Security for managers: leading your team through incidents, new tools and exceptions
What managers do when security goes wrong or rules get in the way: set a no-blame reporting culture, know your team's incident contacts, act fast and correctly in the first hour (report, contain only as told, keep a record, route communications), understand the triage language incident teams use, and handle shadow IT, 'shadow AI' and requests for security exceptions without quietly approving risks you don't own. Based on CISA's Cyber Essentials and the UK NCSC's incident management and shadow IT guidance; your organization's incident plan and policies govern.
- Level
- Intermediate
- Length
- About 40 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 3 Oct 2026
Skills you'll practise
- Describe the leader's part in a culture of cyber readiness and how you encourage prompt, no-blame reporting
- Check that your team's incident contact information is complete and has backups
- Take the right first actions when an incident affects your team, and avoid destroying evidence
- Use the incident team's vocabulary: availability, confidentiality, integrity and incident categories
- Respond to shadow IT and shadow AI by finding the underlying need rather than blaming
- Route security exception requests to the people who can accept the risk, with limits and an end date
Course outline
- 1.Leading your team through incidentsVideo · 2 min
- 2.Your part in the team's security cultureLesson · 12 min
- 3.When an incident hits your team: the first hourLesson · 15 min
- 4.Shadow IT, shadow AI and exception requestsLesson · 13 min
- 5.Security for managers: leading your team through incidents, new tools and exceptions: knowledge checkKnowledge check · 17 questions
- 6.The ransom note on the dispatch deskScenario
- 7.Final exam11 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- CISA (US): Cyber Essentials (six elements: yourself, your staff, your systems, your surroundings, your data, your crisis response)
- NCSC (UK): Incident management: Cyber incident response processes
- NCSC (UK): Shadow IT, including 'shadow AI'
- FTC (US): Protecting Personal Information: A Guide for Business (take stock, scale down, lock it, pitch it, plan ahead)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.