SEMAIS Executive Training

Executive Masterclasses

Awareness → Readiness → Action

Small-room, in-person masterclasses for executives, security leaders, and the teams they run. Every class ends with work you can put in front of your organization the following week.

Every Masterclass

A working session, not a webinar

Built for decision-makers

For the people who approve the budget, sign the risk acceptance, and answer to the board.

Board briefing practice

Three times during class, you brief a partner playing your most difficult stakeholder.

You leave with a plan

Every module ends with something written down and assigned.

CPE credits and certificate

Plus a printed workbook and 30-day access to all materials.

Why These Masterclasses

The Gap Is Not Effort; It Is a Leadership Model That Has Not Kept Pace with the Modern Cyber Landscape

Cybersecurity leaders work hard, invest wisely, and push their teams toward maturity. They follow frameworks, deploy modern tools, and communicate risk with discipline. Yet incidents still occur, gaps still emerge, and boards still question progress. These outcomes do not reflect a lack of effort. They reflect an industry that has evolved faster than leadership models can adapt.
Even strong leaders struggle to see the hidden gaps that sit between governance, technology, operations, and people. These gaps do not appear in dashboards or compliance reports. They show up in misaligned priorities, unclear ownership, and teams that communicate in different languages. Leaders often sense that something is missing, but they cannot pinpoint the source with precision.

Cyber risk is national security risk

Sixteen critical infrastructure sectors run on systems that private organizations own and operate. Nation-state actors have been found pre-positioning inside those networks — not to steal data, but to hold the ability to disrupt at a time of their choosing. An intrusion at a defense supplier, a hospital network, a water utility, or a state agency is not only a business problem.
If your organization supports a federal mission, handles Controlled Unclassified Information, or sits anywhere in the defense industrial base, the decisions these masterclasses ask you to make are part of the country’s defense posture, not just your own. Both instructors served — twenty years in the U.S. Navy, and a retired Marine with federal service at DHS — and they teach it the way they learned it.
“Every audience deserves the Cyber Truth — real insight that drives real protection.”
— Dewayne Hart
The Big 4 Model

01

Governance

02

Technology

03

Operations

04

People

Mindset

The shared root beneath all four
Hidden gaps live between the domains. The Big 4 Model governs them as one coherent system.
Years in cybersecurity and defense
1 +
Keynotes delivered
1 +
Years U.S. Navy, retired Chief Petty Officer
1
Founded SEMAIS, a veteran-owned firm
1
Upcoming Masterclasses

Open Enrollment

Choose a masterclass to see the full agenda, pricing, and PayPal registration.
Half-Day Masterclass
4 CPE
CISO-Level

The Big 4 Model: Winning Cyber Defense Under Pressure

For CISOs and security leaders who own the program. Score your program honestly across governance, technology, operations, and people. Prove which controls hold when they are tested. Leave with a plan to move from assumed compliance to operational ownership.
Tuesday, January 12, 2027
Washington, DC
Half-Day Masterclass

4 CPE

Executive-Level

Governing AI and Cybersecurity Before the Attack

For CEOs and senior executives accountable for cyber and AI risk. Identify the exposure window an attacker will use, assign clear ownership for each gap, and make the governance decisions now rather than during an incident.
Tuesday, February 9, 2027
Washington, DC
Half-Day Masterclass
4 CPE
Board-Level

The Duty of Inquiry: Board Oversight of Cyber and AI Risk

For directors, trustees, and the executives who brief them. Learn the questions a board is expected to ask about cyber and AI risk. Leave with an oversight record that holds up when regulators, auditors, or courts review what the board asked and when.
Tuesday, March 16, 2027
Washington, DC
Executive Sessions

Private sessions for your board or leadership team

From 30-minute insight sessions to half-day private masterclasses, built around your priorities and scheduled around your organization.
Half-Day Executive Masterclass

The Big 4 Model: Winning Cyber Defense Under Pressure

From assumed compliance to operational ownership.

Every program behind the incident numbers passed an assessment

That is the problem this class exists to solve. Compliance proves a control exists — in policy, on an invoice, in a training record. It never proves the control holds when an adversary arrives. Organizations measure compliance every year and measure consequence almost never, which is how a program can be green on reporting day and fail on a specific Tuesday. The gap is not a tooling gap. It is the difference between a control that is assumed to work and one that somebody owns.

Four domains, three levels, one honest score

The four domains are governance, technology, operations, and people, with mindset as the shared root beneath all four. Each domain scores at one of three levels.

Most programs sit at Assumed across all four and still rate as compliant. That is a useful finding, not a failure.

What you own by 1:00 PM

You leave with a completed Big 4 Scorecard: twenty points across the four domains, each scored against evidence you recorded and rolled into one readiness number. You also leave with four metrics that carry named owners, a tested assumption about a control you thought was working, and a 90-day mesh plan you can put in front of your executive committee.

What you will work through

The day runs six modules across three phases — score the program, prove what holds, own the four domains — and you teach the work back three times along the way.

Phase 1 · Score

M1

The Four Domains & the Loop Scope and holding condition for each domain, mindset as the root, your four blind spots, and the point where the loop’s return leg breaks.

A model you can hold in your head

M2

Scoring Your Program Four diagnostic questions answered with evidence, then Assumed, Measured, or Owned for each domain — with the evidence recorded.

A scorecard built on evidence, not assurance

Phase 2 · Prove

M3

The Pressure Test The same four answers run against your worst day, including the first hour of an incident: control verification, response capability, leadership readiness, accountability.

You know which domain fails first

M4

Blind Spots as Engineering Gaps Log source coverage, technique mapping, validation cadence, detection as code — each with the metric that makes it countable and assignable.

Gaps that can be counted and owned

Phase 3 · Own

M5

Signal Over Noise From findings ingested, to the few exploitable on mission systems, to one page carrying one decision and one owner.

One page, one decision, one owner

M6

The Operational Mesh Unify governance, integrate technology, operationalize users, validate and improve — in that order — plus 90 days of moves that each produce evidence.

Four domains at Measured in 90 days

Built for Washington and the mission it supports

The four domains map to all six NIST CSF 2.0 functions: governance to Govern; technology to Identify and Protect; operations to Detect, Respond, and Recover; and people across all six, from roles and accountability to awareness training. Detection coverage is measured against MITRE ATT&CK, validation cadence follows NIST SP 800-137 and SP 800-84, and known-exploited vulnerabilities under CISA BOD 22-01 set the remediation clock. For agencies, the same four scores feed FISMA reporting and RMF ongoing authorization. For the defense industrial base, they map to NIST SP 800-171 and CMMC.

A nation-state actor does not test your compliance posture. The test is whether anyone owns the control. The session stays vendor-neutral throughout.

Secure checkout on PayPal. Pay with PayPal or card, and choose your number of seats at checkout.

What Your Seat Includes

Is This Built for You?

This session is built for the people who run the program: CISOs and deputy CISOs; CIOs and CTOs who share ownership of security; directors of security operations, vulnerability management, and GRC; security architects and program managers who carry out the plan; federal ISSMs, authorizing official designated representatives, and defense contractor security leadership. It is not a hands-on technical course for SOC analysts or security engineers seeking lab work.

Half-Day Executive Masterclass

Governing AI and Cybersecurity Before the Attack

An executive masterclass for the leaders held accountable.

Why this now reaches your desk

Cyberattacks no longer require advanced skill. Exploited vulnerabilities have overtaken stolen credentials as the leading way attackers get in. AI has shrunk the time from disclosure to working exploit from months to hours. Employees are pasting company data into AI tools no one approved. A few seconds of audio is enough to clone a voice, and an AI-written request to move money is indistinguishable from a real one. When something goes wrong, regulators, inspectors general, insurers, and customers will ask what leadership knew and when. That answer is written before the attack, not after.

Six windows, not one

Most programs measure disclosure to patch and report it as risk. Attackers use all six, and your exposure is your widest window, not your average.
You set a tolerance for each one and name who owns closing it — moving from static leadership, where decisions wait for the next meeting, to dynamic leadership, where decisions are made in advance and machines enforce them.

What you own by 1:00 PM

You leave with a scored 25-point readiness checklist and a tolerance set for each exposure window. You also leave with three committed actions that carry named owners and dates, a first-hour command card, and a one-page stakeholder report you can send the same week.

How the day is structured

The day runs six modules across three phases, and each phase pairs a foundation with an applied action. You teach the work back three times along the way.

Phase 1 · Recognize

M1

AI-Powered Threats & the Speed Gap Recognize deepfakes, AI-written fraud, and exploits that arrive in hours, then measure all six exposure windows and set a tolerance for each.

Approvals an attacker cannot hijack

M2

Secure AI Adoption Adopt AI through signed gates with named owners for the data, the model, and the user — and decide what AI is doing to the judgment your organization depends on.

Innovation without new exposure

Phase 2 · Govern

M3

Continuous Exposure Management Scope to crown jewels, rank by what an attacker can actually reach, prove the controls you paid for fire, and fix at machine speed.

Proof that risk is going down

M4

Building a Defensible Program Map the obligations that bind you, pre-delegate decision rights, enforce baselines as code, and score each Big 4 domain on evidence rather than policy.

A program that holds up to scrutiny

Phase 3 · Act

M5

Stakeholder Reporting & Your 90-Day Plan Translate tech talk into stakeholder talk, close the gap between budget and technical need, and leave with three committed moves.

A plan you own by Monday

M6

Resilient Leadership Under Fire Command the first hour — decision rights, the notification clocks, the call list, communications, and continuity — rehearsed in a live scenario.

A rehearsed crisis response

Mapped to federal policy and the mission it protects

The program is anchored to NIST CSF 2.0 and the NIST AI Risk Management Framework. Known-exploited vulnerabilities under the CISA KEV catalog and BOD 22-01 set the clock that matters. Configuration management follows NIST SP 800-128, continuous monitoring follows SP 800-137, the first hour of response follows NIST SP 800-61 Rev. 3, and rehearsal uses NIST SP 800-84 and CISA Tabletop Exercise Packages.

The AI module sets a firm line: Controlled Unclassified Information, PII, PHI, and export-controlled data never enter a public model, and vendor FedRAMP authorization is checked wherever it applies. The first-hour module confirms which notification clocks actually bind your organization, including DFARS 252.204-7012 for defense contractors and agency incident reporting for federal programs. The session stays vendor-neutral throughout.

Secure checkout on PayPal. Pay with PayPal or card, and choose your number of seats at checkout.
What Your Seat Includes
Who Should Be in the Room

This session is built for the people who answer for the program: CEOs, CFOs, COOs, and general counsel; chief risk, compliance, AI, and data officers; CIOs, CTOs, and CISOs who brief the executive team; federal agency, defense contractor, and critical infrastructure leadership. It is not a hands-on technical course for SOC analysts or security engineers seeking lab work.

Half-Day Board-Level Masterclass

The Duty of Inquiry: Board Oversight of Cyber and AI Risk

From briefed to answerable.

Boards are briefed on cyber risk and still cannot answer for it

Modern attacks target payment approvals, vendor bank-detail changes, and executive impersonation. Those are business processes, which puts them inside the board’s remit by definition. Most boards still receive cyber as an IT update: volume they cannot act on, assurance without evidence, and minutes that record the topic was discussed without recording what was decided. When a regulator, an inspector general, an insurer, or plaintiff’s counsel asks what the board knew and when, the answer is whatever the record shows.

Duty, inquiry, record

The session never asks a director to operate anything. It builds the three things a board is actually accountable for.
The board sets the strategy, the risk appetite, and the framework, and sends them down as requirements the technical organization can build to. It then draws the truth back up: what is unfunded, what is unstaffed, and what was accepted by someone without the authority to accept it.

What the board owns by 1:00 PM

Directors leave with a one-page board mandate that carries the crown jewels, the risk appetite, the tolerances, and what requires board approval. They also leave with an obligations map, a minutes standard for risk acceptance, a board pack standard, a CISO engagement model, a rehearsed board crisis card, and three questions to send management within seven days.

How the morning is structured

The morning runs six focused modules across three phases, and each phase pairs a foundation with an applied action. Directors teach the work back three times along the way.

Phase 1 · Duty

M1

Cyber and AI as a Governance Matter Name the crown jewels, scope board reporting to them, put an owner against AI risk, and confirm the verification rule that seniority cannot waive.

A written list of what this board oversees

M2

Regulation, Disclosure, and Personal Liability Map SEC disclosure, FISMA, CMMC, state breach law, and contract terms, set the questions the board must have asked, and fix how decisions are minuted.

An obligations map and a minutes standard

Phase 2 · Inquiry

M3

Strategy, Appetite, and Sending the Framework Down Own the strategy, state appetite in writing, name one framework, and turn tolerance into a requirement engineering can build to.

A one-page board mandate

M4

Drawing Requirements Up, and Using Your CISO Surface what the board is not told, demand evidence with a date, hold executive sessions with the CISO, and require funding requests framed as exposure and cost.

A board pack that reports decisions

Phase 3 · Record

M5

Crisis Oversight and the First Hour Set the escalation threshold, the authority boundary, the notification clocks, privilege, and the extortion position, then rehearse them in a live tabletop.

A rehearsed board crisis card

M6

The Oversight Cadence and Your 7-Day Plan Decide where oversight sits, bring cyber into enterprise risk, budget, and M&A, and put the next review dates in the calendar.

A dated oversight cadence

Oversight when the mission is national security

The session is anchored to the Govern function of NIST CSF 2.0, the part of the framework written for oversight, and to the NIST AI Risk Management Framework. For agencies, the oversight record is what inspectors general examine in the annual FISMA evaluation and what GAO and Congress review after an incident. For public companies, SEC rules require disclosure of how the board oversees cybersecurity risk and of material incidents within four business days. For the defense industrial base, CMMC requires a senior official to affirm compliance, and the False Claims Act holds contractors liable when those affirmations prove false.

The session closes on the two threats most likely to reach the boardroom next: an AI failure and a cloned-voice message from the CEO. Directors leave knowing which questions to ask, when to ask them, and how to document the answers. The session stays vendor-neutral throughout.

Secure checkout on PayPal. Pay with PayPal or card, and choose your number of seats at checkout.
What Each Director Takes Home
Who Should Be in the Room

This session is built for the people who oversee the program: board members and trustees, especially audit and risk committee chairs; corporate secretaries and board governance counsel; CEOs, general counsel, and CISOs who brief the board; federal advisory board and commission members with oversight duties. It is not a technical course, and no security background is required.

Executive Sessions

Private Sessions for Boards and Senior Leaders

Executives want clear insight and honest answers to hard questions. Dewayne delivers both in his executive sessions and private masterclasses.

These smaller settings allow deeper content than a traditional keynote and a conversational format that experienced leaders appreciate. Dewayne’s executive sessions can serve a senior leadership team, a board of directors, or CEO and CISO gatherings, where candid insight and proven strategy deliver the value seasoned leaders expect.

Senior Leadership Teams

Align the C-suite on cyber risk, AI adoption, and what the security program must deliver this year.

Boards of Directors

Give directors the questions to ask, the answers to expect, and a clear view of the organization’s exposure.

CEO & CISO Gatherings

Candid insight and proven strategy for summits and retreats where experienced leaders expect real value.

Executive sessions built on must-know insight, frameworks, and strategy

Dewayne designs these sessions for smaller groups, with more depth and interaction tailored to the responsibilities and priorities of the people in the room. In the longer formats, he works closely with your senior leaders on their most urgent security decisions.

30 min

Insight Session

The must-know risks and decisions for your leaders, delivered at the top of a meeting or retreat.

90 min

Executive Briefing

Deeper insight and discussion on one priority, with time for your leaders’ toughest questions.

Half day

Private Masterclass

The must-know risks and decisions for your leaders, delivered at the top of a meeting or retreat.

Customized to Your Priorities

Each session is customized to your audience, meeting, areas of focus, and strategic priorities.

AI risk & secure adoption

Exposure management

Cyber readiness & board reporting

Security culture that holds under pressure

Plan a session for your leaders

Dewayne has advised leaders at the Department of Veterans Affairs, the U.S. Army, Duke Energy, PwC, Kaiser Permanente, and Wells Fargo, and has spoken at the National Cybersecurity Summit and the GDS Group Security North America Summit. Every engagement begins with a planning call, so his message, depth, and style of interaction match your vision.

Books by Dewayne Hart

You Can Also Buy Dewayne's Books

Keep the insight working after the session ends. Cybersecurity Leadership, The Cybersecurity Mindset, and CISSP Practice Questions & Explanations give leaders and practitioners the mindset, the leadership, and the credential. Bulk orders are available to give every attendee the same playbook.

Questions

Masterclass FAQ

Cannot find your answer? Dewayne personally reviews every inquiry.

How do I register?

Select See More on any masterclass, then Register Now with PayPal. Choose your number of seats and complete payment on PayPal. Your PayPal receipt is your registration confirmation, and class details will follow by email.
PayPal checkout lets you pay with your PayPal balance or a debit or credit card.

Yes. Group seats for leadership teams are available. You can choose multiple seats at PayPal checkout, then email attendee names to dewaynehart@dewaynehart.com. For group rates or to pay by invoice, email dewaynehart@dewaynehart.com or call (470) 409-8316.

Yes. Each executive masterclass is a half-day session that awards 4 CPE credits: The Big 4 Model: Winning Cyber Defense Under Pressure, Governing AI and Cybersecurity Before the Attack, and The Duty of Inquiry: Board Oversight of Cyber and AI Risk. Every session includes a Certificate of Completion.

Email dewaynehart@dewaynehart.com before the class. You can also transfer your seat to a colleague at no cost.
Scroll to Top