Cyber Security Manager

The Cyber Security Manager is responsible for cyber security as a whole. You will learn how to manage security situations, ie managing risks, threats and "switching" from a reactive position to proactive actions. The role is not compatible with the roles responsible for the operation of the information and communication system and with other operational or management roles.

Would you like to compare to other courses?

Virtual Training or e-Learning?

We offer flexibility. You can choose from our selection of in-class courses as well as online courses.

Try a live virtual course

Target audience

Cyber Security Manager §181 / 2014 Coll.

According to the law, he is responsible for the design and implementation of security measures within the organization. This course ends with a certification exam and meets all the requirements of the Cyber Security Act. The graduates of the course thus duly fulfilled the legislative obligation of ZoKB.

In practice, the ISMS manager is a kind of intermediate step between the top management - the cyber security management committee (strategic management level) and the operational level.

Duties and tasks of the information security manager:

  • Implements the necessary security measures;
  • Supervises the fulfillment of the tasks set out in the risk management plan;
  • It monitors the effectiveness of the measures and discusses the results with the committee;
  • Informs the Cyber Security Committee about incidents, disagreements;
  • Prepares documents for safety review by the organization's management.
Grant Thornton Manažerka Kybernetické Bezpečnosti Eliška Houhová

Aims of the course

  • To learn the risk analysis according to Annex No. 1 of Decree 316/2014 Coll.
  • Save costs associated with the implementation of the requirements of the law
  • Show the methodology for a cybernetic manual for organization management
  • Execution of a list of assets (primary and ancillary) for IS that are regulated by CSA
  • Obtain a qualification for the performance of the role according to CSA 181 / 2014 Coll.
  • Implement administrative, procedural and management measures (management of the ZoKB project)
NIS2 ZKB NUKIB education kit

Agenda

09:00 - 10:30

ISMS according to Cyber Security Act

Determination of scope, assets Safety documentation Organizational and technical measures Security policy

Policy development Compliance with Act 181/2014 Coll.

10:30 - 10:45

Coffee Break

10:45 - 12:15

Risk management

Risk management plan, measures Declaration of applicability Criteria for threats and vulnerabilities Org. safety

Determining roles Responsibilities Manager, Auditor, Architect

12:15 - 13:15

Lunch

13:15 - 15:00

Security requirements

Supplier audit Requirements analysis The role of suppliers, IS operation Asset management

Identification Records, links, activities 15:00 - 15:15

Coffee break

15:15 - 16:00

Conclusion

Summary Questions, tips

16:00 - 17:00

Exam

Certification

The Cyber Security Manager is responsible for cyber security as a whole. You will learn how to manage security situations, ie managing risks, threats and "switching" from a reactive position to proactive actions. The role is not compatible with the roles responsible for the operation of the information and communication system and with other operational or management roles.

  • Block duration 90 minutes
  • Hours 16 hours
  • Refreshments Yes
  • Exam Yes
  • Prerequisites

    Basic knowledge of ISMS (Information Security Management System) according to ISO / IEC 2700

Certification

Cyber Security Manager | ISO 17024 accreditation

Rozhodnutím NÚKIB č. j. 8679/2026‑NÚKIB‑E/620

Certification exam

Preparatory course including certification, which is defined by Decree No. 82/2018 Coll.

The certificate proving the professional competence of security roles meets the requirements of ISO 17024, which is defined by Decree No. 82/2018 Coll. on security measures, cyber security incidents, reactive measures, filing requirements in the field of cyber security and data disposal (Decree on Cyber Security)

As part of the certification, they must demonstrate practical knowledge and skills to implement the ISMS (Information Security Management System) so that it meets legislative requirements and at the same time is in accordance with the ISO / IEC 27001 standard in the current valid version.

Test information

  • Number of uestions: 30
  • Pass mark: 60%
  • Certificate validity: 3 years
  • exam language Czech

More info about certification >

Manažer Kybernetické Bezpečnosti NÚKIB NIS2 ENISA
NIS2 Certified CyberSecurity Manager

Jan Cuřín

Graduate of ČVUT FEL, subsequently a consultant with an international dimension in the field of implementation and optimization of the information management system (ITSM) and cyber (ISMS) security. He applies the acquired experience from the position of an accredited Lead Auditor in the areas of IT Service Management, ISMS and GDPR.

  • Cyber Security standard author
  • Lead Auditor ITSM ISO 20000, ISMS ISO/IEC 27001
  • Approved Trainer & Lead Auditor GDPR (EU 2016/679) dle ISO/IEC 17067

Lucie Petrová Balýová

ISO 27001 Auditor | NIS2 compliance | IT právo

Advokátka s více než desetiletou praxí IT práva, auditů kybernetické bezpečnosti, implementace EU Cyber Security nařízení jako NIS2, DORA, CRA a další. Vede pracovní skupinu pro standardizaci rolí dle ECSF (European Cybersecurity Skills Framework), EU regulace NIS2 a zákona č. 264/2025 Sb., vč. vyhlášek.  Aktivně se podílí na vzdělávání organizací, které spadají do kategorie „povinných osob“. Lucie vám pomůže více než „splnit zákon“, ale budovat reálnou kybernetickou odolnost a právní jistotu v prostředí rostoucích hrozeb a nových evropských nařízení.

Vít Lidinský

  • Since 2012, he has been working as a forensic expert in the field of economics, prices and estimates, with a special specialization in information systems and personal data protection.
  • For more than 5 years he was the head of the department. and Chief Executive Officer at the Ministry of Informatics, the Ministry of Foreign Affairs of the Czech Republic and the State Treasury Shared Services Center (ICT Departments).
  • He graduated from the Faculty of Business and Economics, majoring in information management - CULS. Here he gradually obtained a master's (Ing.) And doctoral degree (Ph. D.)

Vyhláška č. 409/2025 Sb. ukládá manažerovi povinnost pravidelně informovat vrcholné vedení o stavu systému řízení bezpečnosti informací. Governance agent tuto povinnost mění z celodenní přípravy na kontrolu hotového podkladu: průběžně sbírá metriky ISMS, eviduje stav bezpečnostních opatření a nápravných úkolů, hlídá kalendář povinností (přezkoumání vedením, revize dokumentace, školení) a z těchto dat skládá pravidelnou zprávu pro vedení.

Současně monitoruje publikace NÚKIB a ENISA a upozorňuje na změny s dopadem na ISMS. Záměrně přitom nezasahuje do provozu technických aktiv: přesně v logice § 5, který výkon role manažera od provozních rolí odděluje. Manažerovi zůstává to podstatné: interpretace stavu, priority a rozhodnutí o riziku.

Největší část auditu netvoří úsudek, ale sběr a třídění důkazů. Evidence agent před auditem shromáždí a katalogizuje dokumentaci, záznamy a exporty konfigurací, namapuje je na požadavky vyhlášky č. 409/2025 Sb. a ISO/IEC 27001 a připraví checklisty i návrh vzorkování. Během auditu strukturuje zjištění, po auditu hlídá termíny nápravných opatření a připravuje podklady pro follow‑up; při opakovaném auditu sám upozorní na rozdíly oproti minulému stavu. Závěry, klasifikace zjištění a nezávislý úsudek zůstávají výhradně auditorovi: agent připravuje důkazní bázi, nikdy hodnocení.

Architektura zastarává tempem, jakým se mění infrastruktura pod ní. Blueprint agent udržuje živou mapu aktiv, vazeb a datových toků, nepřetržitě porovnává skutečnou implementaci s cílovou architekturou a hlásí drift dřív, než se z něj stane zranitelnost. 

Sleduje CVE* relevantní pro technologie v architektuře, kontroluje nové návrhy proti bezpečnostní baseline a udržuje dokumentaci architektonických rozhodnutí. Architekt tak netráví dny inventurou stavu, ale návrhovými rozhodnutími a posuzováním dopadů změn: tedy prací, kterou za něj žádný systém neudělá.

* CVE = Common Vulnerabilities and Exposures. Jde o mezinárodní, veřejně dostupný seznam známých kybernetických zranitelností (bezpečnostních děr) v softwaru a hardwaru.

Graduate ratings

Excellent review from 444 reviewers

What makes our references exceptional? They are not one-off events. Clients come back to us regularly.

  • Libor Čech
  • 01.04.26

Skvělé.

  • Miroslav Hranitský
  • 01.04.26

Doporučuji.

  • Antonín Kovář
  • 01.04.26

Velmi dobře zpracovaný obsah a vysvětlení nové legislativi

  • Vladimír Fiala
  • 01.04.26

skvěle 

  • Radek Nekvasil
  • 01.04.26

Až na hlučnou klimatizaci skvělé

  • Petr Huška
  • 01.04.26

Skvěle

  • Zdrážilová
  • 01.04.26

Dobré

  • Tomáš Hubený
  • 01.04.26

Dobré

  • Petr
  • 01.04.26

Kvalitně zpracovaný obsah

  • Elena P.
  • 24.02.26
  • iXperta

Dobrý, možná pro někoho rychlé, ale pro mě ne. Na dotazy bylo skvěle odpovězeno - školitelka se vyznala.

View the next 10 reviews of our graduates

View the full list of reference clients.

Your rating
*****

Not sure if this is the right courese for you? Get in touch!

For assistance please give us a call.

We are available at +420 222 553 101 Always Monday to Friday: 9am - 5pm.

*items marked with an asterisk are mandatory

Would you like a gift for your birtday?