Practice Like a GRC Analyst
An 8-week, practice-heavy follow-on to the Foundations course. Designed for learners who are ready to perform real GRC tasks under supervision.
After Foundations. Before the Work Network.
Where Foundations focused on concepts and mindset, the Training Lab focuses on execution — small, clearly scoped GRC tasks completed to a defined standard using runbooks, templates, and playbooks.
Execution, Under Supervision
The Training Lab is for learners who have already completed CyberForward Foundations (or an equivalent introductory GRC course) and are ready to perform real GRC-style tasks under supervision.
By the end of the course, learners function as early GRC practitioners who can add positive net value on scoped work for cyber risk assessment, vulnerability management, business continuity / disaster recovery (BCP/DR), and AI-assisted documentation.
- Duration: 8 weeks
- Format: Online, hands-on labs
- Live Sessions: 2 hours per week via Zoom
- Prerequisite: CyberForward Foundations or equivalent
- Instructor: Mike Gentile
- Delivery: Cohort-based, B2B / institutional
What Learners Do
Practice-heavy, ticket-level execution that mirrors the day-to-day of a junior GRC analyst.
Take Scoped Tasks
Risk entries, vulnerability items, BCP/DR steps, documentation tasks — complete each end-to-end against acceptance criteria.
Use Runbooks & Templates
Work to a defined standard using playbooks and templates rather than improvising.
Manage a Small Queue
Prioritize work, communicate status, surface blockers early, and explain trade-offs.
Use AI Safely
Apply guardrails to AI-assisted drafting and summarization while keeping human review and approval in the loop.
Course Objectives
Upon completion of this course, students will be able to:
- Execute specific GRC tasks (risk assessment updates, vuln triage, BCP/DR runbook work, documentation) using provided templates and runbooks.
- Apply a simple troubleshooting and validation flow before finalizing work (check basics → isolate → test → document).
- Populate and update risk registers, ticket systems, and BCP/DR artifacts with clear, reproducible entries.
- Interpret technical and process inputs (scan excerpts, case studies, runbooks, logs) and turn them into actionable, documented outcomes.
- Manage a small queue of tasks, prioritize based on urgency and impact, and clearly explain their choices.
- Use AI tools safely (within guardrails) to speed drafting and summarization while maintaining human review and control.
- Demonstrate Level-2 professional habits: execution under supervision, structured troubleshooting, documentation, and stakeholder awareness.
Credential Earned

CyberForward Training Lab Certified
Issued upon successful completion of the 8-week Training Lab. Demonstrates execution of real GRC tasks (risk assessments, vulnerability triage, BCP/DR runbook work) under supervision. Shareable to LinkedIn, resume, and digital portfolios.
Weekly Schedule
Each week pairs a 2-hour live lab with short homework artifacts (risk register entries, write-ups, runbook edits) and three discussion prompts.
Week 1 — Ramp-Up: From Concepts to Executable GRC Tasks
Subject: Ramp-Up
Re-introduce core GRC ideas from Foundations and shift into “ticket-level” execution. Learners take a mini work request (e.g., update a risk entry, review a small policy section, tidy up a register) and complete it end-to-end using acceptance criteria, templates, and a Kanban/PM tool. Emphasis on status updates, estimates, and surfacing blockers early.
Week 2 — Guided Cyber Risk Assessment: Following the Playbook
Subject: Guided Cyber Risk Assessment
Learners use a structured assessment playbook to collect inputs for a risk assessment on a single system or process. They work from a defined scope and checklist, gather asset/threat/control information, and draft initial risk entries while logging questions and assumptions for a supervisor instead of guessing.
Week 3 — Independent Risk Write-Ups & Control Evaluation
Subject: Independent Risk Write-Ups
Building on Week 2, learners independently refine risk entries and evaluate controls using simple criteria (designed, implemented, effective). They write risk statements with clear cause → event → impact, add rationales for ratings, and prepare a short “risk snapshot” for manager or senior analyst review.
Week 4 — Vulnerability Management: Prioritizing & Driving Remediation
Subject: Vulnerability Management
Learners work with vulnerability scan excerpts and asset information. They identify false positives, group findings, and prioritize based on severity, exploitability, and business impact. They write remediation tickets with clear steps, owners, validation criteria, and due dates — and connect high-priority findings back to risk entries.
Week 5 — BCP & DR I: From BIA to Recovery Objectives
Subject: BCP & DR I — BIA to Recovery Objectives
Learners revisit BIA concepts in a deeper, more practical way. Using a case study, they refine process maps and dependencies, then derive and justify Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for selected systems. They explore high-level recovery strategies and document decisions in continuity planning templates.
Week 6 — BCP & DR II: Runbooks, Exercises & After-Action Notes
Subject: BCP & DR II — Runbooks & Exercises
Learners translate BCP/DR concepts into step-by-step runbooks, then walk through a guided tabletop or simulation. They follow runbook steps, note gaps, and write after-action notes with clear follow-up tasks that tie back into risk registers, remediation, or policy updates.
Week 7 — AI-Enabled GRC Work: Safe Usage, Guardrails & Micro-Automation
Subject: AI-Enabled GRC Work
Learners explore how to safely use AI tools in GRC workflows. They identify safe vs. unsafe AI use cases, apply simple data-handling guardrails, and design a small AI-assisted workflow (drafting control descriptions, summarizing risk entries, rewriting technical notes in plain language) with clear human review and approval checkpoints.
Week 8 — Executing Mixed GRC Work Packages: Integration & Prioritization
Subject: Mixed Work Packages
Learners receive a small mixed work package (risk updates, vuln findings, BCP/DR runbook edits, documentation tasks). They plan the order of work based on risk, dependencies, and deadlines, then execute key pieces and report back on what they did, why they prioritized that way, and what remains. Emphasis on integrated execution rather than new concepts.
Participation, Attendance & Policies
Participation & Attendance
Cameras must be on during live sessions unless otherwise approved by the instructor. Three (3) unexcused absences with no communication may lead to being dropped from the class. If you will miss a session, notify Mike Gentile at mike.gentile@cyberfwd.com.
Honesty Policy
A student caught cheating on any assignment will receive no credit for that assignment. Further academic integrity concerns may be handled according to program policies.
This syllabus may be updated at any point through the program at the instructor’s discretion. Any changes will be communicated via the LMS and in class.
Bring the Training Lab to Your Cohort
Training Lab is sold to community colleges, school districts, and workforce partners as a cohort-based program. Reach out to schedule a cohort.