Jason Hartley is lecturer in criminology at Griffith University in Brisbane, Australia. He is a former police officer with 23 years of experience, and has trained personnel for deployment in Timor Leste, the Solomon Islands, Iraq and Afghanistan. Jason specializes in, and has published on engagement with Muslim communities, Indigenous Polynesian approaches to rehabilitation and reducing recidivism, and Asian Organised Crime. Jason also completed a community internship in Hebron on the West Bank.
ITC515 Cybersecurity Strategy and Enterprise-Risk Leadership
This unit covers the knowledge and skills required to formulate, justify and communicate enterprise-level cybersecurity strategy. Students are equipped to integrate cyber-risk analysis with organisational objectives, design multi-year security programs, and influence executive decision-makers. The unit emphasises adversarial thinking, value-at-risk modelling, cost–benefit justification, and crisis-leadership techniques that underpin Chief Information Security Officer practice.
RELEVANT COURSES
* Core unit
CREDIT POINTS
10
STUDY MODES
On campus, online, hybrid
PREREQUISITE OR CO-REQUISITE
ITC404 Foundations of Cybersecurity and ITC534 Information Technology Project Management
UNIT LEARNING OUTCOMES
- Critically analyse key enterprise-level cybersecurity strategies
- Critically evaluate risk-treatment options using quantitative and qualitative methods to optimise security investment
- Critically analyse organisational contexts to identify cyber-risk drivers and business impacts
- Design an evidence-based multi-year cybersecurity strategy and program roadmap aligned with enterprise objectives
- Justify cybersecurity recommendations to persuade industry executives
CONTENT
- Cyber-risk landscape and value-at-risk models (FAIR, ISO 27005)
- Risk appetite statements and board reporting
- Strategy frameworks (NIST CSF, SABSA, ISO 27001)
- Security economics and cost–benefit analysis
- Program and portfolio management (OKRs, KPIs)
- Adversarial thinking and threat-led defence (red-team insights)
- Cyber-culture, stakeholder engagement and change leadership
- Crisis-communication and media strategy
- Regulatory alignment and assurance (ASD Essential Eight, APRA 234)
- Metrics-driven performance and continuous improvement
- Executive simulation lab: ransomware board exercise
- Current issues and emerging strategic trends (AI governance, quantum risk)
ASSESSMENT METHODS
- Risk-Landscape Report – 20%
- Group Strategy and Program Roadmap – 40%
- Exam – 40%
PRESCRIBED READINGS
Check with the lecturer each semester before purchasing any texts












