Course track
Managers & Executives
Deepens the Core track for people leaders: whaling, deepfake CEO/CFO fraud, building a reporting culture, insider-threat awareness, vendor risk, data classification, access control, and leading with security metrics.
Who takes this: People managers, directors, and executives, after completing All-Staff Core
ISOSOC2NISTCBNNDPA
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| Executive & Whaling Targeting | 4 min | Explain why leaders are higher-value targets and recognize whaling patterns. | ISO, SOC2, NIST |
| Deepfake CEO/CFO Fraud: Verifying Before You Approve | 6 min | Apply a mandatory callback or second-channel rule before approving urgent payments or access changes. | ISO, SOC2, CBN, NIST |
| Building a Reporting Culture | 4 min | Model and reward fast, blame-free incident reporting from the team. | ISO, SOC2, NIST |
| Insider Threats: Manager's Role in Early Detection Priority | 5 min | Spot behavioral warning signs and know the escalation path that protects due process. | ISO, SOC2, NIST |
| Incident Response Leadership: Your First Call in a Breach | 5 min | Know the first 3 decisions a manager must make in the first hour of a suspected breach. | ISO, SOC2, NIST |
| Vendor & Third-Party Risk Basics | 4 min | Ask the right security questions before onboarding a new vendor or tool. | ISO, SOC2, NDPA |
| Data Classification: What Your Team Handles and Why It Matters | 5 min | Identify the main data classification levels and apply the right handling rules to information your team creates, shares, and stores every day. | ISO, NDPA, SOC2 |
| Access Control and the Principle of Least Privilege | 5 min | Apply the principle of least privilege when approving, reviewing, and removing system access for your team members. | ISO, SOC2, NIST |
| Communicating Security Decisions to Your Team Without Losing Them | 5 min | Translate security policies and decisions into clear, motivating messages that your team will actually understand and follow. | ISO, NIST |
| Security Metrics That Actually Help You Lead | 5 min | Identify and interpret the key security metrics that give you a realistic picture of your team's risk exposure and help you make better decisions. | ISO, SOC2, NIST |
Compliance codes show which frameworks each module supports; they describe what the training content covers, not a guarantee of legal compliance. Confirm specific clause wording with your own compliance advisor before citing it to a regulator or auditor.