Overview
Cyber incidents are no longer purely technical events. They can affect service delivery, community trust, sensitive information, third-party relationships, public communications and executive decision-making.
In 2024–25, ASD’s Australian Cyber Security Centre received more than 84,700 cybercrime reports, around one report every six minutes, and responded to more than 1,200 cyber security incidents.
For councils, this pressure is often amplified by practical resourcing realities. Many are expected to protect important services, community data and public trust with small teams, constrained budgets, shared platforms, managed service providers and limited access to enterprise-level cyber capability.
Cyber readiness therefore requires more than an incident response plan. It requires a clear understanding of the services and information that matter most, the threats most likely to create material consequences, the privacy and data breach decisions that may arise, the level of risk the organisation is prepared to tolerate, and the way teams coordinate when facts are incomplete.
This two-part program helps local government leaders and managers strengthen practical cyber readiness. Day 1 focuses on readiness foundations, including business context, credible threats, AI-related risks, privacy and data breach considerations, cyber risk appetite, decision authority and response coordination. Day 2 applies the learning through a realistic incident simulation and provides guidance on how participants can design and run effective tabletop exercises in their own organisations.
The program is designed for managers and functional leaders who may need to lead, support or coordinate during a cyber incident. It builds the practical judgement, shared language and coordination capability needed to respond more effectively when cyber incidents occur, including where AI-enabled deception, tools, services and automation create additional response considerations.
Who Should Attend?
This program is designed for local government participants involved in cyber readiness, incident response, service continuity, governance or decision-making. This is not a technical incident response training course. Relevant participants include:
ICT Managers, Cyber Security Advisors and technology leaders
Risk, governance, compliance and internal audit stakeholders
Business continuity and emergency management leads
Privacy, records and information management leads
Communications, media and community engagement leads
Procurement, vendor and contract management leads
Operational leaders responsible for critical services
Elected members or executive office stakeholders requiring visibility of incident readiness
Learning Outcomes
By the end of this course, you will be able to:
Assess cyber readiness in a council context by identifying the critical services, sensitive information, systems, third-party dependencies and operating constraints that shape incident response
Recognise cyber threats that create operational and governance impacts including risks affecting service continuity, privacy, communications, community trust and executive decision-making
Apply cyber risk appetite to incident decisions including escalation, containment, continuity, communication, recovery and public trust considerations when facts are incomplete
Clarify roles, responsibilities and decision authority across ICT, executive, risk, privacy, communications, operations and vendor management during a cyber incident
Coordinate practical incident response activity by structuring incident updates, decision records, executive briefings and improvement actions in a clear and usable way
Participate effectively in a realistic cyber incident exercise that tests escalation, communication, continuity, coordination and recovery decision-making under pressure
Design and improve future tabletop exercises by translating exercise observations into practical, repeatable improvements for council cyber resilience
In-person Training
Local Government Cyber Incident Response Simulation
Session details
- Move beyond cyber awareness into practical readiness. Learn how cyber incidents affect real council operations, including service delivery, community trust, sensitive information, public communications and executive decision-making.
- Strengthen readiness for local government operating realities. Explore how councils can prepare for incidents despite constrained resources, shared platforms, managed service providers and limited specialist cyber capability.
- Improve decision-making under pressure. Practise using risk appetite, escalation pathways and decision authority to make better choices when information is incomplete and time is limited.
- Build confidence across the whole response team. Cyber incidents are not just ICT events. This program helps risk, privacy, communications, operations and vendor-facing roles coordinate more effectively.
- Prepare for AI-enabled cyber threats. Understand how emerging AI-related risks can complicate verification, communications, escalation and response.
- Test response capability through a realistic simulation. Work through a council-relevant incident scenario involving disruption, third-party dependency, possible data exposure and stakeholder pressure.
- Leave with practical structures you can adapt. Take away approaches for incident updates, decision records, executive briefings, tabletop exercises and post-exercise improvement planning.
Some familiarity with topic is recommended
Key Sessions
• Critical services, sensitive information, systems and third-party dependencies that shape cyber readiness
• Council operating realities, including resourcing constraints, shared platforms and reliance on external providers
• What practical readiness needs to look like before an incident occurs
• Cyber threats most likely to create operational, privacy, governance or service continuity impacts
• AI-related considerations, including synthetic communications, frontier models, tools, automation, prompt injection and emerging agentic use cases where relevant
• Practical verification and escalation challenges as threats, tools and business processes evolve
• How risk appetite informs escalation, containment, continuity, communication and recovery decisions
• Privacy, records and data breach considerations that may arise during an incident
• Decision authority across ICT, executive, risk, privacy, communications, operations and vendors
• Coordinating internal teams and external parties, including vendors, insurers, advisers, agencies and law enforcement
• Maintaining a clear operating picture, update rhythm and executive briefing approach
• Applying readiness concepts to practical incident response and service continuity decisions
- How the simulation will work and what participants are expected to practise
- Applying business context, risk appetite, escalation and communication disciplines during the exercise
Practical incident simulation
- A realistic incident scenario reflecting real world conditions and events
- Escalation, communication, continuity and recovery decisions under pressure
- What the exercise revealed about readiness, roles, decisions and coordination
- Recovery, resilience and post-incident improvement considerations
- How to build repeatable tabletop capability and turn observations into action
• What the exercise revealed about readiness, roles, decisions and coordination
• Recovery, resilience and post-incident improvement considerations
• How to build repeatable tabletop capability and turn observations into action
Meet Your Facilitator
Chirag Joshi
Founder and CEO, 7 Rules Cyber Pty Ltd
Chirag Joshi is a globally recognised cyber security and AI governance leader, Board advisor, bestselling author and Founder of 7 Rules Cyber, a strategic advisory firm helping organisations build defensible, efficient and business-aligned security capability.
He advises boards, executives and senior leaders across government, critical infrastructure, financial services, energy, higher education, consulting and the not-for-profit sector. His work focuses on cyber strategy, governance, resilience, incident readiness, executive decision-making, cyber risk quantification, and secure AI adoption.
Chirag is known for translating complex cyber issues into practical leadership decisions. He helps organisations strengthen cyber readiness by preparing leaders to make clear, defensible decisions during cyber incidents, service disruption, and emerging AI risk.
Chirag is a Fellow of the Australian Information Security Association, a Member of the Australian Institute of Company Directors, President of ISACA Sydney, and National Ambassador for the Critical Infrastructure ISAC Australia. He regularly speaks and writes on cyber governance, resilience, AI risk and the leadership decisions required to build trust in a rapidly changing digital environment.
Register Today
Join this training for professionals working within the Public Sector
Extra Early Bird
Ends 4 Sep
$A 795
per person + tax $400 savingEarly Bird
Ends 2 Oct
$A 995
per person + tax $200 savingRegular
Ends 17 Nov
$A 1195
per person + taxFor group or payment enquiries or custom training solutions, please contact [email protected]
Customised in-house options available for teams
Interested in any of our online trainings?
You can also choose to have them delivered in house. We will work closely with our inspiring session facilitators to tailor the content around the key development areas your team are prioritising, shape the learning outcomes around your core departmental challenges and make the most of your L&D and upskilling budget.
Can't see what you need?
Download our training catalogue to review all available topics