Chief Information Security Officer (CISO) Certificate
The role of the CISO is gaining in prominence. Are you ready?
"The Carnegie Mellon CISO Program helped me expand my perspective beyond cybersecurity operations to the broader leadership, risk, and business challenges facing today's security executives. The combination of world-class faculty, experienced practitioners, and an exceptional network of peers makes it one of the most valuable professional development experiences available to current and aspiring CISOs."
John Gift
SVP and Global CISO, PepsiCo and CMU CISO Program Alumnus
CISO Calendar and Curriculum Details
Applications are currently being accepted for Cohort 27, which begins September 2026.
Virtual Orientation: 12:00 - 5:00 p.m. EDT
September 9-10, 2026
Virtual Modules: 4:00 - 9:00 p.m. EDT
(Note: all virtual class dates are Thursdays)
September 24 (2026)
October 8, 15, 22, 29 (2026)
Program Mid-Session: 9:00 a.m. - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
November 3-4, 2026
Virtual Modules: 4:00 - 9:00 p.m. EST
(Note: all virtual class dates are Thursdays)
November 12, 19 (2026)
December 3, 10, 17 (2026)
January 7, 14, 21, 28 (2027)
Practicum: 9:00 a.m.- 5:00 p.m. EST (Pittsburgh, PA; virtual option available)
February 24-25, 2027
Virtual Orientation: 12:00 - 5:00 p.m. EST
January 14-16, 2026
Virtual Modules: 4:00 - 9:00 p.m. EST
(Note: all virtual class dates are Thursdays)
January 22, 29 (2026)
February 5, 12, 19 (2026)
Program Mid-Session: 9:00 a.m. - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
March 9-11, 2026
Virtual Modules: 4:00 - 9:00 p.m. EDT
(Note: all virtual class dates are Thursdays)
March 26 (2026)
April 2, 9, 23 (2026)
May 7, 14, 21 (2026)
June 4, 11 (2026)
Practicum: 9:00 a.m.- 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
June 17-18, 2026
The program mid-session and practicum will be held in person at our main campus in Pittsburgh:
Heinz College of Information Systems and Public Policy
Carnegie Mellon University
4800 Forbes Avenue
Pittsburgh, PA 15213
A virtual option will be offered for the program mid-session and practicum; students will not be required to travel to complete the program.
Earning your executive education certificate is just the beginning of a lifelong relationship with CMU; we're here to help you advance your career throughout your professional life. The Heinz College Executive Advantage program is meant for people who always want to be ahead of the curve—those who want to lead the conversation, not just be a part of it.
Executive Advantage was designed with you—C-suite executives and lifelong learners—in mind. In addition to the valuable skills you gain through our executive certificate programs, you now have access to workshops, leadership summits, and conferences.
Benefits, Discounts, and the Fine Print
Future Modules Benefit
Graduates of the Chief Information Security Officer Certificate Program will have access to new CISO Program modules created in the future, providing you with continuing education after the program ends. Approval is required.
Please note: This benefit does not extend to future CIO, CRO, CDAIO, or CDigitalO program modules, unless the student is also a graduate of those programs.
MSIT Program Discount
Students who complete the Chief Information Security Officer Certificate Program and who subsequently apply for and are admitted into the Heinz College MSIT Degree Program are eligible for a tuition discount scholarship. Program costs that have been paid for completing any or all of the Heinz College Executive Education certificate programs (up to $40,000) by the individual student or their sponsor/employer will be matched with a tuition discount from the MSIT program — reducing the cost to complete the MSIT degree by up to $40,000.
In order to be considered, applicants to the MSIT program should indicate their enrollment status with the CIO, CISO, CRO, CDAIO, and/or CDigitalO program(s) on the Application for Admission.
Please note: The tuition discount is only available once a student has completed all of the certificate program’s requirements. Completion of a certificate program does not guarantee admission to the MSIT program.
Cancellation/Refund Policy
A non-refundable, non-transferable deposit of 1/6 of the total program cost is required to reserve a seat in the program.
Should a student withdraw from the program after the deposit has been paid but prior to the program start date, students may have 5/6 of the program costs either refunded to them or transferred to the following cohort of the program.
After the program start date, no refunds will be issued. However, under extenuating circumstances and with program director approval, students may petition to postpone their attendance to a future cohort and have 5/6 of the program costs applied accordingly.
Hear From Our Program Alumni
Find out how earning the CISO certificate can help your career.
My Story: Joe
Earning a Chief Information Security Officer certificate from Heinz College helped Joe Lewis become the CISO of the Centers for Disease Control and Prevention.
"This was the right direction to go."
CISOs Patrick Forbes of S&P Global and Corey T. Jackson of the Travelers Companies talk about what they gained from the program, and what executive training from CMU has meant to their careers.
Chief Information Security Officer Curriculum
Instructor:
Alan Levine | Board Chair, Carnegie Mellon University CISO Executive Program
This module is focused on discussing the CISO roles and responsibilities; how the CISO integrates effectively in organizational governance and operations; and leadership and management practices that enhance the ability of today’s CISO to succeed in any organization. This module will help to set the stage for the overall CISO certificate program and the modules that follow.
Instructor:
Dr. Earl Crane | Owner, Risk Executive/Strategic Advisor, Earl Crane LLC
This module will provide an overview of advanced cyber risk management concepts and techniques, and then provide a tangible deep-dive into real-world examples and scenarios. Students will be asked to bring their real-world expertise and risk management challenges to share with their colleagues. Discussions will include an overview of cyber risk management frameworks, relevant regulations, and available tools. We will cover the three lines of defense, the latest thinking in risk-based assessments, and how to represent cyber risk as a decision-making framework for business unit leaders, executives, and your board.
Instructor:
Matt Butkovic | Technical Director of Cybersecurity Risk and Resilience, CERT Division of SEI
This module examines how organizations build and sustain resilience in the face of cyber incidents, operational disruptions, technology failures, and other business-impacting events. Participants will explore the principles of cyber resilience, operational resilience, and resilience management, with a focus on maintaining critical business services during periods of disruption. Using Supply Chain Risk Management (SCRM) as a practical exemplar, the module highlights the challenges of managing resilience when critical technologies, data, personnel, facilities, and services are provided by external partners and third parties. Participants will learn how leading organizations identify critical dependencies, assess risk across interconnected ecosystems, strengthen resilience capabilities, and prepare for effective response and recovery when disruptions occur.
Instructor:
Randy Trzeciak | Director, CERT Insider Threat Center at SEI
Insider threats are influenced by a combination of technical, behavioral, and organizational issues and must be addressed by policies, procedures, and technologies. Decision makers across the enterprise should understand the overall scope of the insider threat problem and communicate it to all the organization’s employees. This module discusses how organizations can effectively mitigate the potential of insider threats and build an effective program.
Instructor:
Greg Porter | Adjunct Professor, Carnegie Mellon University's Heinz College; Founder, Allegheny Digital
This module will begin with an overview of the current threat landscape and examine the array of adversary classes facing organizations. The session will then provide CISO students with a pragmatic overview of common issues and challenges in developing, maintaining, and operating an effective incident management and forensics capability. The module will also cover the current state of security operations center best practices, and will conclude with an overview of supporting frameworks, and the types of tools and infrastructure needed to be effective to respond to cyber incidents and increase end-users' resilience.
Instructor:
Matt Meade | Chair, Cybersecurity, Data Protection & Privacy Group, Eckert Seamans
Larry Kamer | CEO, Kamer Consulting Group
While CISOs are well-prepared to handle IT and forensic issues, guidance on the legal consequences and legal obligations is often siloed to in-house counsel and not part of a collaborative effort. Through this practical and interactive session, students will learn about the legal aspects of a proactive approach to cybersecurity; state and federal law issues associated with responding and reacting to a security incident; and litigation and regulatory investigations arising from data breaches. This module also explores the CISO’s role in developing and executing an effective internal and external communications strategy when faced with a large-scale breach that impacts the operations of the organization. This module will reference various relevant case studies to help students develop a comprehensive approach.
Instructor:
Omar Khawaja | VP and Field CISO, Databricks
This module is an overview of practical “day-to-day" operations. The module will cover how to properly plan, structure, and report on your security team, as well as obtain “buy-in” from your organization. This clear outline of the security structure will better enable CISOs to demonstrate the charter and effectiveness of the security team to their organizations.
Instructor:
Brigadier General (ret.) Gregory J. Touhill | Director, CERT Division at the Software Engineering Institute
This module is focused on the requirement for today’s CISOs to develop a budget that aligns with the annual strategic planning process and is supported by key organizational stakeholders. This often needs to be developed in environments with significant third-party managed services and where growth strategies include regular business acquisitions and divestitures.
Instructor:
Summer Fowler | Corporate Vice President and Principal – Exponent
Effective cybersecurity leadership requires the ability to translate technical activities into meaningful business insights that inform decision-making, risk management, and organizational performance. This module explores how security leaders establish governance mechanisms, develop risk-informed metrics, and create executive reporting practices that demonstrate the effectiveness of cybersecurity programs and support strategic business objectives.
Instructor:
Rick Howard | CEO of the Cybersecurity Canon Project; former CSO – Palo Alto Networks
Jack Jones | Chairman Emeritus of the FAIR Institute
In today’s rapidly evolving threat landscape, CISOs must move beyond reactive defense and incremental controls. This module provides a strategic reset by returning to core cybersecurity "first principles" — foundational truths that endure regardless of new technologies or attack vectors. Participants will explore how to apply these principles to reframe both strategy and day-to-day tactics in a way that aligns with business objectives, reduces complexity, and increases resilience. This module will also assist students, via the FAIR methodology, to accurately assess IT and cybersecurity loss exposure, to learn how to identify the significance of control weaknesses, determine how to optimize security budgets and priorities, and understand how to support governance and compliance requirements.
Instructor:
Dennis Allen | Founder and Principal Consultant, Green Owl Cyber
This module is designed to equip students with the knowledge and skills necessary to understand, design, and implement robust cybersecurity architectures and leverage essential cybersecurity tools effectively. The module will guide you through the tooling selection process and discuss configuration and implementation best practices of the right technologies based on your needs.
Instructor:
Rich Friedberg | CISO, Envestnet
Mark Fabro | President and Chief Security Strategist, Lofty Perch, Inc.
As more organizations embrace the benefits of cloud-based infrastructures and services, they face significant challenges in how to secure their information and applications. This module will examine the changes to risks, threats, and vulnerabilities when companies move from on-prem to cloud services. The module will also discuss how to develop a business-focused security strategy to balance enabling transformation with protecting the organization through their cloud journey.
This module will also address specific OT and IIOT concerns faced by organizations and their supply-chain partners. It is designed to explore best practices used by industry to ensure that OT and IIOT achieves functional goals and meets security requirements.
Instructor:
Josh Corman | Executive in Residence for Public Safety & Resilience at the Institute for Security and Technology (IST)
As organizations increasingly rely on internally developed software, commercial products, open-source components, and AI-enabled applications, vulnerability management has evolved beyond patching systems to become a strategic capability that supports secure development, product security, and enterprise risk management. This module examines how security leaders can build and operationalize modern vulnerability management programs that effectively identify, prioritize, remediate, and communicate software and product security risks.
Instructor:
Bob Rudis | Distinguished Engineer, Censys; former V.P. Data Science, Security Research, & Detection Engineering, GreyNoise Intelligence
In an era of rapidly evolving threats, data-driven threat intelligence is essential for proactive and informed cybersecurity leadership. This module equips CISOs with the frameworks and tools to harness internal and external data sources — such as telemetry, behavioral analytics, open-source intelligence (OSINT), and threat feeds — to generate actionable insights. Participants will explore methods for operationalizing threat intelligence, integrating it into risk management strategies, and aligning intelligence programs with business objectives. Through case studies and practical exercises, the module emphasizes the strategic value of intelligence-led decision-making in anticipating threats, reducing risk, and enhancing organizational resilience.
Instructor:
Omar Khawaja | VP and Field CISO, Databricks
As organizations rapidly adopt generative AI, large language models, machine learning, and other AI-enabled capabilities, leaders must address a new set of security, governance, operational, and ethical challenges. This module provides a practical framework for managing AI-related risks while enabling innovation and business value creation. Participants will examine how organizations establish governance structures, secure AI systems and data, manage model risks, and implement responsible AI practices across the enterprise.
Instructor:
Chris Hughes | VP of Security Strategy – Zenity; author of Securing Agentic AI
This module examines the unique risks associated with agentic AI systems and provides leaders with practical frameworks for securing, governing, and assuring autonomous and semi-autonomous AI capabilities. Participants will explore how to establish trust, maintain human oversight, manage delegated authority, secure AI-enabled workflows, and implement controls that ensure AI systems operate safely, reliably, and in alignment with organizational objectives and risk tolerance.
Instructor:
Matt Butkovic | Technical Director of Cybersecurity Risk and Resilience, CERT Division of SEI
This module explores the practical application of AI across the cybersecurity lifecycle, focusing on how organizations can use machine learning, generative AI, and advanced analytics to improve threat detection, security operations, vulnerability management, incident response, and cyber resilience. Participants will examine real-world use cases, implementation considerations, and emerging best practices for integrating AI into modern security programs while maintaining appropriate governance, oversight, and human decision-making.
To further enrich the CISO Program, participants will have the opportunity to engage with industry experts, thought leaders, and practitioners through a series of robust guest lectures. These sessions will provide cutting-edge insights on critical and emerging topics, including:
Cyber Insurance Landscape — this guest lecture provides an executive-level overview of the evolving cyber insurance market and its role in enterprise risk management. Participants will explore underwriting trends, coverage considerations, claims experiences, and how cybersecurity maturity influences insurability, pricing, and organizational resilience.
Effective Executive Presentations and Influence — this guest lecture focuses on the communication skills required to effectively engage executives, boards, and other senior stakeholders. Participants will learn how to craft compelling messages, communicate complex topics with clarity, influence decision-making, and deliver impactful presentations that drive alignment, action, and organizational outcomes.
Vendor Management/Contract Negotiations — this guest lecture examines leading practices for managing strategic vendor relationships and negotiating contracts that align with organizational objectives. Participants will explore approaches for evaluating vendors, managing performance, mitigating risk, and negotiating commercial, operational, and security requirements to achieve successful long-term partnerships and business outcomes.
Cyber Defense Matrix — this guest lecture introduces the Cyber Defense Matrix, developed by Dr. Sounil Yu, as a practical framework for organizing, assessing, and communicating cybersecurity capabilities across the enterprise. Participants will learn how the framework can be used to align security investments with business objectives, identify capability gaps, prioritize strategic initiatives, and enhance executive and board-level discussions around cybersecurity risk and resilience.
These guest lectures will complement the core curriculum, ensuring that participants receive real-world perspectives, actionable strategies, and executive-level insights from those shaping the future of cybersecurity leadership.
"The most effective CISOs are those who can bridge cybersecurity, business strategy, and executive decision-making. The practicum provides participants with a unique opportunity to apply what they learn to real-world challenges while receiving guidance from experienced security leaders who have spent decades managing risk, leading organizations, and advising executives and boards."
Darrell Keeling
Executive Coach and CISO Program Alumnus
Frequently Asked Questions
Q: What is a Chief Information Security Officer (CISO) certificate program?
A: Chief Information Security Officer (CISO) certificate programs are designed to prepare cybersecurity leaders to manage enterprise security strategy, governance, and risk. These programs are geared toward senior leaders and typically focus on leadership skills, cybersecurity strategy, incident response, and communication with executive leadership and boards.
The CISO Certificate Program at Carnegie Mellon University’s Heinz College combines practical cybersecurity frameworks with leadership training to help experienced professionals strengthen their ability to lead enterprise security programs.
Q: What skills does a Chief Information Security Officer need today?
A: Modern CISOs must combine technical cybersecurity expertise with strategic leadership skills.
Key capabilities include:
- Creating and implementing enterprise cybersecurity strategy
- Risk management and governance
- Incident response leadership
- Communication with executive leadership and boards
- Regulatory and compliance awareness
Carnegie Mellon’s CISO Certificate program helps experienced professionals develop these leadership capabilities while strengthening their technical security perspective.
Q: What's the difference between a CISO and a CIO?
A: While both roles require leadership and strategic thinking, the CISO role is more specialized in cybersecurity, whereas the CIO or CIDO role has a broader organizational technology focus.
- Chief Information Security Officers focus on security, risk, and compliance — protecting organizational assets from cyber threats.
- Chief Information Officers/Chief Information & Digital Officers focus on technology strategy, innovation, and IT alignment—leveraging technology to achieve business goals.
Q: Who should attend a CISO executive education program?
A: CISO executive education programs are designed for experienced cybersecurity and technology professionals who want to strengthen their ability to lead security programs at the enterprise level.
Participants often include:
- Current or aspiring Chief Information Security Officers
- Cybersecurity directors and security architects
- Senior IT or risk leaders responsible for enterprise security
- Government or defense cybersecurity professionals
These programs help leaders expand their strategic, governance, and communication capabilities beyond technical security expertise.
Q: How long does the Carnegie Mellon CISO Certificate Program take to complete?
A: The CISO Certificate Program at Carnegie Mellon University is a six-month executive education program that combines synchronous virtual learning with in-person sessions. The format allows working professionals to develop advanced cybersecurity leadership skills while continuing in their current roles.
Q: What makes the Carnegie Mellon CISO program unique?
A: Carnegie Mellon’s CISO Certificate Program combines executive leadership training with deep cybersecurity expertise from Heinz College and the CERT Division of the Software Engineering Institute.
Participants benefit from:
- Instruction from faculty and industry leaders with real-world cybersecurity experience
- Practical case studies and applied frameworks
- A cohort of experienced cybersecurity professionals from multiple sectors
This interdisciplinary approach helps leaders translate technical cybersecurity knowledge into enterprise strategy.
Q: How does this program help professionals advance to a CISO role?
A: CMU's CISO program helps professionals transition from technical security roles to executive cybersecurity leadership by strengthening skills in governance, risk management, communication, and organizational strategy.
Participants learn how to:
- Align cybersecurity initiatives with business objectives
- Communicate cyber risk to executives and boards
- Lead cross-functional security programs
- Build resilient cybersecurity strategies across complex organizations
Not Sure the CISO Program Is Right for You?
Explore our suite of executive education open-enrollment programs to find the one that best fits you:
- CDAIO Certificate (Chief Data And AI Officer)
- CIDO Certificate (Chief Information and Digital Officer)
- CRO Certificate (Chief Risk Officer)
- LEAAID Certificate (Leading Enterprise Agentic AI Development Program)
Additionally, the Master of Science in Information Technology (MSIT) is our part-time online program for professionals seeking graduate degrees in IT; Heinz certificate program graduates are eligible for a MSIT tuition discount.
What's Next?
Have questions? Reach out to us to find out more:
- Email: heinzexeced@cmu.edu
- Phone: David Ulicne, Executive Director — 412-268-5543
- Phone: Emily Brown, Director — 412-268-6730
Check out our detailed program guide.
Ready to apply?
Contact Us
Heinz College Executive Education
Carnegie Mellon University
5000 Forbes Ave
Hamburg Hall
Pittsburgh, PA 15213-3890
heinzexeced@cmu.edu