Jason Hartley is lecturer in criminology at Griffith University in Brisbane, Australia. He is a former police officer with 23 years of experience, and has trained personnel for deployment in Timor Leste, the Solomon Islands, Iraq and Afghanistan. Jason specializes in, and has published on engagement with Muslim communities, Indigenous Polynesian approaches to rehabilitation and reducing recidivism, and Asian Organised Crime. Jason also completed a community internship in Hebron on the West Bank.
ITC516 Communication and Cyber-Program Management
This unit equips students with the knowledge and skills required to lead cyber-security programs and communicate strategic value to executives, boards and external stakeholders. The unit emphasises programme-portfolio management, metrics and KPI design, financial justification, and crisis-communication strategies. Students will learn to translate complex technical risk into concise business narratives, manage cross-functional teams, negotiate budgets, and steer projects through change, disruption and regulatory scrutiny.
RELEVANT COURSES
* Core unit
CREDIT POINTS
10
STUDY MODES
On campus, online, hybrid
PREREQUISITE OR CO-REQUISITE
ITC402 Cybersecurity Management
UNIT LEARNING OUTCOMES
- Critically evaluate and prioritise cybersecurity initiatives for an enterprise portfolio
- Design business cases and cost-benefit justifications for cybersecurity investments
- Create metrics, KPIs and dashboards of cyber-risk posture and program performance
- Orchestrate crisis-communication plans that maintain stakeholder trust during high-impact cyber incidents
- Influence and negotiate with C-suite and board members to enhance cybersecurity
CONTENT
- Program-portfolio management frameworks
- Business-alignment techniques and value realisation
- Budgeting, financial modelling, ROI & NPV for cyber investment
- KPI and OKR design; leading & lagging indicators; Power BI dashboards
- Vendor, contract and SLA negotiation strategies
- Executive storytelling and data visualisation for boards
- Regulatory reporting and audit liaison (APRA CPS 234, SOC-2, ISO 27001)
- Stakeholder engagement and change-management leadership
- Media relations and public-statement protocols during incidents
- Crisis-simulation lab: ransomware breach war-game
- Post-incident reviews and lessons-learnt frameworks
- Future of program governance (AI-assisted PMO, quantum risk)
ASSESSMENT METHODS
- Portfolio Prioritisation Report – 20%
- Group Executive KPI Dashboard and Briefing – 30%
- Invigilated Crisis-Communication Simulation – 50%
PRESCRIBED READINGS
Check with the lecturer each semester before purchasing any texts












