Risk Management in IG
Effective risk identification and risk management are not just best practices for organisations; they are obligations under GDPR and the Data Protection Act 2018 to demonstrate accountability, ensure data security and safeguard data subjects’ rights.
A robust risk management process helps identify vulnerabilities, reduces the likelihood of data breaches, helps complete DPIAs and provides evidence of GDPR compliance. Unfortunately, the GDPR is silent on how organisations should assess and quantify risk, which means information governance professionals have to consider generic guidance from other sectors.
In this workshop you will gain critical insights and practical tools to identify, assess, and mitigate information risks in your organisation. Designed for information governance professionals, it delivers actionable strategies, real-world examples, and expert guidance to strengthen your risk posture and support compliance.
By the end of the workshop, you will be able to map information assets, threats, and vulnerabilities to assess real-world risks, produce a risk register tailored to your organisation, make informed decisions on mitigating or accepting specific risks and begin embedding a risk aware approach in daily operations, projects, and strategic planning.
Key Topics
- The role of risk management in data protection compliance
- Key frameworks (ISO 27005, NIST RMF, FAIR)
- Identifying and assessing risks
- The 5 risk management steps
- Identifying threats and vulnerabilities
- Assessing severity and likelihood of risk
- Risk response strategies
- Selecting effective controls
- Applying a risk matrix
- Identifying risk appetite
- Planning and implementing controls
- Risk reporting and culture
Dates & Cost
Online
£449 plus VAT
Classroom
£499 plus VAT
Timings: 10am to 4pm
Course tutors
All our associates are experienced information governance professionals who have been training and advising in this field for many years.
What our clients say about us
I would highly recommend the GDPR Practitioner Course. The Tutor was extremely knowledgeable and gave plenty of chance for group conversation or individual questions. A great course for anyone wanting to expand their knowledge of GDPR and understand putting the principles into practise.
SL, BCH
I would highly recommend the GDPR Practitioner Course. The Tutor was extremely knowledgeable and gave plenty of chance for group conversation or individual questions. A great course for anyone wanting to expand their knowledge of GDPR and understand putting the principles into practise.
SL, BCH
I learned so much! The course was just the right balance of theory and practical, and was very well delivered.
CB, CHAS
The course was very useful as an IG Officer. The trainer was knowledgeable and explained some complex aspects of the legislation using interesting examples and real life scenarios. As a refresher, even with lots of work experience behind me, it was very useful to undertake the Practitioner course. The course materials and handbook are invaluable and I know I will re-use them in conjunction with my usual resources.
NC, Lincolnshire County Council
A very practical and all-encompassing coverage of the UK GDPR provided over 4 days. Although 4 days is not enough time to cover this whole subject in depth, there was just enough covered with further resources and links provided within the sessions to cover all aspects of the GDPR to a level at which I now feel a lot more confident in my role. Thank you, Kirsty!
SW, Norwich University of the Arts