IT Risk Masterclass

Grip on IT risks, control measures, and critical systems.

IT Risk in a nutshell

IT plays an increasingly significant role in internal control. At the same time, dependencies, complexity, and risks are increasing, partly due to cloud solutions, outsourcing, and an ever more integrated IT landscape.

Many risk professionals recognize the challenge: you are responsible for judgment, but sometimes lack the overview or the tools to properly understand IT risks and translate them into concrete controls.

This masterclass helps you pragmatically and structurally map IT risks, assess control measures, and engage in discussions with IT and suppliers with more confidence.

What do we offer?

After this masterclass, you will master the fundamentals of IT Risk. Included:

In your Risguard Digital Goodie Bag

A digital backpack with immediately applicable templates from our own audit and compliance practice:

  • IT Risk Register with Sector Examples
  • Application Register with Criticality Matrix
  • Supplier Assessment Model including ISAE Scorecard
  • ITGC test matrix with sample controls
  • IT Risk Board Reporting (Template)
  • Cheat sheet “Four steps to map critical applications”

Templates are maintained. Alumni get access to new versions when we publish them.

Who is this training intended for?

  • Risk Managers and Compliance Professionals
  • Internal auditors (with or without an IT background)
  • Audit managers who want to better manage IT risks
  • Professionals involved in IT governance and vendor management

Our approach

How we work

The IT Risk masterclass is taught by experienced professionals in audit, risk, and compliance. No dry theory here. Instead, you'll get real cases and examples from our daily practice, showing exactly where organizations go wrong with IT risks, supplier management, and critical applications. Based on this practical experience, we provide focused direction rather than a general overview.

We prefer to work in compact groups of 5 to 15 professionals. Small enough to allow for questions, discussion, and individual challenges. Large enough to bring together different sectors and perspectives.

What can you implement immediately tomorrow?

That is the question that is central all day. We practice the material with workshops, simulations, and practical assignments, so that you not only understand how IT risks, control measures, and critical applications work, but can also directly translate that to your own organization. Capability building over knowledge transfer.

Our focus remains the same: concrete, practical, and directly usable.

Concrete · Practical · Directly usable

Interested in a masterclass? Get in touch.

Recognizable practical challenges

IT is perceived as complex and difficult to understand

Insufficient visibility into critical applications and dependencies

IT suppliers are a 'black box'

Difficulty prioritizing IT risks and translating them into impact

Uncertainty about what constitutes 'sufficient control'

What are you learning?

Module 1. IT Developments and Risks (incl. IT Supplier Management)

In addition, we will focus on IT supplier management based on four key questions:

  • When is a supplier critical?
  • What risks remain with you as an organization?
  • How do you assess ISAE reports and SLAs?
  • What do you record at a minimum in contracts?
Module 2. Mapping Critical Applications and Risks

We are working with a concrete action plan:

  1. Determine the main business processes
  2. Link applications to processes
  3. Determine critical applications
  4. Identify risks per application
Module 3. Implementation of IT Control Measures

Topics we're covering:

  • Access control
  • Change Management
  • IT Continuity Management (backups, monitoring, incident management)

The action plan: mapping critical applications

In Module 2, we work with a concrete action plan that you can directly apply to your own organization. Each step delivers a work product that can be reused for audit, risk, and business continuity.

The four steps
Step 1
Determine the main business processes
Step 2
Link applications to processes
Step 3
Determine critical applications
Step 4
Identify risks per application

Results after completion

What you take away after a half-day masterclass.

Check mark
Understanding the IT risk landscape
Check mark
Ability to identify critical applications
Check mark
Better understanding of IT vendor risks
Check mark
Concrete handles for control measures
Check mark
Practical application of BIAs
Check mark
More grip and confidence in IT risk issues

Practical information

Where
On-site or in-company training
When
Upon request
Duration
half a day
Costs
From €295 p.p.

Interested?

Contact Risguard, we're happy to brainstorm with you.