Cybersecurity challenges and compliance requirements
Your cybersecurity approach needs to connect requirements, risks and concrete actions. Use a structured framework to assess practices, identify gaps and establish priorities. Strengthen your ability to explain protection decisions and coordinate their implementation.
- Duration
- 2 days 14 hours
- Code
- GSI001FR Code
Presentation
Today's digital landscape makes cybersecurity and data compliance essential for all professionals. Mastering these complementary areas is now vital to ensure information system resilience and maintain the trust of customers, partners and colleagues. This course raises awareness of major IT security challenges and provides fundamental skills.
The programme covers cybersecurity fundamentals: key concepts, types of threats (phishing, ransomware) and identifying malicious actors. You will also study regulatory requirements relating to the GDPR and the ISO 27001 standard to understand legal obligations and integrate compliance into professional practice. Practical exercises throughout the course reinforce understanding and help you apply the concepts.
By the end of this 2-day course, you will have the essential operational skills to support your organisation's compliance and implement basic security measures. You will know how to respond effectively to incidents, becoming a key contributor to data protection.
Objectives
By the end of this introductory cybersecurity course, you will be able to:
- Understand cybersecurity threats and risks;
- identify essential legal and standards-based obligations, particularly the GDPR and ISO 27001;
- implement fundamental security measures in your workplace;
- contribute actively to your organisation's compliance with data security requirements;
- respond effectively and systematically to a security incident.
Program
Module 1: Understanding cybersecurity fundamentals
- Key definitions (cybersecurity, cybercrime and cyberattack).
- Types of threats (phishing, ransomware, malware and DDoS attacks).
- Major threat actors (hackers, insiders, hacktivists and state entities).
- Potential impacts of cyberattacks (financial consequences, reputational damage and legal implications).
Module 2: Securing your working environment
- Individual security best practices (robust password management using MFA and password managers, and identifying fraudulent emails).
- Security of mobile devices and collaboration tools (file sharing, videoconferencing and cloud solutions).
- Physical and logical security measures (premises access control, workstation locking and data backup strategies).
Practical exercises:
- Analyse a phishing email to identify its characteristics.
- Respond to a simulated security incident.
- Debrief as a group on observed errors and good practices.
Module 3: Applying the GDPR in practice
- Fundamental GDPR principles (lawfulness, fairness, transparency, data minimisation and storage limitation).
- Data subjects' rights (access, rectification, erasure and portability).
- Key organisational obligations (maintaining records of processing activities, notifying data breaches and appointing a DPO).
- Practical GDPR use cases (recruitment, human resources management and subcontracting).
Module 4: Introduction to ISO 27001:2022
- The objectives of ISO 27001 (implementing an Information Security Management System — ISMS).
- The standard's structure (security policy, risk assessment and risk treatment plan).
- Security controls recommended by ISO 27001 (access control, activity logging, data encryption and incident management).
- Links and complementarity between ISO 27001 and the GDPR.
Practical exercises:
- Identify personal data within a specific business process.
- Assess the risks associated with that data.
- Develop a compliance action plan.
Audience
This course is intended for:
- Non-technical employees who handle data or need IT security awareness.
- HR, legal and administrative managers who manage sensitive data and need to understand compliance challenges.
- IT recruiters seeking a better understanding of cybersecurity fundamentals and related roles.
- Anyone handling personal or sensitive data as part of their professional duties.
Prerequisites
This course requires the following prerequisites:
- General knowledge: familiarity with basic computing concepts and how a business is generally organised is recommended.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Comprehensive awareness of the challenges: this course helps professionals recognise major cybersecurity challenges and understand the importance of compliance requirements, particularly the GDPR and ISO 27001.
- Immediate practical application: a balanced combination of theory, concrete cases and hands-on workshops prepares participants to apply the measures and concepts directly in their workplace.
- Mastery of compliance fundamentals: develop essential skills to identify threats, apply basic security measures, contribute actively to organisational compliance and respond effectively to incidents.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en