Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

Cybersecurity for Executives & the Board

Boards are not expected to understand firewalls. They are expected to know whether the organisation has decided how much cyber risk it will carry, whether someone owns that decision, and whether the answer they were given last quarter was true. This briefing is built around the questions a director should be able to ask without technical vocabulary, the answers that should worry them, and the specific duties that Malaysian law now places on the people at the top rather than on the IT department.

Programme Agenda

Cyber Risk as a Governance Problem

Reframing security from a technical spend to a risk the board already knows how to handle. Risk appetite, tolerance, treatment and transfer, applied to a domain where the numbers feel less certain.

What Directors Are Actually Accountable For

Duties under the Companies Act, the Personal Data Protection Act as amended in 2024, and the Cyber Security Act 2024 where the organisation is a designated NCII entity. Where accountability cannot be delegated to a vendor or a CIO.

The Eight Questions to Ask Management

A working set of oversight questions covering crown jewels, third-party dependency, detection capability, backup recoverability, incident rehearsal, insurance, and the gap between the policy and the practice. Including what a satisfactory answer sounds like.

Reading a Security Report Without Being Technical

Interpreting maturity scores, penetration test summaries, patch compliance figures and incident counts. Spotting the report that has been written to reassure rather than to inform.

Deciding on Spend

Judging a security budget request when the benefit is an absence of events. Comparing proposals on risk reduction rather than product features, and recognising the controls that deliver disproportionate value.

When an Incident Reaches the Board

Escalation triggers, the board's role during a live incident versus management's, regulatory notification decisions, customer communication, and the legal privilege questions that arise early.

Third Parties, Cloud and Concentration Risk

The supplier who holds your data, the platform that runs your operations, and what happens when they are the ones breached. Contractual protections and the limits of them.

Board Simulation: A Disclosed Breach

A short scenario played out at board level. Participants take positions on notification, disclosure, customer response and public statement, then review the consequences of each choice.

Learning Outcomes:
Frame cyber risk in the same governance language the board already uses
State where director accountability sits under Malaysian law and where it cannot be delegated
Put a structured set of oversight questions to management and judge the answers
Read a security report critically rather than accepting a summary score
Assess a security investment proposal on risk reduction
Act appropriately during a live incident without displacing management
Weigh notification and disclosure decisions against regulatory and reputational exposure

Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Senior / Leadership
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Board directors, audit and risk committee members, chief executives, chief financial officers, chief operating officers and company secretaries. Chief information officers and chief information security officers sometimes attend alongside their board to align on the language used in reporting.

No. There are no configuration exercises and no product demonstrations. Technical topics appear only as far as a director needs them to interrogate a report or a proposal.

Yes. The programme is regularly condensed into a half-day board session or a ninety-minute pre-meeting briefing. The full day allows the simulation and the oversight-question workshop to run properly.

For in-house delivery we tailor the governance module to the regimes that apply to you, whether that is Bank Negara policy documents, Securities Commission guidelines, Act 854 designation, or PDPA obligations alone.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Cybersecurity