions
- Risk owners
- Existing controls
- Risk ratings
- Treatment plans
- Residual risk
- Management reporting
Practical
Activity:
Create a cybersecurity risk register containing at least five identified risks.
MODULE 3: SECURITY CONTROLS & RISK MITIGATION
Session 7: Understanding Security Controls
Topics
- Meaning of security controls
- Preventive controls
- Detective controls
- Corrective controls
- Administrative controls
- Technical controls
- Physical controls
- Access controls
- Security awareness
Practical
Activity:
Match identified cyber risks with appropriate security controls.
Session 8: Risk Treatment & Mitigation
Topics
- Risk avoidance
- Risk reduction
- Risk transfer
- Risk acceptance
- Control selection
- Cost-benefit considerations
- Risk ownership
- Residual risk
Practical
Activity:
Develop a risk-treatment plan for five simulated cybersecurity risks.
Session 9: Information Assurance & Security Governance
Topics
- Information assurance principles
- Confidentiality
- Integrity
- Availability
- Accountability
- Security policies
- Governance
- Compliance
- Internal controls
- Audit and assurance
Special Focus for Auditors & Accountants
- IT controls
- Financial information security
- Access controls
- Segregation of duties
- Audit evidence
- Cyber-risk reporting
Practical
Activity:
Evaluate a simulated organisation's cybersecurity controls and identify
weaknesses.
MODULE 4: CYBER RISK MANAGEMENT PROJECT
Session 10: Developing a Cyber Risk Management Framework
Topics
- Cyber-risk governance
- Risk identification
- Risk assessment
- Risk treatment
- Control implementation
- Monitoring
- Reporting
- Continuous improvement
Practical
Activity:
Design a cyber-risk management framework for an educational institution or
organisation.
Session 11: AI, Emerging Technology & Cyber Risk
Topics
- AI-related cyber risks
- Generative AI
- Data privacy risks
- AI-assisted cyberattacks
- Shadow AI
- Cloud and digital transformation risks
- Third-party technology risks
- Responsible AI governance
Practical
Activity:
Assess the cyber risks associated with introducing an AI-powered system into a
school.
Session 12: Final Cyber Risk Management Project
Participants will present a:
Cyber Risk Management & Information Assurance Plan
The project should include:
- Organisation profile
- Critical information assets
- Threat identification
- Vulnerability identification
- Cyber-risk scenarios
- Risk assessment
- Risk matrix
- Risk register
- Existing security controls
- Risk-treatment strategy
- AI/emerging technology risks
- Monitoring and review plan
9. Practical Tools & Techniques
Participants will work with practical frameworks and tools such as:
- Cyber-risk registers
- Risk matrices
- Asset inventories
- Risk assessment templates
- Control assessment checklists
- Cybersecurity dashboards
- Business impact analysis
- Security-control mapping
- AI-assisted risk analysis
The emphasis is on professional decision-making and risk management, rather than advanced technical hacking.
10. Teaching & Learning Methods
The programme will use:
- Interactive lectures
- Case studies
- Risk-assessment exercises
- Audit scenarios
- Group discussions
- Cybersecurity simulations
- Risk-register development
- Control assessment exercises
- AI demonstrations
- Practical institutional projects
Recommended 2-hour session structure
20
minutes — Concept
introduction
30 minutes — Explanation and examples
30 minutes — Case study
30 minutes — Practical activity
10 minutes — Review and questions
11. Assessment
|
Assessment Component |
Weight |
|
Class participation & practical activities |
15% |
|
Individual assignments |
15% |
|
Cyber-risk assessment exercise |
20% |
|
Security-control evaluation |
15% |
|
Final Cyber Risk Management Project |
25% |
|
Project presentation |
10% |
|
Total |
100% |
12. Final Project Options
Participants can select a project such as:
- Cyber Risk Management Plan for a School
- Cyber Risk Assessment of an Educational Institution
- Cybersecurity Risk Register for an Organisation
- Information Security Control Assessment
- Cyber Risk Assessment for an Accounting Firm
- Cyber Risk Management Plan for a Small Business
- AI Risk Assessment for an Educational Institution
- Cybersecurity Governance & Assurance Framework
13. Certification Requirements
Participants should:
- Attend at least 80% of sessions
- Complete required assignments
- Participate in practical activities
- Complete the final project
- Present the project
- Meet the required assessment standard
14. Graduate Profile
A successful graduate should be able to:
Identify cybersecurity risks, assess their potential impact, evaluate security controls, recommend risk-treatment measures and communicate cyber risks effectively to management and institutional stakeholders.