Intermediate · 10 weeks
Governance, Risk & Compliance
Where cybersecurity meets the business, with no coding required.
- Live online, from anywhere
- 10 weeks
- A 2-hour live class every Monday
- 4 hours a week
- Next cohort: 15 January 2027
Who it’s for
- Career switchers. From audit, law, finance or operations, moving into security through GRC.
- IT and security practitioners. You want to grow from technical work into programme and audit leadership.
- Compliance and risk officers. You want to specialise in information security frameworks.
Who it isn’t for
- You want hands-on technical or offensive work: Ethical Hacking or Security+ fit better.
Before you start: Basic IT literacy. No coding. Experience in audit, risk, compliance, law or operations is a plus.
What you’ll build
A full ISO 27001 or SOC 2 readiness plan, with a risk register and treatment plan, presented as you would to a board.
Curriculum
10 modules, 10 weeks
Ten weeks on building security programmes, running risk assessments, preparing organisations for audit and explaining technical risk to the people who make decisions.
01Foundations of GRC
- What GRC means
- The three lines of defence
- The business value of security
- GRC in Nigeria and abroad
02Governance and security programmes
- Building a programme from scratch
- Committees and reporting lines
- Roles, responsibilities and RACI
- Reporting to a board
03Risk management
- Identifying and scoring risk
- Qualitative and quantitative risk
- Building a risk register
- Treating risk
04ISO/IEC 27001:2022
- ISMS scope and context
- The Statement of Applicability
- Annex A controls
- Stage 1 and Stage 2 audits
05SOC 2 and NIST CSF
- Trust Services Criteria
- Type 1 and Type 2 reports
- NIST CSF functions
- Mapping controls across frameworks
06Data protection: NDPA and GDPR
- Data subject rights
- DPIAs and records of processing
- Cross-border transfers
- Breach notification
07Policies and awareness
- Policies people follow
- Procedures and standards
- Awareness programmes
- Phishing simulations
08Third-party risk
- Vendor questionnaires
- Security clauses in contracts
- Ongoing monitoring
- Supply chain risk
09Audit readiness
- Collecting evidence
- Working with auditors
- Managing findings
- Continuous compliance
10Capstone: readiness plan
- An ISO 27001 or SOC 2 readiness plan
- Risk register and treatment plan
- An executive presentation
- Portfolio deliverables
Get the full syllabus
Every module, lab and tool as a one-page PDF. Enter your email and it downloads straight away.
How you learn
A week on the track
Live classes
A 2-hour live class every Monday. The time is confirmed when you enrol.
Mentor hours
Small-group office hours with a practising security engineer, every week
Labs
A hands-on lab every week
Tools
Risk registers in Excel, Policy libraries in Notion or Confluence, Jira for audit tracking, Compliance platforms (Vanta, Drata) in concept
Two kinds of lab: guided labs in our cloud environment, with nothing to install, and some virtual-machine work on your own laptop. We help you set the virtual machines up.
- MonLive class2-hour instructor-led session with real-world examples
- TueGuided labHands-on lab in our cloud environment
- WedMentor hoursSmall-group office hours with a practising security engineer
- ThuSolo challengeA timed challenge to lock in the week’s concepts
- FriCTF FridayTeam capture-the-flag with a leaderboard

$ nmap -sV -Pn 10.10.20.0/24Nmap scan report for dc01.lab.learncyber (10.10.20.10)88/tcp open kerberos-sec Microsoft Windows Kerberos389/tcp open ldap Microsoft Windows AD LDAP445/tcp open microsoft-ds$ GetUserSPNs.py lab.learncyber/analyst -request[*] 3 service accounts with SPNs found$ hashcat -m 13100 tickets.txt wordlist.txtsvc_backup: cracked (weak password)
Exam and certificate
There’s no external exam built in. You finish with a LearnCyber certificate of completion and a readiness plan for your portfolio.
Certificate, not certification
You receive a LearnCyber certificate of completion. It proves you completed the track, and employers can check it online. A certification is awarded by an exam body such as CompTIA.
What you’ll need
- Laptop
- A laptop with at least 8 GB of RAM and a stable internet connection
- Internet
- A connection that can hold a video call; every class is recorded if yours drops
- Time
- 4 hours a week, including the 2-hour live class
Who teaches
Taught by Hackrowd Technology’s working penetration testers, the team that does this work for clients.
Offensive security
Penetration tests of web apps, APIs, networks and Active Directory for client organisations.
Security operations
SOC work: monitoring, detection and incident response.
Governance and audit
GRC programmes and ISO 27001 audits.
After the track
- Step 1
Train
Live classes, labs and your capstone.
- Step 2
Internship
A three-month internship after the training.
- Step 3
Certificate and letter
A certificate of completion employers can verify, and a recommendation letter.
Admissions
Three steps to your seat
- Step 1Join a free webinar
Meet an instructor and ask anything first.
- Step 2Apply
A short questionnaire, not a test, so we can recommend the right track.
- Step 3Reserve your seat
Pay in full or in instalments. Your place is confirmed when the payment clears.
Questions
Is there a job guarantee?
No. No reputable school can guarantee you a job, and we won’t pretend to. What you do get: hands-on labs, a portfolio piece you can show an employer, and CV and interview coaching.
Do I need a technical background?
No. Basic IT literacy is enough. GRC is the most accessible way into security for non-technical professionals.
Which frameworks does it cover?
ISO/IEC 27001:2022, SOC 2, NIST CSF, the NDPA and GDPR, with lighter coverage of PCI DSS.
Could I lead an ISO 27001 project afterwards?
You’ll be able to contribute to and coordinate a readiness project. Leading one end to end usually takes a real engagement or two.
What’s the time commitment?
4 hours a week, including the 2-hour live class on Monday.
Ready to start Governance, Risk & Compliance?