Cyber Incident Response Management Foundation Training Course

Provided by

Enquire about this course

About the course

Cyber Incident Response Management Foundation Training Course

Learn from anywhere: get 20% off August training dates, plus selected self-paced online courses. For a limited time only. (T&Cs apply)


  • Provides a full introduction to developing a cyber incident response programme to protect your business.
  • Learn how to effectively manage and respond to a disruptive incident, such as a data breach or cyber attack.
  • Learn from anywhere – choose whether you attend our courses Live Online or in person. Find out more.
  • Our Classroom / Live Online option allows you to study your way, keeping travel and costs down to a minimum.
  • IBITGQ accredited specialist led one-day training course.
  • Successful completion of the course and included exam leads to the ISO 17024-Certificated Cyber Incident Response Management (CIRM F) qualification and 7 CPD/CPE points.

Training course outline
Cyber attacks are now classed as the top threat to organisations. With the average cost of a cyber attack being £857,000 the financial implications for businesses are not something to ignore. It’s not just the financial loss but the damage to brand and reputation that businesses need to plan for.

This course will teach you:

  • The components of the cyber kill chain;
  • How to recognise common cyber threats and understand common threat actors; and
  • How to define the structure, role and responsibilities of the cyber incident response team.

COVID-19: remote delivery options
We would like to reassure our clients that all training courses will go ahead as scheduled during the current COVID-19 situation. As a company that fully embraces flexible and remote working, we have adjusted our delivery methods to allow you to learn from anywhere. Our Classroom / Live Online delivery option enables you to attend either in person or online. Please also refer to our COVID-19 policy.

Cyber Incident Response Management Foundation training course benefits

  •  Reduce damage
  • Know how to identify the cause of an incident and reduce further damage.
  •  Learn from anywhere

Choose whether you attend Live Online or in person at one of our training venues throughout the UK.

  •  Respond faster

Participate in group discussions, practical exercises and case studies throughout the course.

  •  Communication is key

Real-world practitioners show you how to tackle cyber security from start to finish.

  •  Hands-on study

Participate in group discussions, practical exercises and case studies throughout the course.

  •  Meet reporting deadlines

Meet incident reporting deadlines of the GDPR and NIS Regulations.

See what our previous learners think about this course
100% found the trainer was engaging

100% thought the trainer had good knowledge of the subject

100% thought the trainer answered questions adequately

100% thought trainer supported individual

“I have already recommended this course to two colleagues. They are just seeking approval from training dept. for funding! This is my fourth ITG course (CISP, CISF, CISLI previously) so you must be doing something right.”

- Anonymous

Who should attend this course?
Managers who are already involved in incident management with either an information security or data protection background. Individuals with little experience who are keen to enter the field or broaden their knowledge of cyber incident management with a professional qualification. 

Business managers 
Compliance managers 
IT managers
Helpdesk managers
Project managers 
Risk managers 
Information security managers 
ISO 27001 lead auditors

Why choose IT Governance for your training needs?
We’re acknowledged leaders - in ISO 27001, information security, GDPR and business continuity management training.
Trained by industry experts – our trainers are working consultants with years of practical, hands-on experience.
Pass first time or train again for free – we have trained more than 17,000 people and we’re confident you’ll pass with us first time. If you don’t, we’ll train you again for free.*
Learn from anywhere – as a company that fully embraces flexible and remote working, we have adjusted our delivery methods to allow you to learn from anywhere. Our Classroom / Live Online delivery option enables you to attend either in person or online.
Access your training anywhere – all our course materials are provided as a digital copy, allowing you to access them anywhere and at any time. Documents will be made available 20 days before your course.
Business solutions to suit you – whether you’re a multinational wanting us to manage all your training needs or a small business wishing to boost your workforce skills, we offer a range of training solutions.


What does this training course cover?
Understand key definitions and legal requirements that underpin incident response.
Identify the components of the cyber kill chain, recognise common cyber threats and understand common threat actors.
Define the structure, role and responsibilities of the incident response team.
Comprehend the seven stages of incident response.
Propose the steps to formulate and test an incident response plan and define the scope of a business impact analysis.
Apply incident response techniques to common risk scenarios.
Know the role of cyber resilience in supporting incident response management.
Manage communications and reporting requirements under the General Data Protection Regulation (GDPR) and the Directive on security of network and information systems (NIS Directive).

Course agenda:
What is incident response management?
Cyber risk
The cyber incident response team
The cyber incident response process
The cyber incident response plan
Cyber incident response scenarios
Scenario practical exercise
Cyber resilience
What’s included in this course?
A professional training venue with lunch and refreshments;
Full course materials (digital copy provided as a PDF file);
The Cyber incident Response Management exam; and
A certificate of attendance.
What equipment do I need?
You will need a laptop for the duration of your course and exam.

Course duration and times
Day 1: 9:00am – 5.00pm

Course locations
Learn from anywhere with our instructor-led Live Online courses, or Classroom / Live Online delivery options. Learn more.
Alternatively you can study in a classroom at one of our venues in London or Ely (Cambridgeshire).
Are there any prerequisites for this course?
There are no formal entry requirements but this is a professional course. It is assumed that attendees will have a good general understanding of cyber security principles and controls that underpin the protection of confidentiality, integrity and availability of data, gained through practical experience or reading.

Is there any recommended reading?
We would recommended purchasing one or more of the following:

True Cost of Information Security Breaches and Cyber Crime
Assessing Information Security - Strategies, Tactics, Logic and Framework
Disaster Recovery and Business Continuity

Cyber incident Response Management exam
Attendees take the ISO 17024-certificated CIRM F exam set by IBITGQ
(International Board for IT Governance Qualifications). There is no extra charge for this exam.

Delivery method: Online
Duration: 60 minutes
Questions: 40
Format: Multiple choice
Pass mark: 65%
This course is equivalent to:

7 CPD points

What qualifications will I receive?
Cyber Incident Response Management (CIRM F).

This course is accredited by the International Board for IT Governance Qualifications (IBITGQ).

You can demonstrate your professional and practical knowledge and expertise by registering your qualification on the IBITGQ/GASQ successful candidate register.

Do I need to bring proof of identity?
Delegates must bring a form of photographic ID with them as the invigilator my request to check it prior to the exam.

How will I receive my exam results and certificates?
Provisional exam results will be available immediately on completion of the exam. Confirmed exam results will be issued within ten working days from the date of the exam.
Certificates for those who have achieved a passing grade will be issued within ten working days from the date of the exam.
Results notifications and certificates are sent directly to candidates by the relevant exam board in electronic format; please note that hard copy exam certificates are not issued.
Can exams be retaken?
Yes, if you are unsuccessful on the first attempt you can retake the exam for an additional fee. You can email us to schedule the retest for the exam.

Your training pathway
This course is part of our training programme. You can download your training pathway below to find your next recommended courses.

Learn from anywhere with our range of instructor-led courses
Wherever you are in the world, you can now attend an IT Governance online course, and get the full benefit of a classroom session.

To make your life as easy as possible, we offer 3 ways to attend an instructor-led course:

Our instructor-led courses are hosted at professional training centres located in major cities across the UK.

Live Online
Our instructor-led Live Online courses are hosted and delivered live by one of our expert trainers.

Learn from anywhere
Our instructor-led Classroom / Live Online courses give you the flexibility of attending a classroom course, either in person or by joining the classroom course online.


The benefits of learning from anywhere
Choosing an online option means you save on travel, parking, hotels and other fees.
Learn and obtain a professional certification from the comfort of your home.
Our courses use the latest conferencing technology that is compatible with all devices.
Our trainers focus on maximising audience participation and getting the most out of our online attendees.
All trainers have been hand-picked for their technical and practical expertise.
You have full control over your course booking, meaning you can edit delegate details, course dates and any special requirements.
Our Classroom / Live Online courses give you the full experience of a classroom course, whether you attend in person or to join the classroom online from your home or office.


Start date Location / delivery
09 Feb 2021 Online

Related article

For those looking to reskill into a new career sector, cyber security is an attractive option. We are becoming increasingly reliant on technology