Saltar al contenido
04 · Formación04 · Training

Workshops EjecutivosExecutive Workshops

Sesiones cortas sobre riesgos, inversión y ciber-resiliencia.Short sessions on risk, investment and cyber resilience.

C-LevelC-Level Programas de formación y concienciaciónTraining and awareness programmes

¿Qué es este servicio?What is this service?

Son sesiones cortas y cerradas para el equipo directivo sobre lo que de verdad les toca decidir: qué riesgos tecnológicos amenazan al negocio, cuánto cuesta cubrirlos, cuánto costaría no cubrirlos y cómo se comporta la organización durante una crisis. Suelen incluir un ejercicio de mesa con un escenario realista del sector.

Short, closed sessions for the executive team on what they actually have to decide: which technology risks threaten the business, what covering them costs, what not covering them would cost, and how the organisation behaves during a crisis. They usually include a tabletop exercise with a realistic sector scenario.

¿Para qué se usa?What is it used for?

Sirve para que las decisiones de inversión en seguridad se tomen con criterio y no por el susto del último titular. La dirección no necesita entender de tecnología; necesita entender el riesgo en términos de impacto, plazo y dinero. Un ejercicio de mesa de dos horas revela más huecos de gobierno que tres meses de informes.

It exists so security investment decisions get made on judgement rather than on the fright of the latest headline. Executives do not need to understand technology; they need to understand risk in terms of impact, timing and money. A two-hour tabletop exposes more governance gaps than three months of reports.

Qué beneficios traeBenefits it delivers

  • Traduce el riesgo técnico a lenguaje de negocio, que es lo que desbloquea presupuesto y no la lista de vulnerabilidades.
  • El ejercicio de mesa saca a la luz quién decide qué en una crisis, pregunta que casi nunca está resuelta antes de que pase.
  • Alinea a dirección y al área de seguridad sobre qué se acepta, qué se transfiere y qué se corrige.
  • Ocupa poco tiempo de agenda: media jornada bien preparada rinde más que un ciclo largo que nadie termina.
  • Translates technical risk into business language, which is what unlocks budget, not the vulnerability list.
  • The tabletop surfaces who decides what in a crisis, a question rarely settled before one happens.
  • Aligns executives and the security function on what is accepted, transferred and fixed.
  • Takes little diary time: a well-prepared half day yields more than a long cycle nobody finishes.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal de formar a la dirección ejecutiva en Costa Rica.
  • En entidades supervisadas por SUGEF, SUGEVAL, SUPEN y SUGESE, el Acuerdo CONASSIF 5-24 asigna al gobierno de la organización responsabilidad sobre la gestión de la tecnología y su riesgo, y esa responsabilidad se ejerce mal sin criterio propio.
  • Ante una fuga de datos personales, quien responde ante PRODHAB bajo la Ley 8968 es la organización, no el área técnica.
  • There is no legal obligation to train the executive team in Costa Rica.
  • In entities supervised by SUGEF, SUGEVAL, SUPEN and SUGESE, CONASSIF Agreement 5-24 places responsibility for technology management and its risk on the organisation's governance, and that responsibility is exercised badly without informed judgement.
  • In a personal data breach, the party answering to PRODHAB under Law 8968 is the organisation, not the technical team.

InternacionalInternational

  • DORA y NIS2 exigen que la dirección de las entidades cubiertas mantenga conocimientos suficientes sobre riesgo tecnológico y responda por la gestión del mismo.
  • ISO 27001 exige liderazgo y compromiso demostrable de la alta dirección con el sistema de gestión.
  • Las aseguradoras de ciberriesgo y los cuestionarios de terceros preguntan de forma habitual por la implicación directiva.
  • DORA and NIS2 require the management of covered entities to hold sufficient knowledge of technology risk and to answer for its management.
  • ISO 27001 requires demonstrable leadership and commitment from top management to the management system.
  • Cyber insurers and third-party questionnaires routinely ask about executive involvement.

Requisitos mínimosMinimum requirements

  • Asistencia real de la dirección. Si delegan en mandos medios, el taller pierde todo su sentido.
  • Información previa sobre el negocio: procesos críticos, dependencias tecnológicas y qué pérdida sería inaceptable.
  • Un escenario acordado para el ejercicio de mesa, alineado con amenazas reales del sector.
  • Reglas claras de confidencialidad, porque en la sesión se dicen cosas incómodas y conviene que se digan.
  • Actual attendance by the executives. If they delegate to middle management, the workshop loses its point.
  • Prior information about the business: critical processes, technology dependencies and what loss would be unacceptable.
  • An agreed scenario for the tabletop, aligned to real sector threats.
  • Clear confidentiality rules, because uncomfortable things get said in the room and it is best they do.

Plazo típico de entregaTypical delivery time

3 a 6 semanas 3 to 6 weeks rango habitual del mercado usual market range

Desde el encargo hasta la sesión pasan de tres a seis semanas, casi todas en preparación: entender el negocio, construir el escenario y ajustar el material. La sesión en sí ocupa entre dos horas y media jornada. Sube al extremo alto cuando hay que coordinar agendas de varios directivos o preparar un escenario sectorial a medida.

From engagement to the session takes three to six weeks, most of it preparation: understanding the business, building the scenario and tailoring the material. The session itself runs from two hours to half a day. It reaches the top of the range when several executive diaries must be coordinated or a bespoke sector scenario is required.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

Ejercicio de mesaTabletop exercise
Simulacro conversado de una crisis: no se toca ningún sistema, se practican las decisiones y la comunicación. A talked-through crisis simulation: no system is touched, decisions and communication are what get practised.
Ciber-resilienciaCyber resilience
La capacidad de seguir operando y recuperarse cuando el ataque ya ocurrió, no solo la de evitarlo. The ability to keep operating and recover once the attack has happened, not merely to prevent it.
Apetito de riesgoRisk appetite
El nivel de riesgo que la organización decide asumir de forma consciente y por escrito. The level of risk the organisation consciously decides to take on, in writing.
Riesgo residualResidual risk
El riesgo que queda después de aplicar los controles. Nunca es cero y alguien tiene que aceptarlo formalmente. The risk left after controls are applied. It is never zero and somebody has to accept it formally.