Skip to content

Intermediate · 10 weeks

Governance, Risk & Compliance

Where cybersecurity meets the business, with no coding required.

  • Live online, from anywhere
  • 10 weeks
  • A 2-hour live class every Monday
  • 4 hours a week
  • Next cohort: 15 January 2027

Who it’s for

  • Career switchers. From audit, law, finance or operations, moving into security through GRC.
  • IT and security practitioners. You want to grow from technical work into programme and audit leadership.
  • Compliance and risk officers. You want to specialise in information security frameworks.

Who it isn’t for

  • You want hands-on technical or offensive work: Ethical Hacking or Security+ fit better.

Before you start: Basic IT literacy. No coding. Experience in audit, risk, compliance, law or operations is a plus.

What you’ll build

A full ISO 27001 or SOC 2 readiness plan, with a risk register and treatment plan, presented as you would to a board.

Curriculum

10 modules, 10 weeks

Ten weeks on building security programmes, running risk assessments, preparing organisations for audit and explaining technical risk to the people who make decisions.

  1. 01Foundations of GRC
    • What GRC means
    • The three lines of defence
    • The business value of security
    • GRC in Nigeria and abroad
  2. 02Governance and security programmes
    • Building a programme from scratch
    • Committees and reporting lines
    • Roles, responsibilities and RACI
    • Reporting to a board
  3. 03Risk management
    • Identifying and scoring risk
    • Qualitative and quantitative risk
    • Building a risk register
    • Treating risk
  4. 04ISO/IEC 27001:2022
    • ISMS scope and context
    • The Statement of Applicability
    • Annex A controls
    • Stage 1 and Stage 2 audits
  5. 05SOC 2 and NIST CSF
    • Trust Services Criteria
    • Type 1 and Type 2 reports
    • NIST CSF functions
    • Mapping controls across frameworks
  6. 06Data protection: NDPA and GDPR
    • Data subject rights
    • DPIAs and records of processing
    • Cross-border transfers
    • Breach notification
  7. 07Policies and awareness
    • Policies people follow
    • Procedures and standards
    • Awareness programmes
    • Phishing simulations
  8. 08Third-party risk
    • Vendor questionnaires
    • Security clauses in contracts
    • Ongoing monitoring
    • Supply chain risk
  9. 09Audit readiness
    • Collecting evidence
    • Working with auditors
    • Managing findings
    • Continuous compliance
  10. 10Capstone: readiness plan
    • An ISO 27001 or SOC 2 readiness plan
    • Risk register and treatment plan
    • An executive presentation
    • Portfolio deliverables

Get the full syllabus

Every module, lab and tool as a one-page PDF. Enter your email and it downloads straight away.

How you learn

A week on the track

Live classes

A 2-hour live class every Monday. The time is confirmed when you enrol.

Mentor hours

Small-group office hours with a practising security engineer, every week

Labs

A hands-on lab every week

Tools

Risk registers in Excel, Policy libraries in Notion or Confluence, Jira for audit tracking, Compliance platforms (Vanta, Drata) in concept

Two kinds of lab: guided labs in our cloud environment, with nothing to install, and some virtual-machine work on your own laptop. We help you set the virtual machines up.

  1. MonLive class2-hour instructor-led session with real-world examples
  2. TueGuided labHands-on lab in our cloud environment
  3. WedMentor hoursSmall-group office hours with a practising security engineer
  4. ThuSolo challengeA timed challenge to lock in the week’s concepts
  5. FriCTF FridayTeam capture-the-flag with a leaderboard
Two people sketching a network diagram on a whiteboard
lab.learncyber · Week 7: Active Directory
$ nmap -sV -Pn 10.10.20.0/24
Nmap scan report for dc01.lab.learncyber (10.10.20.10)
88/tcp open kerberos-sec Microsoft Windows Kerberos
389/tcp open ldap Microsoft Windows AD LDAP
445/tcp open microsoft-ds
$ GetUserSPNs.py lab.learncyber/analyst -request
[*] 3 service accounts with SPNs found
$ hashcat -m 13100 tickets.txt wordlist.txt
svc_backup: cracked (weak password)
Illustration · real lab screenshots coming

Exam and certificate

There’s no external exam built in. You finish with a LearnCyber certificate of completion and a readiness plan for your portfolio.

Certificate, not certification

You receive a LearnCyber certificate of completion. It proves you completed the track, and employers can check it online. A certification is awarded by an exam body such as CompTIA.

What you’ll need

Laptop
A laptop with at least 8 GB of RAM and a stable internet connection
Internet
A connection that can hold a video call; every class is recorded if yours drops
Time
4 hours a week, including the 2-hour live class

Who teaches

Taught by Hackrowd Technology’s working penetration testers, the team that does this work for clients.

Offensive security

Penetration tests of web apps, APIs, networks and Active Directory for client organisations.

Security operations

SOC work: monitoring, detection and incident response.

Governance and audit

GRC programmes and ISO 27001 audits.

After the track

  1. Step 1

    Train

    Live classes, labs and your capstone.

  2. Step 2

    Internship

    A three-month internship after the training.

  3. Step 3

    Certificate and letter

    A certificate of completion employers can verify, and a recommendation letter.

Admissions

Three steps to your seat

  1. Step 1Join a free webinar

    Meet an instructor and ask anything first.

  2. Step 2Apply

    A short questionnaire, not a test, so we can recommend the right track.

  3. Step 3Reserve your seat

    Pay in full or in instalments. Your place is confirmed when the payment clears.

Questions

Is there a job guarantee?

No. No reputable school can guarantee you a job, and we won’t pretend to. What you do get: hands-on labs, a portfolio piece you can show an employer, and CV and interview coaching.

Do I need a technical background?

No. Basic IT literacy is enough. GRC is the most accessible way into security for non-technical professionals.

Which frameworks does it cover?

ISO/IEC 27001:2022, SOC 2, NIST CSF, the NDPA and GDPR, with lighter coverage of PCI DSS.

Could I lead an ISO 27001 project afterwards?

You’ll be able to contribute to and coordinate a readiness project. Leading one end to end usually takes a real engagement or two.

What’s the time commitment?

4 hours a week, including the 2-hour live class on Monday.

Ready to start Governance, Risk & Compliance?