Navigator - Curriculum | ISTARI

Curriculum

Elevating cyber leaders into transformative business leaders

What you will learn

Co-developed with University of Cambridge academics, our curriculum combines ISTARI’s proprietary resilience framework with practical leadership strategy. Through Navigator, you will collaborate with fellow executives in an open setting to dissect real-world cyber scenarios, exchange peer insights, and build an organization that is resilient by design.

The Resilience-by-Routine Model

Designed in partnership with the University of Oxford Saïd Business School, our Resilience-by-Routine Model is a conceptual framework that global leaders can use to understand how to build resilience within their organisations.

© ISTARI Global Limited. All rights reserved

 

Primary Activities

Arrow
Cap
ResiliancebyRoutine2
ResiliancebyRoutineMob
Develop - Navigator Icons

Develop

The skills required to lead the organisational transition from cyber security to cyber resilience.

Design - Navigator Icons

Design

Your organisation’s resilience journey using a proprietary framework.

Deliver - Navigator Icons

Deliver

Your strategy with effective communication and influence skills.

istari navigator 2024 159

A curriculum designed to accelerate

Day 1 - Afternoon

Resilience in an Era of Unpeace: Geopolitical Risk in Cyberspace
Prof. Lucas Kello, Strategic Advisor, ISTARI & Professor of Technology & Geopolitics, University of Oxford

We are now operating in a space between peace and war... Our world is being actively remade, with profound implications for national and international security.”

Blaise Metreweli, Chief of MI6

This session will examine how the geopolitics of cyberspace is reshaping corporate risk. It situates contemporary cyber contests in historical perspective, mapping the evolution of cyber risk across distinct stages – from the criminal nuisance of the 1980s to today’s highimpact interstate operations with economic and political effects. It reviews the concept of “unpeace”: a persistent condition of strategic contest below the threshold of war in which economic disruption and political subversion become common tools of statecraft. It will discuss the growing instability in cyberspace arising from the converging forces of geopolitical fragmentation and technological uncertainty associated with AI and other technological trends. Participants will leave with a sharper lens on where cyber risk intersects with great-power rivalry and what this means for enterprise resilience strategy.

 

Day 1 - Afternoon

The Anatomy of a Crisis
Jo De Vliegher & Jason Mallinder, ISTARI

A cyberattack can hit all departments globally within minutes, even seconds. Not many other crises have that same immediate impact.”

Jo De Vliegher, Client Partner at ISTARI and former CIO at Norsk Hydro

“It’s not if, but when.” In today’s interconnected world, cyberattacks can cripple global operations within minutes, leaving organisations facing operational paralysis, financial loss, reputational fallout, and strategic risk. In this session, Jo De Vliegher—Client Partner at ISTARI and former CIO of Norsk Hydro—shares firsthand lessons from one of the most significant ransomware attacks in industrial history. When Norsk Hydro’s 22,000 computers across 170 sites were disabled almost instantly, Jo and his teams were forced to navigate a high-stakes recovery under extreme pressure. Through direct testimony and practical insights, participants will explore what it takes to lead through a cyber crisis, protect critical operations, and prepare their organisations for the realities of large-scale digital disruption.

 

 

Day 2 - Morning

Systemic Shocks & Resilience of the Enterprise
Dr. Danny Ralph

“The resilient resists shocks and stays the same; the antifragile gets better.”

Nassim Nicholas Taleb, Author, Antifragile

 

Even well-prepared organisations and governments struggle to imagine — let alone prepare for — large-scale, systemic events. This session asks a pressing question: How can leaders navigate unpredictable crises? Through interactive discussion, peer exchange, and scenario-based group work, participants will explore what securing organisational resilience means, how to test it, and how to strengthen it for the future. We will examine contagion effects to identify the cascading impacts of systemic crises, apply a taxonomy of business risks to reveal organisational blind spots, and use comparative scenario analysis to assess resilience and pinpoint vulnerabilities across ecosystems. Participants will leave with practical tools to embed foresight into their risk management practices, build adaptive capacity, and position their organisations to withstand — and even thrive in — the unexpected.

Day 2 - Afternoon

NorthRiver Health Trust: Incident Response in Critical Healthcare Infrastructure
Dr. Simon Learmount, Cambridge Judge Business School

“Adversity does not build character, it reveals it.”

James Lane Allen,19th–20th century American author

The simulation places participants in the role of board members (executive and non-executive directors) as a cyber incident unfolds, starting from weak signals about supplier risk, through acute disruption of digital systems, ransomware and data exfiltration threats, mounting government and media pressure, internal culture fractures, and finally full system outage requiring analogue operations.

 

Day 2 - Afternoon

Emerging Technology and Cyber Risk: What Does AI Teach Us for the Future?
Prof. Lucas Kello, Strategic Advisor, ISTARI & Professor of Technology & Geopolitics, University of Oxford

“We can only see a short distance ahead, but we can see plenty there that needs to be done.”

Alan Turing, Mathematician

This session will examine what the recent evolution of AI can teach leaders about resilience under accelerating technological change. It traces the evolution of machine intelligence from Alan Turing’s 1950 conception through rules-based systems in the 1960s to today’s neural network foundation models, with a focus on the strategic implications of agentic AI as systems shift from tools to autonomous actors. It will then structure the risk landscape around three pathways: offensive acceleration, model manipulation and compromise, and supply-chain targeting. The session also reviews the origins of quantum computing and the probabilistic timeline for universal quantum processors, translating those projections into concrete preparedness measures and decision thresholds. The central aim is preparedness: understanding why LLMs caught many organisations off guard and applying that lesson to build quantum readiness early enough to avoid strategic surprise in technology management.

Day 3 - Morning

Resilience by Routine
Dr. Manuel Hepfer, University of Oxford

“In the middle of difficulty lies opportunity.”

Albert Einstein, Theoretical Physicist & Researcher

Disruption is inevitable. Yet organisations respond to it very differently. Some falter in the face of adversity, while others adapt and even thrive. Executives often describe this difference using the word resilience, yet few define it clearly. What creates resilience? What undermines it? This session explores the core activities that enable organisations to navigate disruption and emerge stronger. Drawing on insights from strategy, risk management, and research, we examine what distinguishes resilient organisations from those that struggle in times of crisis. By the end of this session, participants will be able to articulate what resilience means in their own organisational context and identify the foundations required to build it.

Day 3 - Morning

Cyber Risk Management
Jason Mallinder, Client Partner, ISTARI

“We will bankrupt ourselves in the vain search for absolute security.”

Dwight D. Eisenhower, 34th President of The United States

Security budgets are rising, yet most organisations struggle to demonstrate whether investments reduce the biggest risks or just check compliance boxes. Many operate fragmented security governance where reporting, governance, and operational security work in silos. Most decisions are driven without full understanding, reacting to incidents rather than proactively preparing for the future threat. Data-driven governance measures threat exposure, control effectiveness, and incident patterns to make defensible decisions about where to invest and what risks to accept. This session examines how to build measurement frameworks that inform strategy, communicate risk at the boards in business terms, and optimise spending based on actual cyber postures. Participants will gain practical approaches to quantifying cyber risk and using real time data to drive security decisions.

Day 3 - Afternoon

Crafting a Cyber Resilience Strategy
Dr. Manuel Hepfer, University of Oxford & ISTARI

“Then, in 72 words, I laid out the strategy, which was essentially to be the conduit of capital between those who have it and those who need it. That’s our job. Then we took a poll, and the result was that 98 percent understood and agreed with the strategy. Clarity of message is key.”

James Gorman, CEO Of Morgan Stanley, 2019

This module is a specially designed Cambridge Judge Business School case study. Focusing on Uber and Jaguar Land Rover (JLR), the session explores the how cyber crises play out across an entire organisation, from the security operations and supply chain to the C-suite and boardroom. Both cases reveal how organisational culture, stakeholder management, governance and leadership shape the handling of cyber crises, from data breach disclosure issues and the prosecution of Uber’s former CSO, Joe Sullivan, to JLR’s business continuity and stakeholder impact. The session critically analyses how different types of incidents demand different crisis leadership approaches, while still relying on common foundations: clear governance, stakeholder management, well-rehearsed incident response, effective internal and external communications, and a culture that supports transparency and learning.

Day 4 - Morning

Systems Thinking and New Leadership in a Changing World
Professor Jennifer Howard-Grenville, Cambridge Judge Business School

“Ultimately, being a CISO in times of crisis requires a mix of strong decision-making, clear communication, and a focus on both the technical and human elements of leadership. It’s about guiding the team through challenging situations while ensuring they feel supported and confident in your direction.”

Tim Brown, CIO, Solar Winds

In today’s rapidly evolving organisational environment, CISOs must navigate uncertainty and instability, both internally and externally. This session equips participants with frameworks from systems thinking, culture theory, and leadership studies to strengthen their ability to lead with confidence in unpredictable conditions. Through interactive exercises, structured reflection, and practical discussions, participants will gain insights into how uncertainty and instability manifest in complex systems—and, importantly, how they can take meaningful action.

Day 4 - Morning

Autonomous AI: Agent or Double Agent?
Dr. Yashovardhan Sharma, AI Innovation Lead, ISTARI

“To betray, you must first belong.”

Kim Philby, MI6 officer and Soviet double agent

As AI moves from basic chatbots to fully autonomous agents, the threat horizon expands exponentially. In this hands-on session, participants will move past the theoretical hype to explore the practicalities of securing these systems with insights directly from the keyboard. We will put a real-world agentic AI use case to the test via a live hackathon—demonstrating exactly how an everyday productivity assistant can be exploited as a primary attack vector. From there, we will unpack the broader AI risk landscape—including prompt injection, data leakage, hallucination, and third-party exposure—before delivering a five-pillar framework for secure deployment: governance, architecture, culture, third-party risk, and incident response. You will leave with an actionable roadmap to identify, govern, and secure the AI agents already operating inside your organisation.

Day 4 - Afternoon

Shaping Governance & Leadership
Dr. Simon Learmount, Cambridge Judge Business School

“Uber, the world’s largest taxi company, owns no vehicles.Facebook, the world’s most popular media owner, creates no content. Alibaba, the most valuable retailer, has no inventory. And Airbnb, the world’s largest accommodation provider, owns no real estate. Something interesting is happening.”

Tom Goodwin, Tech Crunch

This module is a specially designed Cambridge Judge Business School case study. Focusing on Uber and Jaguar Land Rover (JLR), the session explores the how cyber crises play out across an entire organisation, from the security operations and supply chain to the C‑suite and boardroom. Both cases reveal how organisational culture, stakeholder management, governance and leadership shape the handling of cyber crises, from data breach disclosure issues and the prosecution of Uber’s former CSO, Joe Sullivan, to JLR’s business continuity and stakeholder impact. The session critically analyses how different types of incidents demand different crisis leadership approaches, while still relying on common foundations: clear governance, stakeholder management, well-rehearsed incident response, effective internal and external communications, and a culture that supports transparency and learning.

Day 5 - Morning

Split Second Choices - Outsmarting AI-Driven Threats: A Cyber Wargame Exercise
Chris Crummey, Director Executive & Board Cyber Services, Sygnia

“Winning is not about being the fastest, it’s about making the fewest mistakes.”

Alain Prost, British Formula One driver

In today’s rapidly evolving organisational environment, CISOs must navigate uncertainty and instability, both internally and externally. This session equips participants with frameworks from systems thinking, culture theory, and leadership studies to strengthen their ability to lead with confidence in unpredictable conditions. Through interactive exercises, structured reflection, and practical discussions, participants will gain insights into how uncertainty and instability manifest in complex systems— and, importantly, how they can take meaningful action.

Day 5 - Morning

Putting Your Cyber Resilience Strategy into Action
Dr. Simon Learmount Cambridge Judge Business School

“Thinking is easy, acting is difficult, and to put one’s thoughts into action is the most difficult thing in the world.”

Johann Wolfgang von Goethe

The final session culminates all the knowledge and skills gained throughout the programme. It provides a toolkit that can empower cyber executives to put their learning into action within their respective companies. This session serves as a platform for participants to share their strategic thinking, leadership abilities and new-found expertise and how as a cohort they can continue their journey as a community of peers.