Executive Masterclasses
Small-room, in-person masterclasses for executives, security leaders, and the teams they run. Every class ends with work you can put in front of your organization the following week.
A working session, not a webinar
Built for decision-makers
For the people who approve the budget, sign the risk acceptance, and answer to the board.
Board briefing practice
Three times during class, you brief a partner playing your most difficult stakeholder.
You leave with a plan
Every module ends with something written down and assigned.
CPE credits and certificate
Plus a printed workbook and 30-day access to all materials.
The Gap Is Not Effort; It Is a Leadership Model That Has Not Kept Pace with the Modern Cyber Landscape
Cyber risk is national security risk
01
Governance
02
Technology
03
Operations
04
People
Mindset
Open Enrollment
The Big 4 Model: Winning Cyber Defense Under Pressure
4 CPE
Governing AI and Cybersecurity Before the Attack
The Duty of Inquiry: Board Oversight of Cyber and AI Risk
Private sessions for your board or leadership team
The Big 4 Model: Winning Cyber Defense Under Pressure
Every program behind the incident numbers passed an assessment
That is the problem this class exists to solve. Compliance proves a control exists — in policy, on an invoice, in a training record. It never proves the control holds when an adversary arrives. Organizations measure compliance every year and measure consequence almost never, which is how a program can be green on reporting day and fail on a specific Tuesday. The gap is not a tooling gap. It is the difference between a control that is assumed to work and one that somebody owns.
Four domains, three levels, one honest score
The four domains are governance, technology, operations, and people, with mindset as the shared root beneath all four. Each domain scores at one of three levels.
- Assumed — the control appears in policy, on an invoice, or in a training record.
- Measured — telemetry proves it works, but response leans on a vendor.
- Owned — an internal team answers for the outcome under real pressure.
What you own by 1:00 PM
You leave with a completed Big 4 Scorecard: twenty points across the four domains, each scored against evidence you recorded and rolled into one readiness number. You also leave with four metrics that carry named owners, a tested assumption about a control you thought was working, and a 90-day mesh plan you can put in front of your executive committee.
What you will work through
Phase 1 · Score
M1
The Four Domains & the Loop Scope and holding condition for each domain, mindset as the root, your four blind spots, and the point where the loop’s return leg breaks.
M2
Scoring Your Program Four diagnostic questions answered with evidence, then Assumed, Measured, or Owned for each domain — with the evidence recorded.
Phase 2 · Prove
M3
The Pressure Test The same four answers run against your worst day, including the first hour of an incident: control verification, response capability, leadership readiness, accountability.
M4
Blind Spots as Engineering Gaps Log source coverage, technique mapping, validation cadence, detection as code — each with the metric that makes it countable and assignable.
Phase 3 · Own
M5
Signal Over Noise From findings ingested, to the few exploitable on mission systems, to one page carrying one decision and one owner.
M6
The Operational Mesh Unify governance, integrate technology, operationalize users, validate and improve — in that order — plus 90 days of moves that each produce evidence.
Built for Washington and the mission it supports
The four domains map to all six NIST CSF 2.0 functions: governance to Govern; technology to Identify and Protect; operations to Detect, Respond, and Recover; and people across all six, from roles and accountability to awareness training. Detection coverage is measured against MITRE ATT&CK, validation cadence follows NIST SP 800-137 and SP 800-84, and known-exploited vulnerabilities under CISA BOD 22-01 set the remediation clock. For agencies, the same four scores feed FISMA reporting and RMF ongoing authorization. For the defense industrial base, they map to NIST SP 800-171 and CMMC.
A nation-state actor does not test your compliance posture. The test is whether anyone owns the control. The session stays vendor-neutral throughout.
Secure checkout on PayPal. Pay with PayPal or card, and choose your number of seats at checkout.
Sending a team? Contact us for group rates or call (470) 409-8316.
What Your Seat Includes
- Seven hours of live, in-person instruction and scoring workshops
- The Big 4 Scorecard: domain scoring instrument, evidence worksheet, one-page readout template, and the 90-day mesh planner
- 4 CPE credits and a Certificate of Completion
- Printed student workbook
- Networking break
- 30-day access to all materials plus instructor follow-up
This session is built for the people who run the program: CISOs and deputy CISOs; CIOs and CTOs who share ownership of security; directors of security operations, vulnerability management, and GRC; security architects and program managers who carry out the plan; federal ISSMs, authorizing official designated representatives, and defense contractor security leadership. It is not a hands-on technical course for SOC analysts or security engineers seeking lab work.
Governing AI and Cybersecurity Before the Attack
Why this now reaches your desk
Cyberattacks no longer require advanced skill. Exploited vulnerabilities have overtaken stolen credentials as the leading way attackers get in. AI has shrunk the time from disclosure to working exploit from months to hours. Employees are pasting company data into AI tools no one approved. A few seconds of audio is enough to clone a voice, and an AI-written request to move money is indistinguishable from a real one. When something goes wrong, regulators, inspectors general, insurers, and customers will ask what leadership knew and when. That answer is written before the attack, not after.
Six windows, not one
- Vulnerability — disclosure to verified fix
- Configuration — drift to correction
- Policy— threat change to policy update
- Operations — compromise to containment
- Decision — risk known to decision made
- Adoption — AI tool live to governed
What you own by 1:00 PM
How the day is structured
Phase 1 · Recognize
M1
AI-Powered Threats & the Speed Gap Recognize deepfakes, AI-written fraud, and exploits that arrive in hours, then measure all six exposure windows and set a tolerance for each.
M2
Secure AI Adoption Adopt AI through signed gates with named owners for the data, the model, and the user — and decide what AI is doing to the judgment your organization depends on.
Phase 2 · Govern
M3
Continuous Exposure Management Scope to crown jewels, rank by what an attacker can actually reach, prove the controls you paid for fire, and fix at machine speed.
M4
Building a Defensible Program Map the obligations that bind you, pre-delegate decision rights, enforce baselines as code, and score each Big 4 domain on evidence rather than policy.
Phase 3 · Act
M5
Stakeholder Reporting & Your 90-Day Plan Translate tech talk into stakeholder talk, close the gap between budget and technical need, and leave with three committed moves.
M6
Resilient Leadership Under Fire Command the first hour — decision rights, the notification clocks, the call list, communications, and continuity — rehearsed in a live scenario.
Mapped to federal policy and the mission it protects
The program is anchored to NIST CSF 2.0 and the NIST AI Risk Management Framework. Known-exploited vulnerabilities under the CISA KEV catalog and BOD 22-01 set the clock that matters. Configuration management follows NIST SP 800-128, continuous monitoring follows SP 800-137, the first hour of response follows NIST SP 800-61 Rev. 3, and rehearsal uses NIST SP 800-84 and CISA Tabletop Exercise Packages.
The AI module sets a firm line: Controlled Unclassified Information, PII, PHI, and export-controlled data never enter a public model, and vendor FedRAMP authorization is checked wherever it applies. The first-hour module confirms which notification clocks actually bind your organization, including DFARS 252.204-7012 for defense contractors and agency incident reporting for federal programs. The session stays vendor-neutral throughout.
Sending a team? Contact us for group rates or call (470) 409-8316.
- Four hours of live, in-person instructor-led training
- The Big 4 Leadership Toolkit: the 25-Point AI & Cyber Readiness Checklist, accountability RACI, first-hour command card, and stakeholder reporting template
- 4 CPE credits and a Certificate of Completion
- Printed student workbook
- Networking breaks
- 30-day access to all session materials plus instructor follow-up
This session is built for the people who answer for the program: CEOs, CFOs, COOs, and general counsel; chief risk, compliance, AI, and data officers; CIOs, CTOs, and CISOs who brief the executive team; federal agency, defense contractor, and critical infrastructure leadership. It is not a hands-on technical course for SOC analysts or security engineers seeking lab work.
The Duty of Inquiry: Board Oversight of Cyber and AI Risk
Boards are briefed on cyber risk and still cannot answer for it
Duty, inquiry, record
- Duty — what this board oversees, and the obligations that bind it.
- Inquiry — the channel with the technical organization in both directions, with the CISO as translator.
- Record — the crisis position and the standing cadence, written down and dated.
What the board owns by 1:00 PM
How the morning is structured
Phase 1 · Duty
M1
Cyber and AI as a Governance Matter Name the crown jewels, scope board reporting to them, put an owner against AI risk, and confirm the verification rule that seniority cannot waive.
M2
Regulation, Disclosure, and Personal Liability Map SEC disclosure, FISMA, CMMC, state breach law, and contract terms, set the questions the board must have asked, and fix how decisions are minuted.
Phase 2 · Inquiry
M3
Strategy, Appetite, and Sending the Framework Down Own the strategy, state appetite in writing, name one framework, and turn tolerance into a requirement engineering can build to.
M4
Drawing Requirements Up, and Using Your CISO Surface what the board is not told, demand evidence with a date, hold executive sessions with the CISO, and require funding requests framed as exposure and cost.
Phase 3 · Record
M5
Crisis Oversight and the First Hour Set the escalation threshold, the authority boundary, the notification clocks, privilege, and the extortion position, then rehearse them in a live tabletop.
M6
The Oversight Cadence and Your 7-Day Plan Decide where oversight sits, bring cyber into enterprise risk, budget, and M&A, and put the next review dates in the calendar.
Oversight when the mission is national security
The session is anchored to the Govern function of NIST CSF 2.0, the part of the framework written for oversight, and to the NIST AI Risk Management Framework. For agencies, the oversight record is what inspectors general examine in the annual FISMA evaluation and what GAO and Congress review after an incident. For public companies, SEC rules require disclosure of how the board oversees cybersecurity risk and of material incidents within four business days. For the defense industrial base, CMMC requires a senior official to affirm compliance, and the False Claims Act holds contractors liable when those affirmations prove false.
The session closes on the two threats most likely to reach the boardroom next: an AI failure and a cloned-voice message from the CEO. Directors leave knowing which questions to ask, when to ask them, and how to document the answers. The session stays vendor-neutral throughout.
Sending a team? Contact us for group rates or call (470) 409-8316.
- Four hours of live, in-person instruction and oversight workshops
- The Director’s Oversight Toolkit: the 20-point oversight checklist, board mandate template, board pack standard, crisis card, and model minutes language
- 4 CPE credits and a Certificate of Completion
- Printed director’s workbook
- 30-day access to all materials plus instructor follow-up
This session is built for the people who oversee the program: board members and trustees, especially audit and risk committee chairs; corporate secretaries and board governance counsel; CEOs, general counsel, and CISOs who brief the board; federal advisory board and commission members with oversight duties. It is not a technical course, and no security background is required.
Private Sessions for Boards and Senior Leaders
Executives want clear insight and honest answers to hard questions. Dewayne delivers both in his executive sessions and private masterclasses.
These smaller settings allow deeper content than a traditional keynote and a conversational format that experienced leaders appreciate. Dewayne’s executive sessions can serve a senior leadership team, a board of directors, or CEO and CISO gatherings, where candid insight and proven strategy deliver the value seasoned leaders expect.
Senior Leadership Teams
Boards of Directors
CEO & CISO Gatherings
Executive sessions built on must-know insight, frameworks, and strategy
Dewayne designs these sessions for smaller groups, with more depth and interaction tailored to the responsibilities and priorities of the people in the room. In the longer formats, he works closely with your senior leaders on their most urgent security decisions.
30 min
Insight Session
The must-know risks and decisions for your leaders, delivered at the top of a meeting or retreat.
90 min
Executive Briefing
Deeper insight and discussion on one priority, with time for your leaders’ toughest questions.
Half day
Private Masterclass
The must-know risks and decisions for your leaders, delivered at the top of a meeting or retreat.
Customized to Your Priorities
Each session is customized to your audience, meeting, areas of focus, and strategic priorities.
AI risk & secure adoption
Exposure management
Security culture that holds under pressure
Plan a session for your leaders
Dewayne has advised leaders at the Department of Veterans Affairs, the U.S. Army, Duke Energy, PwC, Kaiser Permanente, and Wells Fargo, and has spoken at the National Cybersecurity Summit and the GDS Group Security North America Summit. Every engagement begins with a planning call, so his message, depth, and style of interaction match your vision.
You Can Also Buy Dewayne's Books
Keep the insight working after the session ends. Cybersecurity Leadership, The Cybersecurity Mindset, and CISSP Practice Questions & Explanations give leaders and practitioners the mindset, the leadership, and the credential. Bulk orders are available to give every attendee the same playbook.
Masterclass FAQ
How do I register?
Do I need a PayPal account?
Can I register a group or pay by invoice?
Yes. Group seats for leadership teams are available. You can choose multiple seats at PayPal checkout, then email attendee names to dewaynehart@dewaynehart.com. For group rates or to pay by invoice, email dewaynehart@dewaynehart.com or call (470) 409-8316.
Do masterclasses offer CPE credits?
Yes. Each executive masterclass is a half-day session that awards 4 CPE credits: The Big 4 Model: Winning Cyber Defense Under Pressure, Governing AI and Cybersecurity Before the Attack, and The Duty of Inquiry: Board Oversight of Cyber and AI Risk. Every session includes a Certificate of Completion.