CyBe AI Summit 2026 — NIMHANS Convention Centre, Bengaluru — 4 Sep 2026Learn more
CAISO·Intermediate

Certified AI Security Officer

You already run the security function. What you have not been tested on is the boardroom — defending a budget to a CFO who wants a number, translating risk into language a CEO will act on, and owning the decision when a ransomware attacker gives you an hour to answer. CAISO runs that tenure end to end, against one continuous executive cast, then puts you through two live crisis simulations where the wrong call has a five-year cost.

Curriculum reviewed by 13 independent security and governance leaders from the CSA Bangalore network.

9 modules

Six leadership frameworks plus three live crisis simulations

$20M

Ransomware boardroom simulation — five roles, five stages, one deadline

Practitioner-level

Certification, human-graded not auto-scored

Leader-built

For team leads, security managers and aspiring CISOs — not implementers

Built on the frameworks

The SABSA InstituteSABSA
The Open Group / FAIR InstituteFAIR
NISTNIST CSF
ISO/IECISO 27001
Microsoft / VerSpriteSTRIDE / PASTA
European UnionEU AI Act
₹19,999₹33,500

40% off the release price. Five live 2-hour evening sessions plus a full-day Saturday immersion, taught virtually with international coverage. Includes all assignments, labs and the certification assessment.

A CISO was criminally convicted in 2022 for how a breach was handled, not for the breach itself. Most security leaders have never rehearsed that boardroom — next cohort starts soon.

Register for the CohortSee the CAIGL Programme

This was a different learning experience altogether… I recommend this learning methodology to every learner.

Pravinkumar Jha, Head of Product and Cloud Security

This course includes

  • Five live 2-hour evening sessions plus a full-day Saturday immersion
  • Run online with international coverage — join from any timezone
  • All 9 modules taught live: six leadership frameworks plus three live crisis simulations
  • Assignments and hands-on labs between sessions, reviewed by the faculty
  • 40 MCQs + 8 written responses, human-reviewed
  • AI implications built into every module
  • Joins from any device — sessions are recorded for the cohort

Why This Course

You already run a security function. CAISO is where you rehearse the part of the job nobody trains you for: defending a budget to a CFO who tests every number, translating a technical risk into a decision a CEO will actually make, and knowing exactly where personal liability lands when a regulator calls. One continuous scenario runs across all nine modules — the same CFO, CEO, General Counsel and mentor CISO recur and escalate, so a boardroom skill you build in Module 4 is the one you are tested on again in the live crisis simulations.

Work back from the business, not the tools — apply SABSA’s six layers from context down to operations, including where AI changes the architecture.
Threat-model at enterprise scale with STRIDE and run PASTA’s seven stages to focus on adversary goals, not component lists.
Baseline a security programme against CMMI, NIST CSF Tiers or C2M2, and build a 90-day roadmap that earns board confidence in the first quarter.
Translate technical risk into a one-page, four-quadrant board brief a CEO and a CFO will act on — not a slide deck of vulnerability counts.
Quantify a risk in financial terms with the FAIR model and build the ROI case a CFO cannot wave away.
Know exactly where personal liability lands, post-Uber conviction, and build the decision-documentation habit that protects you.
Run a shadow AI discovery audit, build an AI Tool Register, and draft a 5-pillar Acceptable Use Policy mapped to the EU AI Act and GDPR Art. 22.
Lead a live $20M ransomware response from one of five executive seats, and defend the pay-or-not-pay call under a hard deadline.
Run a five-stage adversarial AI incident end to end — identification through post-incident governance reform.

Built around: SABSA · STRIDE & PASTA · FAIR · NIST CSF · ISO/IEC 27001 · EU AI Act

Skills You’ll Gain

SABSASTRIDE at ScalePASTA MethodologySecurity Maturity Models90-Day CISO RoadmapBoard CommunicationFAIR ModelVendor Risk ManagementKPIs & KRIsCISO Personal LiabilityShadow AI DiscoveryAI Acceptable Use PolicyEU AI ActLive Crisis SimulationAI Incident Response

Who Should Attend

👔

Team Leads

Technical or operational leads ready to take on programme-level ownership and board-facing responsibility for the first time.

🛡️

Security Managers

Managers running a security function day to day who need the architecture, budget, and communication frameworks a CISO role demands.

🎯

Aspiring CISOs

Anyone deliberately building toward a CISO or Head of Security title, including from an adjacent function like IT or risk.

Curriculum

5 modules · 33 lessons

Evening 1

Enterprise Security Architecture + Enterprise Threat Modelling

SABSA’s six layers from business context down to operations, then STRIDE and PASTA at enterprise scale — Diane sets the tenure’s framing on day one

You learn SABSA’s six architectural layers and how each answers a different business question, plus the core principles — defence in depth, least privilege, security as an enabler rather than a list of prohibitions — and where AI changes the architecture. Diane opens the tenure here: work back from the business, not the tools. Then you apply STRIDE across all six threat categories at enterprise scale, and run PASTA’s seven stages to build a risk-centric model focused on adversary goals rather than component checklists — including AI as both a new threat actor and a new threat-modelling tool.

Skill: Think in architectures, not just controls, and threat-model at the scale a real enterprise actually presents

40 min content · 6 lessons

Evening 2

Building and Managing a Security Programme + Board Communication

Maturity models and the 90-day CISO roadmap, then the one-page board brief — Sandra’s counsel and the board scene where Marcus and Priya both weigh in

You learn to baseline a programme against CMMI, NIST CSF Tiers and C2M2, choose the right model for board reporting versus internal management, and build a 90-day roadmap that shows quick wins while laying real foundation. Sandra’s counsel lands here: don’t announce changes before you understand the org. Then you learn to translate technical risk into business language, structure a one-page four-quadrant board brief, and pick 3-4 metrics a board will actually act on — tested live in the board scene, where Marcus challenges the numbers and Priya watches the liability.

Skill: Build a programme that survives contact with a board, and defend it in the room

40 min content · 6 lessons

Evening 3

Security Budget, ROI, Vendor Management + Metrics, Regulatory Engagement

The FAIR model against Marcus’s ROI pushback, then KPIs, KRIs and the personal-liability peak with Priya, Sandra, and the regulator

You learn to quantify risk in financial terms with the FAIR model — Annual Loss Expectancy, the case for investment — against Marcus’s set-piece skepticism ("we have never had a ransomware attack, so the frequency is zero"), then structure a Run/Change/Leap budget and score vendor RFPs against a fixed framework, including AI vendor due diligence. You then design a KPI/KRI programme using the five-element metric standard, and reach the tenure’s liability peak: engaging regulators without converting a civil matter into a criminal one, and understanding personal CISO liability after the 2022 Uber conviction — with Sandra’s "I have sat where you are sitting, in front of the SEC."

Skill: Make the financial case a CFO cannot wave away, and know exactly where liability lands before you need to

40 min content · 6 lessons

Evening 4

The Shadow AI Reckoning + The Ransomware Boardroom Game

A discovery audit becomes an AI Tool Register and Acceptable Use Policy, then a live 5-role, 5-stage boardroom simulation of a $20M ransomware attack

You run a shadow AI discovery audit using proxy logs, expense reports and department interviews, convert the findings into an AI Tool Register, and draft a 5-pillar Acceptable Use Policy — resisting the ban instinct, since a blanket ban only manufactures ungoverned shadow IT. You map the estate to the EU AI Act risk classes and GDPR Article 22. Then the tenure turns live: TechNovaCloud has been hit by a $20M ransomware attack, and you play CEO, CIO, CISO, Head of Legal, or an external consultant through five stages — identification, containment, analysis and the pay-or-not-pay decision, eradication, and recovery — under a hard deadline and real OFAC-sanctions stakes.

Skill: Answer a regulator who asks what AI you actually run, then lead a live incident response in role, under real time pressure

70 min content & live simulation · 8 lessons

Immersion Day

The Poisoned Matrix: AI Security War Room + Certification

CAPSTONE

A five-stage adversarial AI incident at NimbusMind, run from five executive seats, then the certification assessment: 40 MCQs plus 8 written responses, human-graded

The tenure closes with its highest-stakes scenario: an adversarial AI compromise at NimbusMind, run live from five executive seats through identification, containment, the pay-or-resist decision, eradication, and post-incident governance reform. You sequence the first hour so containment does not destroy the forensic evidence eradication depends on, weigh pay-or-resist against sanctions exposure and an unverifiable deletion guarantee, and trace the incident to its root cause in the AI supply chain rather than patching posture generally. The day closes with the certification assessment: 40 scenario-based multiple-choice questions plus 8 written leadership responses — board memos, budget cases, incident summaries — graded by a senior practitioner, not auto-scored.

Skill: Run an AI security incident end to end under fire, then prove the judgment behind it under assessment

90 min live simulation + certification assessment · 7 lessons

Upcoming cohort dates

The same leadership content delivered as a facilitated CAISO cohort, run in executive cabinets of four with two live boardroom crisis simulations. ₹19,999 per seat, down from ₹33,500. One cohort, run with international coverage at the request of our global members: five 2-hour evening sessions Monday to Friday, then a full-day Saturday immersion.

November–December 2026 cohort

Online — international coverage

5 sessions · 18:00–20:00 IST

  1. Mon 30 Nov
  2. Tue 1 Dec
  3. Wed 2 Dec
  4. Thu 3 Dec
  5. Fri 4 Dec
Sat 5 DecImmersion day11:00–16:00 IST

Cabinets are capped at 24 participants per cohort, because the live boardroom simulations depend on that structure. Private cohorts for a single leadership team run on a date of your choosing.

What backs this up

The specifics behind the claims on this page. Open any of them for the detail.

  • Scenario-based multiple choice

    40 questions set in situations a security leader actually faces.

  • Eight written leadership responses

    Board memos, budget cases and incident summaries, graded by a senior practitioner on judgment and defensibility.

  • Pass mark 75%

    Earns the CAISO practitioner-level certification.

How You’ll Be Certified

1

Learn

Attend all nine modules taught live across five evening sessions and the Saturday immersion. Six pair a leadership framework — SABSA, STRIDE/PASTA, maturity models, board communication, FAIR, KPIs/KRIs — with what changes once AI and personal liability are in the picture, and set an assignment to apply it. Three run as live boardroom crisis simulations: the Shadow AI audit, a $20M ransomware attack, and a five-stage adversarial AI incident.

5 evenings + immersion day

2

Live the Scenario

One continuous narrative tenure runs across all nine modules — the same CFO, CEO, General Counsel and mentor CISO recur and escalate, so a skill you build translating risk to the board in Module 4 is the one you are tested on live under fire in the crisis simulations.

One executive cast, nine modules

3

Assess

Sit the CAISO certification assessment: 40 scenario-based multiple-choice questions set in situations a security leader actually faces, plus 8 written leadership responses graded by a senior practitioner, not auto-scored.

40 MCQs · 8 written responses

4

Certify

Score 75% or above to earn the CAISO certification — a practitioner-level credential demonstrating executive-level security leadership capability, awarded on judgment a human reviewed.

Pass mark: 75%

Frameworks and standards this programme is built on

CAISO is a practitioner-level credential in its own right, not exam preparation. These are the frameworks the nine modules teach and apply directly — the same ones your board, your auditors and your regulator already use, so the vocabulary you leave with is theirs rather than ours.

The SABSA Institute

SABSA Enterprise Security Architecture

The layered architecture model used in Module 1 to design security from business drivers down to implementation.

The Open Group / FAIR Institute

FAIR — Factor Analysis of Information Risk

The quantification model behind the budget module — how a risk becomes a number a board and a CFO will argue with.

NIST

NIST Cybersecurity Framework

One of three maturity models used to baseline a programme and structure the 90-day roadmap.

ISO/IEC

ISO/IEC 27001

The management-system standard your programme will be audited against, referenced throughout the programme and metrics modules.

Microsoft / VerSprite

STRIDE and PASTA threat modelling

Applied at enterprise scope in Module 2, including AI as both threat actor and threat-modelling tool.

European Union

EU AI Act

Risk classification for the Shadow AI Tool Register, and where CISO personal liability actually lands.

Framework and standard names are the property of their respective owners and are used here only to identify what this curriculum teaches. CyBe Global is not affiliated with, endorsed by or accredited by any of these bodies, and this programme is not an official preparation course for any of their certifications.

Faculty for This Course

Satyavathi Divadari

Satyavathi Divadari

CEO & Founder · CyBe Global / CSA Bangalore

Madhukeshwar Bhat

Madhukeshwar Bhat

Academia Advisor · CSA Bangalore Chapter

Course Advisors

Practising security leaders who review this curriculum and keep it current.

See all 13 advisors →

R S Lakshminarayanan

GM & Regional CISO · Wipro Limited

Shobha Jagathpal

Managing Director · Morgan Stanley

Ashish Shrivastava

Director – Cyber Security · Honeywell

Ravi Subbiah

Managing Partner · TCS Ltd

What Learners Say

This was different learning experience all together. So much fun and so much to learn. The energy was continuously high to know what’s next. Not just regular content but every time something new and different. I recommend this learning methodology to every learner.

PJ

Pravinkumar Jha

Head of Product and Cloud Security

That sounds like such a refreshing change from usual conferences. Learning through music and teamwork really makes complex concepts stick in a fun way.

RP

Rohan Pinto

CTO and Founder, 1Kosmos

Frequently Asked Questions