
Cyber Security for Leaders and Decision Makers
Cyber incidents rarely become organisational crises because of technology alone. They become crises because of the decisions made before, during and after the incident.
Our Leadership Cyber Security input is designed for directors, executives, senior leaders, trustees and decision makers. Rather than focusing on technical detail, the session helps leaders understand cyber security as a business risk that must be governed, managed and rehearsed like any other significant organisational risk.
Whether you’re a large public-sector organisation, a growing business, a charity, or a multinational enterprise, the principles remain the same: understanding risk, building resilience and being ready to respond when incidents occur.
As part of the Home Office-funded Police Cyber Crime Programme, this service is provided completely free of charge. All advice delivered through this training aligns with guidance from the National Cyber Security Centre (NCSC), the UK’s technical authority for cyber security. We work closely with national policing and government partners to ensure organisations receive trusted, evidence-based advice that reflects current threats and recognised good practice.
Who Is It For?
This workshop is suitable for:
- Boards of Directors
- Executive leadership teams
- Senior management teams
- Business owners
- Trustees
- Charity leadership teams
- Public sector leadership teams
- Risk and governance groups
We regularly deliver sessions to organisations ranging from large enterprises and public-sector bodies through to SMEs. We can adapt the content to suit organisations of different sizes and levels of cyber maturity.
Sole Traders and Micro Businesses
For sole traders and very small businesses, we typically recommend our Sole Trader or Small Business workshops instead.
We can still deliver our leadership presentation virtually if appropriate, but some of our interactive in-person activities are designed for leadership teams of Small Businesses and above. If you’re a sole trader or micro business owner, consider working with a local Chamber of Commerce, business network or trade association to host a Sole Trader or Small Business Cyber Security Workshop for multiple businesses at once.
What You’ll Learn
Topics may include:
- Why cyber security is a business risk, not just an IT issue
- The real-world cyber threats facing UK organisations
- The causes of most cyber incidents and breaches
- Business email compromise and invoice fraud
- Ransomware and organisational resilience
- Supply chain and third-party cyber risk
- Cyber governance and board responsibilities
- Cyber security culture and human risk
- Cyber assurance and meaningful reporting
- Incident response planning
- Business continuity and recovery
- Cyber Essentials and security frameworks
- Free services available from the National Cyber Security Centre
- Practical actions leaders can take in the next 90 days
What Leaders Take Away
Participants leave with:
- A clearer understanding of their organisation’s cyber risks.
- Greater confidence discussing cyber security at board and leadership level.
- Practical steps to improve organisational resilience.
- An understanding of what good cyber governance looks like.
- A framework for meaningful conversations with technical teams and suppliers.
- Confidence that cyber security decisions are primarily about risk management rather than technical expertise.
- An action plan that can be adapted to their organisation.
Interactive Leadership Exercise

Where suitable, this session can be combined with our flagship tabletop leadership exercise, Considerations and Consequences. Using an engaging LEGO®-based1 scenario, leaders work together through a realistic cyber incident and the difficult decisions that follow.
The exercise is specifically designed to:
- Encourage discussion and participation.
- Build confidence among non-technical leaders.
- Demonstrate the organisational impacts of cyber incidents.
- Explore competing priorities and decision making under pressure.
- Highlight the importance of preparation and governance.
Participants quickly discover that successful cyber incident management is rarely about technical decisions. It is about leadership, planning, communication, risk management and organisational resilience.
Enquire Now
Tell us a little about your organisation, location, cybersecurity maturity and audience size and we’ll discuss the options with you. We typically need at least one month’s notice to find a date that works for everyone, although this can sometimes be longer during busy periods.
FAQs
Nothing. This input is delivered free of charge as part of the Home Office-funded Police Cyber Crime Programme.
Our goal is to help organisations improve their cyber resilience and reduce their likelihood of becoming victims of cyber crime.
Ideally, the people responsible for making strategic, financial and operational decisions.
This may include directors, senior leaders, trustees, business owners, department heads, risk managers and governance leads.
The most effective sessions involve a broad cross-section of organisational leadership rather than just IT staff.
No. The input is specifically designed for leaders and decision makers rather than technical specialists.
We focus on risk, resilience, governance and decision making. Technical topics are discussed only where they support leadership decision making.
No technical background is required.
Yes, but only to a degree. There are key topics and messages that we are expected to cover, but we will tailor examples, discussion points and case studies to suit your organisation’s sector, size and cyber maturity.
Typically 1.5-2 hours. This is normally made up of 50 mins for the interactive LEGO exercise, and 30 to 50 mins of presentational content depending on the topics that need to be covered for your size and maturity.
For in-person delivery we typically require:
- A suitable meeting room
- Seating for participants
- A projector, screen or large display, ideally with audio capability as our presentations may include videos with audio elements
Tea, coffee and biscuits are always welcome, but entirely optional!
Yes, but without the interactive LEGO exercise. However, we generally recommend in-person delivery wherever possible, particularly where an interactive exercise is included. If you would like the presentational input online, we prefer you to provide the meeting link and invite us as a presenter in order to minimise security risks and technology issues. We can join any common online meeting platform provided no paid licence is required to present.
For very small organisations we typically recommend joining or hosting one of our Sole Trader or Small Business Cyber Security Workshops. We typically work in partnership with business groups such as Chambers of Commerce, Federation of Small Businesses, growth and accelerator groups to organise these events. If you would like to take part, please encourage a local gathering to get in touch to arrange a workshop.
Where appropriate, we can also deliver the leadership presentation virtually to micro businesses (without the LEGO exercise). We cannot offer this on a 1-2-1 basis for sole traders, but if there is enough interest we periodically offer an open-signup webinar version.
Considerations and Consequences is our enhanced cyber incident exercise for organisational leaders.
The exercise is based on the award-winning Decisions & Disruptions framework originally developed by Lancaster University to help leadership teams explore cyber incident response in a safe and engaging environment.
We’ve evolved the format to reflect the incidents and trends we see affecting organisations today. Through our work with victim organisations, intelligence partners and Cyber Pursue colleagues investigating cybercrime, we have incorporated lessons learned from real-world cyber incidents, emerging criminal tactics and updated guidance from the National Cyber Security Centre.
Using LEGO® as a hands-on facilitation tool, participants work together through a realistic cyber incident, discussing priorities, decisions, consequences and recovery.
Most importantly, the exercise demonstrates that cyber security leadership is rarely about making technical decisions. It is about risk management, communication, governance and organisational resilience. No technical expertise is required.
Yes. Our presentations are delivered by qualified Cyber Security Advisors from the Police Cyber Protect team, whose role is to help individuals, organisations and communities reduce their exposure to cyber crime. Our team receives specialist training and works closely with national policing, government and industry partners to ensure the advice we provide reflects current threats, recognised good practice and lessons learned from real incidents.
Cyber crime is unlike many traditional crime types.
Many cyber criminals operate internationally, often from jurisdictions where enforcement action is difficult or impossible. While police continue to investigate offenders wherever possible, we cannot arrest our way out of the cyber crime problem.
That is why prevention, protection and resilience are so important.
By helping organisations become harder targets and better prepared to respond to incidents, we can reduce the harm caused by cyber crime across the region.
Quite a lot.
Police Cyber Protect teams work alongside colleagues across UK policing to help organisations prevent, prepare for and respond to cyber incidents.
Through our work, we regularly engage with organisations that have experienced phishing attacks, ransomware incidents, business email compromise, supply-chain compromises and other forms of cyber crime. This provides valuable insight into the real-world causes and consequences of cyber incidents, rather than purely theoretical risks.
We also deliver threat briefings to organisations of all sizes, maintain relationships with government, policing and industry partners, and receive intelligence about emerging threats, criminal tactics and trends.
Our Regional Cyber Protect Officers and Sergeant are Certified Information Security Managers (CISM), combining recognised professional cyber security qualifications with practical experience supporting organisations across the South East.
The result is training that combines recognised good practice with real-world lessons learned from the incidents affecting organisations today.
Use the button below to contact our team.
Tell us a little about your organisation, leadership team and what you’re hoping to achieve, and we’ll discuss the available options with you.
1 Our Considerations and Consequences exercise uses LEGO® bricks as a hands-on facilitation tool. LEGO® is a trademark of the LEGO Group, which does not sponsor, authorise or endorse this exercise.
Service Availability and Disclaimer
All services are delivered through the Home Office-funded Police Cyber Crime Programme and are subject to available resources, operational commitments and ongoing programme funding.
Services are primarily available to eligible organisations, communities and individuals located within the South East region served by SEROCU, including Berkshire, Buckinghamshire, Oxfordshire (Thames Valley Police); Hampshire & the Isle of Wight; Surrey; and East Sussex and West Sussex (Sussex Police).
In exceptional circumstances, we may be able to support organisations outside the region where there is a clear connection to our policing area, such as organisations headquartered within the region but seeking to use an alternative venue elsewhere. Any such arrangements are entirely at our discretion.
Whilst we aim to accommodate requests wherever possible, submission of an enquiry does not guarantee that a service will be delivered. We reserve the right to decline, defer or prioritise requests based on operational priorities, capacity, funding, audience suitability and anticipated impact.
All advice, guidance, training and exercising activities are based on recognised good practice and align with guidance published by the National Cyber Security Centre (NCSC), the UK’s technical authority for cyber security. However, responsibility for assessing, implementing and acting upon any advice remains with the individual or organisation receiving the service. Training and awareness services are intended to complement, not replace, organisation-specific policies, procedures, legal obligations, professional advice or regulatory requirements.
The South East Regional Organised Crime Unit, participating police forces and partners accept no liability for any loss, damage, cost or consequence arising from reliance upon information, advice, training materials, exercise outcomes or recommendations provided through these services.