Compliance Programme Hub
Guide a business through ISO 27001, SOC 2, CMMC, PCI DSS, HIPAA, GDPR and AI governance with eight structured stages.
Build your compliance programmeI help organisations build practical cybersecurity and GRC programmes, design meaningful InfoSec curricula, and develop the people who put them to work.

Guided tools for organisations improving their security and practitioners building skills. Explore the full toolkit or choose a starting point below.
Assess access, vulnerabilities, suppliers, audits, privacy, cloud security and more. Follow professional guidance, link business evidence and download CyberJA-branded working documents.
Guide a business through ISO 27001, SOC 2, CMMC, PCI DSS, HIPAA, GDPR and AI governance with eight structured stages.
Build your compliance programmeWork through data security, impact analysis, network design, cloud protection, monitoring and forensic investigation.
Start your Cybersecurity JourneyBring documented completed tasks into your skills and project sections, then review and personalise your resume.
Build your professional CVUse CyberJA Continuity to develop BCP and DR plans around your business processes and the systems they depend on.
Free to use. Your planning information stays in your browser.
Practise twelve workplace decisions in governance, risk, compliance and leadership. Find your next step in Cybersecurity & GRC.
For organisations building stronger security, institutions developing relevant curricula, and professionals growing their skills.
Connect security decisions to business objectives. Understand your risks, clarify accountability, and build governance practices your organisation can put to work.
Discuss your GRC priorities (opens in a new tab)Risk assessments, maturity reviews, and a clear view of your priorities.
Access approvals, lifecycle workflows, reviews, and accountability.
Practical policies, procedures, and control guidance aligned to your context.
Evidence preparation, gap analysis, and prioritized remediation planning.
Build a program around your business assets, risks, and operational needs. Bring people, processes, and technology together with clear ownership and achievable priorities.
Discuss your security program (opens in a new tab)Identify critical assets, business dependencies, and security gaps.
Define objectives, responsibilities, and a phased implementation plan.
Develop control practices, incident response plans, and awareness activities.
Use reporting, reviews, and remediation tracking to guide ongoing improvement.
Give learners a clear path from understanding concepts to applying them. Develop structured InfoSec curricula for educational institutions, training providers, and organisational teams.
Discuss a curriculum project (opens in a new tab)Audience needs, learning outcomes, module sequencing, and delivery plans.
Lecture materials, workbooks, teaching guides, and supporting templates.
Hands-on activities that connect security concepts to real business problems.
Quizzes, practical tasks, grading rubrics, and learner feedback tools.
Explore self-paced courses or discuss a workshop built around your team’s goals. Apply cybersecurity and GRC concepts through practical examples, assessments, and guided discussion.
Workflows, lifecycle management, and governance in practice.
View course on Udemy (opens in a new tab)ASSESSMENTS & ASSURANCEDevelop a practical approach to assessing security and GRC.
View course on Udemy (opens in a new tab)SECURITY ARCHITECTUREReadiness, strategy, and implementation in cloud and on-premises environments.
View course on Udemy (opens in a new tab)Practical. Business-focused. Built around your context.
Examples of the frameworks, learning materials and structured thinking I bring to an engagement.
A practical approach to onboarding, access approvals, role design, access reviews and offboarding.
Illustrative teaching scenario
A new finance analyst needs access to financial reports. The manager confirms the business need; the data owner approves a suitable role; IT provisions access after policy checks.
Connect critical assets, risk decisions, control ownership and reporting in a manageable security program.
Illustrative 90-day starting plan
The schedule is adapted to each organisation’s risk, resources and starting point.
Discuss your program (opens in a new tab)Understand · Apply · Assess
A 30-hour Cybersecurity Principles and Fundamentals learning plan built around business scenarios and practical tasks.
Teaching and curriculum example
Progress through cybersecurity fundamentals, threats, security principles, networks, operating systems, tools, risk and incident response, legal and ethical issues, and emerging technologies.
Learners connect assets, vulnerabilities, threats, business impact and controls through scenarios, guided labs, quizzes and assessment rubrics.
Discuss a curriculum project (opens in a new tab)These are sample approaches and teaching examples, rather than named client case studies.
Whether we are shaping a security program or a learning experience, we start with what you need to achieve.
Discuss your business, audience, priorities and current challenges.
Define the outcomes, deliverables, responsibilities and timeline together.
Build practical guidance, program materials or learning resources around your context.
Walk through the deliverables and agree how progress and improvements will be reviewed.
Build practical capability in governance, assessments and security implementation, at your own pace or with guided instruction.
Develop lifecycle workflows, access approvals and governance practices across cloud environments.
View course (opens in a new tab)Connect evidence, security gaps and business risk through structured assessment practice.
View course (opens in a new tab)Explore readiness, strategy and implementation in cloud and on-premises environments.
View course (opens in a new tab)Discuss instructor-led sessions in IAM governance, risk assessment, GRC or cybersecurity fundamentals, with relevant scenarios and practical activities.
See how CyberJA courses and tools support 17 certification options, with official guidance and clear additional study needs.
Download useful working resources, watch a practical introduction and explore the official frameworks behind your learning.
Explore free practical tools to start your cyber journey or strengthen your existing expertise.
PDF guideUnderstand common roles, essential skills and where to start.
Get the free resource
Excel workbookPractise identifying risks, assessing impact and recommending controls.
Get the free resource
PDF checklistReview access approvals, excessive permissions and employee offboarding.
Get the free resource
PDF guide · Word editionBuild practical skills with ten tools, learning exercises and a CyberJA course catalogue with workplace context.
Download the free PDF guideExplore the foundations behind practical Cybersecurity & GRC skills.

I bring cybersecurity, governance and education together to help organisations and learners move forward with clarity.
My work spans IT and information security across the petroleum, hospitality and education sectors. I connect technical controls to business priorities, and make complex concepts accessible through practical scenarios and structured learning.
As a consultant, curriculum developer, instructor and CyberJA podcast host, I focus on useful outcomes: clearer accountability, stronger security programs and people who can apply what they learn.
Background listed on my consultation profile (opens in a new tab) and instructor profile (opens in a new tab).
Consultation feedback and course reviews reflect different experiences. Explore each at its source.
Praised the professionalism and knowledge shared during the session.
Summary of publicly posted consultation feedback
Based on 10 public ratings, checked October 2026. Ratings apply to this course.
Read learner reviews (opens in a new tab)Read, listen and explore practical perspectives on cybersecurity, governance and professional growth.
A CyberJA edition exploring modern identity assurance, cloud risk and practical assessment questions.
Read the magazine (PDF, opens in a new tab)Download PDFMy conversation with Dejan Kosutic on the Secure & Simple podcast, covering course creation, communication and building a consulting practice.
Listen to the interview (opens in a new tab)A reflection on why understanding business risk should guide how we apply security controls.
Read the article (opens in a new tab)Get an alert when a new CyberJA cybersecurity and GRC publication is available. Choose the channels that suit you.
Subscribe to CyberJA publication alerts. Confirm your email to activate your subscription.
Used only for publication alerts. Confirmation may take up to an hour. Unsubscribe from any email.
Allow this browser to notify you when a new CyberJA publication is available. No email address required.
Availability depends on your browser, device and notification settings.
Follow Richea Perry on LinkedIn, then use the profile’s notification bell to choose how often you hear from me.
Follow on LinkedIn (opens in a new tab)LinkedIn manages these notifications through your account settings.
Your security program. Your curriculum. Your team’s capability. Let’s start with your goals.