Cyber Governance Training
Resources to enable Boards to govern cyber risks with confidence.
Cyber security incidents can have a huge impact on an organisation in terms of cost, productivity, reputation, loss of customers and legal implications. Cyber resilience is about being prepared for an inevitable cyber security breach and Boards have a critical role, and accountability, in cyber governance.

By actively engaging, Boards can strengthen their organisation's ability to prepare for, respond to, and recover from cyber security incidents. By actively engaging, directors can ensure their organisation is equipped to anticipate threats, mitigate risks, and effectively manage incidents when they occur.
About the Training
The NCSC has created five interactive training modules aligned with the principles of the Cyber Governance Code of Practice. Developed with insights from industry Non-Executive Directors and government subject-matter experts, these modules are designed to meet the needs of Boards. They support Boards and Directors in understanding the principles of the Code and putting its recommended actions into practice, helping to improve their organisation's cyber resilience, without delving into the technical detail.
The training begins with an introductory module that outlines the purpose of the Cyber Governance Code of Practice, why cyber governance is important for Boards, and how it can support them to effectively govern cyber risks within their organisation.

It is followed by five modules, each covering one of the Code of Practice principles. Each module should take approximately 20 minutes to complete and all 5 don’t need to be completed in one session. Each module includes:
- An overview of the principle
- The Cyber Governance Code of Practice actions under that principle
- The learning outcomes that are expected to be achieved following completion of the module
- A short video covering a use-case or scenario
- Five multiple-choice questions
- A final overview and a printable PDF summarising the key points
- A link to relevant NCSC resources
Board members don’t need to be cyber experts, but understanding key governance principles is essential for ensuring your organisation’s resilience.
Get started with the training modules
Get in touch
The NCSC is committed to helping Non-Executive Directors and Directors govern cyber risk and build cyber resilience within their organisations. If your organisation would like to integrate this training into its own platform, please email [email protected]. The package is completely free to use; we only require a simple licence agreement.
We hope you’ve found this training valuable and welcome any feedback. If you’d like to share your thoughts, please email [email protected].





