Program design and contents
Data and Information Security
In 6 weeks, move from compliance and incident response to strategic resilience and trust in your organization.
In this module, you will delve into the role of information security within digital transformation. You will examine how risks arise in a data-driven, connected world and how policy, governance, and technology come together to make organizations resilient. From strategic frameworks such as NIS2 and DORA to practical issues surrounding data classification, identity management, monitoring, and incident response—you will learn to think in terms of coherence rather than isolated measures.
The learning journey starts with the current threat landscape and its impact on organizations and their chains. You will then work on frameworks and governance structures that link security, compliance, and innovation. Finally, you will translate the insights into your own organization or client case: how do you set up security as a strategic function that ensures trust and continuity?
Over the course of six weeks, you will complete an online kick-off, three intensive on-campus days, and an in-depth phase. You will conclude with an assessed assignment based on your practical experience. By combining theory, frameworks, simulations, and realistic incident cases, you will develop the insight and skills to structurally strengthen digital security.
Online kick-off
During the online kick-off, you will meet the instructors and fellow participants and receive an explanation of the program structure and the final assignment. You will explore your learning objectives, the context of your organization, and recent incidents or compliance issues, so that you can get started in a focused manner during the on-campus days.
Day 1 – Threats, risks, and strategic security
The first day focuses on understanding the current threat landscape and its impact on business operations and supply chains. You will examine how risks arise from dependencies, human factors, and technological choices, and learn how to translate these into strategic priorities. You will also explore current legislation and regulations (such as NIS2, DORA, and the AI Act) and their implications for governance and responsibility.
Day 2 – Governance, compliance and security organization
On day 2, you will delve into the structure of security governance: who decides, who is responsible, and how do you ensure continuity? You will examine how organizations implement frameworks such as ISO 27001, NIS2, and DORA in a practical manner without stifling innovation. You will also learn how roles such as CISO, DPO, CIO, and line management come together in policy, control frameworks, and audits.
Day 3 – Incident response, crisis management and trust
The third day focuses on translating policy into action. You will practice with scenarios involving data breaches, ransomware, and supply chain disruptions and explore how communication, leadership, and coordination are decisive during incidents. You will learn how to set up crisis structures, prepare decision-making, and formulate recovery plans.
In-depth study after the lecture days
After the lecture days, you will continue to work independently with literature, assignments, and your own case. You will apply insights from the lectures to your organization: you will identify risks, governance, and measures and formulate concrete steps for improvement in policy, awareness, and incident response.
Assessment based on your own practice
You will complete the master's module with an assessed assignment that directly relates to your work environment and learning objectives. You will demonstrate that you can analyze digital risks, substantiate governance and measures, and formulate concrete recommendations for strategic security and compliance within your organization.