Full course description
About this course
Course Snapshot
Across four modules, you’ll build the knowledge and judgement needed to address cyber and privacy risk across an organisation. You’ll begin by exploring privacy and data protection, including the legal, ethical and organisational responsibilities involved in collecting, using, storing and sharing personal information.
You’ll then examine the human dimension of cyber risk, including how social engineering exploits trust, routine, authority and time pressure. The course moves from individual behaviour to organisational governance, exploring how risks are identified, assessed, prioritised and owned using structured processes and recognised frameworks.
The final module brings these ideas together through cyber leadership and crisis decision-making. You’ll consider how leaders set cyber priorities, establish risk ownership, prepare for incidents and guide coordinated organisational responses when systems or data are compromised. By the end of the course, you’ll be better equipped to make defensible cyber and privacy decisions that strengthen organisational trust, resilience and operational readiness.
The micro-credential consists of four (4) modules designed to build organisational cybersecurity, risk and governance capability:
Privacy, Data Protection and Trust: examines privacy as a governance and organisational responsibility. You’ll explore data protection obligations, Privacy Impact Assessments, privacy-preserving approaches and how responsible data practices support trust.
People, Behaviour and Social Engineering: explores how attackers exploit trust, routine, authority and urgency. You’ll examine phishing and other social engineering techniques, the behavioural factors that increase exposure and practical actions that strengthen awareness and reporting.
Cyber Risk Management and Governance: examines how organisations identify, assess and manage cyber risk. You’ll explore assets, threats, vulnerabilities, controls, risk ownership, third-party risk and recognised governance and assurance frameworks.
Cyber Leadership and Crisis Decision-Making: explores how leaders translate cyber governance into action before, during and after incidents. You’ll examine capability, accountability, incident preparedness, crisis communication, recovery and organisational resilience.
This course is ideal for leaders, managers, operational professionals, risk and governance practitioners, and people whose roles involve data, privacy, organisational decision-making or business continuity.
It will be particularly valuable for participants who want to understand cybersecurity from an organisational, risk and leadership perspective. No technical background is required. The course focuses on developing the judgement, awareness and leadership capability needed to assess cyber risk, influence secure behaviour and contribute confidently to governance and incident-readiness discussions.
Participants who complete this micro-credential will earn a certificate of completion. Participants who package this course together with Cybersecurity Foundations and Technical Fundamentals (study both courses) will be eligible to receive a digital badge to recognise their achievement, demonstrating to employers and peers the skills and knowledge acquired. Participants who complete both this course and Cybersecurity Foundations and Technical Fundamentals will also earn 10 credit points (CP) that contribute toward the Master of Cyber Security at Griffith University.
This 6-week online course is structured for flexible, self-paced learning and is hosted on Griffith University’s Learning Management System.
The course includes:
- Rich learning content featuring videos, case studies, practical examples, reflections and workplace-focused activities.
- Four sequential learning modules.
- Activities that allow you to apply privacy, behavioural, governance and leadership concepts to realistic organisational situations.
- Assessments that include quizzes, workplace analysis, Privacy Impact Assessment processes, cyber risk evaluation and scenario-based decision-making.
- Optional interactive webinars that provide opportunities to engage with facilitators, ask questions, discuss practical examples and connect with other participants.
Professor Ernest Foo
Professor Ernest Foo is a cybersecurity researcher and educator with extensive experience in critical infrastructure security, industrial control systems, network security, and cyber resilience.
Throughout his career, Ernest has worked with industry, government, and critical infrastructure operators to help address complex cybersecurity challenges in sectors where reliability, safety, and trust are essential. His research has focused on protecting the systems that underpin modern society, including energy networks, industrial control systems, and other cyber-physical environments.
At Griffith University, Ernest has played a leading role in cybersecurity education and workforce development, helping to prepare the next generation of cyber professionals and leaders.
Known for his practical and engaging approach, Ernest is passionate about helping people understand cybersecurity as more than a technical issue - it is a leadership, governance, and organisational challenge that affects every sector and profession.

