Module 1 — Enterprise Cyber Defense Strategy and Governance
- Cyber-defense maturity and readiness
- Enterprise strategy and priorities
- Governance and accountability
- Operating models and strategic roadmaps
Anticipate Threats. Govern Defense. Lead Cyber Crises. Build Enterprise Resilience.
Cyber-defense leadership is no longer limited to managing a Security Operations Center or purchasing security technologies.
Command Detection, Response and Cyber Resilience.
Master the core areas of cyber defense.
The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral professional certification designed to validate management and leadership competency across enterprise cyber-defense strategy, SOC governance, threat and exposure management, incident and crisis leadership, recovery, resilience, investment, technology governance, workforce leadership, AI-enabled defense, and executive decision-making.
Offered by the: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
CCDM® represents the advanced management level of the IBACTP® cyber-defense certification pathway.
Lead Cyber Defense as an Enterprise Capability
Advanced Manager level — Three-year certification cycle with continuing professional education
CCDM® Leadership Objective
Anticipate Threats → Govern Defense → Lead Response → Restore Operations → Strengthen Resilience → Protect Enterprise Value
Modern cyber-defense leadership extends far beyond managing security tools, reviewing alerts, or supervising technical teams. Today’s cyber-defense managers must be prepared to anticipate threats, govern enterprise defensive capabilities, prioritize exposures, direct security operations, lead major incidents, coordinate crisis response, restore critical services, measure resilience, evaluate technology investments, develop cyber-defense teams, and communicate effectively with executives and boards.
The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral management certification offered by the International Board of AI, Cybersecurity & Technology Professionals (IBACTP®).
CCDM® is designed for experienced professionals responsible for the strategy, governance, leadership, performance, investment, risk, and transformation of enterprise cyber-defense capabilities.
“Can the organization detect the threats that matter, respond effectively when attacks occur, restore critical operations, and continuously strengthen its resilience?”
A technically sophisticated security program can still fail if the organization cannot make effective decisions during a crisis.
Cyber-defense managers must connect:
Technology + Threats + Risk + Operations + People + Business Priorities + Executive Decisions
CCDM® develops leadership competency to answer questions such as:
CCDM® is designed for experienced professionals moving into or currently serving in cyber-defense management and leadership roles.
CCDM® can also support senior technical professionals preparing for management, director, or enterprise leadership responsibilities.
Absolutely. Below is a comprehensive, executive-level version for CCDM®, written to distinguish the course description, course learning outcomes, and certification testing outcomes clearly.
Upon successful completion of the Certified Cyber Defense Manager (CCDM®) program, participants will be able to demonstrate advanced competency across eight integrated cyber-defense management domains.
Assess cyber-defense maturity, identify capability gaps, establish strategic priorities, define governance structures, develop operating models and roadmaps, and align defensive capabilities with enterprise risk and business objectives.
Govern SOC strategy, monitoring, detection, threat intelligence, threat hunting, automation, escalation, staffing, sourcing, service levels, and operational performance.
Evaluate threat conditions, attack surfaces, vulnerabilities, exploitability, asset criticality, business impact, remediation priorities, and enterprise exposure to support risk-based defensive decisions.
Establish incident-governance structures, severity models, escalation criteria, command responsibilities, containment priorities, cross-functional coordination, executive decisions, and crisis communication.
Integrate incident response with technical recovery, business continuity, disaster recovery, critical-service restoration, resilience testing, lessons learned, and continuous improvement.
Develop business cases, evaluate defensive technologies, prioritize resources, govern vendors and managed services, establish KPIs and KRIs, and measure defensive effectiveness, maturity, and value.
Evaluate AI-assisted security, defensive automation, Generative AI, AI-enabled attacks, cloud-native risks, IoT, OT, APIs, software supply chains, and emerging technologies while maintaining appropriate governance and human oversight.
Build cyber-defense teams, identify skills gaps, develop workforce capabilities, strengthen organizational readiness, communicate cyber risk and resilience to executives and boards, and lead enterprise transformation.
Upon completion of the program, participants will be prepared to connect:
The ultimate course learning objective is to enable participants to:
The CCDM® certification assessment evaluates whether candidates can apply advanced cyber-defense management knowledge, interpret enterprise risk and technical evidence, prioritize defensive actions, and exercise sound managerial and executive judgment across eight competency domains.
The certification assessment emphasizes application, analysis, evaluation, prioritization, governance, leadership, and scenario-based decision-making rather than memorization alone.
Evaluate cyber-defense maturity, strategic priorities, governance structures, operating models, decision rights, capability roadmaps, and alignment with enterprise risk and organizational objectives.
Testing Focus: Determine the most appropriate strategic and governance response to identified defensive gaps and organizational risk.
Evaluate SOC capabilities, monitoring coverage, detection effectiveness, threat intelligence, escalation models, automation, staffing, sourcing, and performance.
Testing Focus: Determine whether security operations provide sufficient visibility, detection, investigation, and response capability.
Evaluate threat intelligence, vulnerability findings, exploitability, attack surfaces, asset criticality, business impact, compensating controls, and remediation priorities.
Testing Focus: Prioritize enterprise exposure according to actual risk rather than technical severity alone.
Evaluate incident severity, escalation requirements, containment options, decision authority, investigation priorities, executive involvement, communication, and crisis coordination.
Testing Focus: Determine the most appropriate management action during significant or escalating cybersecurity incidents.
Evaluate critical-service dependencies, recovery priorities, backup and restoration capabilities, business continuity, disaster recovery, recovery validation, exercises, lessons learned, and resilience improvements.
Testing Focus: Determine how the organization should restore operations securely while reducing future disruption.
Evaluate cybersecurity business cases, technology options, vendor performance, managed services, resource allocation, KPIs, KRIs, maturity measures, and investment priorities.
Testing Focus: Select and justify defensive investments and management actions based on risk reduction, capability improvement, cost, performance, and enterprise value.
Evaluate AI-assisted detection, security automation, Generative AI, AI-enabled attacks, cloud-native threats, IoT, OT, software supply chains, and emerging defensive technologies.
Testing Focus: Balance innovation, automation, security, reliability, risk, and human oversight when evaluating emerging cyber-defense capabilities.
Evaluate workforce structures, skills gaps, leadership requirements, organizational culture, stakeholder coordination, executive reporting, board communication, and transformation priorities.
Testing Focus: Translate technical cyber-defense conditions into clear leadership decisions, organizational actions, and executive recommendations.
The CCDM® certification assessment evaluates whether candidates can demonstrate advanced managerial skill, professional judgment, governance capability, and leadership competency across eight enterprise cyber-defense domains.
Candidates are expected to demonstrate competency in:
Assess organizational readiness, define cyber-defense priorities, establish governance structures, develop operating models, and align defensive capabilities with enterprise risk and business objectives.
Evaluate SOC effectiveness, monitoring coverage, detection capabilities, threat intelligence, escalation processes, automation, staffing, sourcing, and operational performance.
Analyze threat information, vulnerability findings, exploitability, asset criticality, attack surfaces, business impact, and remediation priorities to reduce enterprise exposure.
Evaluate incident severity, determine escalation, establish command and decision authority, prioritize containment, coordinate response, and lead executive and crisis communication.
Evaluate recovery priorities, critical-service dependencies, business continuity, disaster recovery, restoration strategies, recovery validation, and resilience improvements.
Evaluate business cases, technology investments, vendor capabilities, resource allocation, KPIs, KRIs, maturity measures, and cyber-defense performance.
Assess AI-assisted defense, security automation, Generative AI risks, AI-enabled attacks, cloud-native threats, IoT, OT, software supply chains, and emerging cyber-defense technologies.
Evaluate workforce structures, capability gaps, leadership requirements, security culture, stakeholder engagement, executive reporting, board communication, and organizational transformation.
CCDM® evaluates advanced professional judgment across the following levels:
Interpret relevant cyber-defense concepts, risks, technologies, governance structures, and management practices.
Apply management principles to realistic enterprise cyber-defense situations.
Interpret threat intelligence, operational information, incident evidence, exposure data, resilience information, and performance metrics.
Compare alternatives, assess tradeoffs, evaluate risk, and determine appropriate management responses.
Determine which threats, incidents, exposures, investments, or recovery actions require the greatest attention.
Select defensible management actions under conditions of uncertainty, operational pressure, and competing business priorities.
Determine how people, processes, technologies, governance, communication, and executive oversight should be coordinated.
CCDM® assesses more than knowledge of cyber-defense management terminology.
Successful candidates demonstrate the ability to integrate:
Strategy + Governance + Threat Judgment + SOC Leadership + Exposure Prioritization + Incident Leadership + Recovery + Resilience + Investment + Technology + Workforce + Executive Judgment
The CCDM® certification competency progression is:
Assess → Strategize → Govern → Prioritize → Decide → Lead → Recover → Measure → Transform
The ultimate certification testing objective is to validate whether a candidate can:
Interpret Threat and Risk Information → Establish Priorities → Govern Cyber Defense → Lead Major Incidents → Direct Recovery → Measure Resilience → Advise Executives → Protect Enterprise Value
A successful CCDM® candidate demonstrates the advanced managerial competency necessary to lead cyber defense as a strategic, measurable, resilient, and enterprise-wide capability.
CCDM® develops advanced competency across eight integrated management dimensions.
Assess defensive maturity, establish priorities, define governance, develop operating models, establish roadmaps, and align cyber defense with enterprise risk.
Govern SOC strategy, monitoring, detection, intelligence, automation, escalation, staffing, service providers, and performance.
Prioritize threats and enterprise exposures according to exploitability, intelligence, asset criticality, business impact, and organizational risk.
Establish incident governance, severity models, command structures, decision authorities, escalation criteria, containment priorities, and crisis communication.
Integrate incident response with business continuity, disaster recovery, critical-service restoration, exercises, lessons learned, and resilience improvement.
Evaluate business cases, technologies, vendors, resource priorities, KPIs, KRIs, capability maturity, and defensive value.
Evaluate AI-assisted defense, automation, AI-enabled attacks, cloud-native risks, OT, IoT, software supply chains, and emerging defensive technologies.
Build cyber-defense teams, develop organizational capabilities, communicate readiness and risk to executives and boards, and lead transformation.
Eligible instructor-led candidates may demonstrate competency through a structured three-part management Capstone.
Assess enterprise cyber-defense maturity, threats, exposure, capabilities, governance, technology, and workforce.
Develop:
Current State → Capability Gaps → Target State → Priorities → Investment Roadmap
Manage a simulated enterprise cyber incident involving technical, operational, business, regulatory, and executive decisions.
Demonstrate:
Assess → Escalate → Decide → Contain → Coordinate → Communicate
Develop recovery priorities, resilience improvements, metrics, investments, and executive recommendations.
Conclude with an executive-level presentation:
What Happened → Why It Matters → What Was Done → What Remains at Risk → What Must Improve → What Decision Is Required
The Certified Cyber Defense Manager (CCDM®) is an advanced professional certification for managers and leaders responsible for building, governing, directing, measuring, and continuously improving enterprise cyber-defense capabilities.
CCDM® moves beyond the question:
“How do we detect and respond to an attack?”
It develops competency to address the broader leadership question:
“Is the enterprise prepared to anticipate, withstand, respond to, recover from, and learn from a significant cyberattack?”
The certification addresses:
Evaluate defensive readiness, identify capability gaps, and develop priorities.
Assess monitoring, detection, escalation, staffing, technology, and SOC performance.
Prioritize critical vulnerabilities and exposures using threat, exploitability, asset, and business information.
Make escalation, containment, communication, operational, and executive decisions during an evolving incident.
Evaluate recovery capability, critical-service dependencies, continuity, lessons learned, and resilience priorities.
The CCDM® Body of Knowledge incorporates relevant principles from:
ISO/IEC 27001 • ISO/IEC 27002 • ISO/IEC 27005 • ISO/IEC 27701 • ISO 22301 • ISO 31000 • ISO/IEC 42001 • ISO/IEC 23894 • NIST Cybersecurity Framework • NIST NICE Workforce Framework • NIST AI RMF • Relevant NIST Cybersecurity and Incident-Response Guidance • CISA Guidance
The management progression is:
CCDM® is not tied to one:
SIEM • SOAR • EDR/XDR • Firewall • Cloud Provider • Vulnerability Platform • Threat-Intelligence Vendor • Forensic Product • Incident Platform • AI Security Vendor
Managers learn to evaluate technologies based on:
Capability • Integration • Performance • Risk Reduction • Cost • Scalability • Governance • Resilience • Enterprise Value
The recommended IBACTP® progression is:
The curriculum develops managerial capability through:
The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral professional certification designed to develop and validate the management, governance, strategic, analytical, and leadership competencies required to direct enterprise cyber-defense capabilities.
CCDM® prepares experienced cybersecurity and technology professionals to move beyond operational cyber-defense tasks and lead integrated programs involving Security Operations Centers, threat detection, threat intelligence, vulnerability and exposure management, incident response, cyber crisis management, digital investigation oversight, recovery, business continuity, cyber resilience, security investment, workforce leadership, AI-enabled defense, and executive communication.
The program emphasizes the management decisions required to ensure that cyber-defense capabilities are aligned with enterprise risk, business priorities, critical services, regulatory expectations, technology dependencies, and organizational resilience objectives.
Participants learn how to evaluate whether an organization can:
CCDM® integrates:
The program places particular emphasis on transforming cyber defense from a collection of technical tools and operational activities into a measurable, governed, and resilient enterprise capability.
The central management objective is:
Build professional competency in:
Monitoring • Detection • Analysis • Investigation • Response • Recovery
Advance into management competency in:
Strategy • Governance • Prioritization • Leadership • Measurement • Transformation
Equivalent qualifying cybersecurity, cyber-defense, SOC, incident-response, technology-risk, continuity, resilience, or security-management experience may satisfy applicable IBACTP® eligibility requirements.
Understand the organization's threats, exposure, maturity, readiness, and resilience.
Determine where the organization needs to go and establish a defensible roadmap.
Define accountability, authority, operating models, policies, and decision rights.
Direct attention and resources toward the threats and exposures that matter most.
Ensure security operations possess effective visibility, detection, intelligence, and defensive capabilities.
Lead coordinated organizational action during significant cyber incidents.
Restore critical operations securely and connect technical recovery with business priorities.
Evaluate performance using meaningful KPIs, KRIs, maturity measures, exposure trends, and resilience indicators.
Use evidence, incidents, exercises, investments, workforce development, and emerging technologies to continuously improve enterprise cyber defense.
100 Questions
90 Minutes
Advanced Multiple-Choice + Scenario-Based Questions
Closed Book
Secure Online Proctoring or Approved Testing Center
Recommended Passing Score: 70%
Assessment emphasizes:
Strategy • Governance • Threat Judgment • Exposure Prioritization • Incident Decisions • Crisis Leadership • Recovery • Resilience • Investment • Executive Judgment
CCDM® remains vendor-neutral while developing management competency across technology categories such as:
SIEM • SOAR • EDR/XDR • Threat Intelligence • Security Analytics • Monitoring Platforms
Vulnerability Scanners • Asset Discovery • Attack-Surface Management • Exposure Management • Configuration Management
Firewalls • IDS/IPS • Segmentation • Zero Trust • Cloud Security • Secure Access
Incident Platforms • Digital Forensics • Backup & Recovery • Continuity Technologies • Crisis-Management Platforms
AI-Assisted Detection • Security Automation • AI Analytics • Automated Response • AI Threat Analysis
CCDM® focuses on:
Selection → Integration → Governance → Cost → Performance → Risk → Enterprise Value
—not simply operation of individual products.
One of the defining CCDM® competencies is determining when a technical security event requires enterprise leadership.
CCDM® examines the progression:
Managers develop competency to determine:
CCDM® prepares cyber-defense managers to translate technical conditions into executive decisions.
Effective leadership communication answers:
What Is Happening? → Why Does It Matter? → What Is at Risk? → What Are We Doing? → What Decision Is Required?
Relevant reporting may include:
The goal is not to overwhelm executives with technical information.
The goal is to provide the right information for the right decision at the right time.
CCDM® emphasizes evidence-based management.
Managers learn to evaluate measures involving:
CCDM® develops the ability to move from:
CCDM® teaches frameworks as management and decision-support resources, rather than simple memorization requirements.
Framework alignment does not constitute accreditation, recognition, approval, or endorsement by the referenced organizations.
The CCDM® framework incorporates credentialing-quality principles associated with:
ISO/IEC 17024 • ANAB • NCCA • I.C.E. • International Personnel-Certification and Conformity-Assessment Practices
The certification framework encompasses:
Job Task Analysis • Defined Management Competencies • Eligibility Standards • Validated Body of Knowledge • Examination Blueprint • SME Participation • Psychometric Principles • Examination Security • Identity Verification • Impartial Certification Decisions • Appeals and Complaints • Ethics • Continuing Education • Recertification • Credential Verification • Periodic Review • Continuous Improvement
The CCDM® credentialing-quality lifecycle is:
Define → Validate → Assess → Certify → Maintain → Verify → Review → Improve
Alignment does not constitute formal accreditation, recognition, approval, endorsement, or affiliation. Such status is represented only after officially awarded by the applicable independent organization.
Certified Cyber Defense Professional
Primary emphasis:
Professional objective:
Defend the Environment. Respond Effectively. Strengthen Cyber Resilience.
↓
Certified Cyber Defense Manager
Primary emphasis:
Leadership objective:
Govern Enterprise Defense. Lead Cyber Crises. Build Resilience. Protect Enterprise Value.
Below is a more comprehensive, polished, and marketable FAQ section for the CCDM® webpage, with stronger emphasis on management, executive decision-making, incident leadership, and enterprise resilience.
CCDM® develops the ability to connect:
The certification moves professionals from managing individual defensive activities toward governing cyber defense as an integrated enterprise capability.
CCDM® — Lead the Defense. Direct the Response. Strengthen the Enterprise.
The strongest cyber-defense organizations connect:
CCDM® develops managers capable of bringing those capabilities together.
Advance your professional journey into enterprise cyber-defense leadership.
APPLY NOW →
Ready to demonstrate advanced management competency?
REGISTER FOR THE EXAM →
Develop advanced competency across strategy, operations, incident leadership, recovery, resilience, investment, and executive decision-making.
ENROLL NOW →
Demonstrate advanced competency through an instructor-led enterprise cyber-defense management project.
EXPLORE THE CAPSTONE →
Review eligibility, competencies, Body of Knowledge, assessment pathways, standards alignment, and certification requirements.
DOWNLOAD PROGRAM GUIDE →
CCDM® is designed for experienced professionals and current or aspiring leaders such as:
Module 6 — Cyber Defense Investment, Technology & Performance
Module 8 — Workforce, Executive Communication & Transformation
Upon successful completion, participants will be able to:
1. Develop Enterprise Cyber Defense Strategy and Governance
Assess defensive maturity, establish strategic priorities, design operating models, develop roadmaps, and align cyber defense with enterprise risk.
2. Lead SOC, Detection and Security Operations
Govern monitoring, detection, intelligence, automation, escalation, staffing, sourcing, and operational performance.
3. Govern Threat, Vulnerability and Exposure Management
Prioritize exposures using threat intelligence, exploitability, asset criticality, business impact, and risk.
4. Direct Incident Response and Cyber Crisis Management
Establish command structures, escalation criteria, severity models, containment priorities, executive decision processes, and crisis communication.
5. Lead Recovery, Continuity and Cyber Resilience
Integrate technical recovery with business continuity, disaster recovery, critical-service restoration, exercises, and resilience improvement.
6. Manage Cyber Defense Investment, Technology and Performance
Develop business cases, evaluate technologies, manage vendors, prioritize resources, and measure effectiveness through KPIs and KRIs.
7. Govern AI-Enabled Defense and Emerging Cyber Risk
Evaluate AI-assisted defense, automation, AI-enabled attacks, cloud, OT, IoT, supply-chain, and emerging risks.
8. Lead Workforce, Executive Communication and Transformation
Build cyber-defense teams, develop capabilities, communicate with executives and boards, and lead organizational transformation.
CCDM® assesses management competency—not merely knowledge recall.
Candidates demonstrate the ability to:
Assess defensive maturity, establish priorities, define target capabilities, and develop enterprise roadmaps.
Establish operating models, decision rights, accountability, policies, escalation, and oversight.
Determine which threats, vulnerabilities, exposures, incidents, and investments require attention first.
Lead security operations, major incidents, containment decisions, cyber crises, and recovery priorities.
Evaluate whether defensive capabilities, service providers, recovery processes, and controls are effective.
Use KPIs, KRIs, exposure trends, detection measures, response performance, recovery metrics, and resilience indicators.
Develop business cases, prioritize budgets, evaluate technologies, and allocate scarce resources.
Translate technical information into business risk, executive decisions, investment requirements, and board-level reporting.
Use incidents, exercises, metrics, emerging technologies, and lessons learned to improve enterprise resilience.
CCDM® is organized around eight integrated management dimensions.
Develop the ability to assess defensive maturity, identify capability gaps, establish strategic priorities, define governance structures, develop operating models, and align cyber defense with enterprise objectives.
Managers evaluate:
Align cyber-defense capabilities with enterprise risk, business priorities, and organizational resilience objectives.
The effectiveness of cyber defense depends heavily on the organization’s ability to achieve meaningful visibility and detection.
CCDM® addresses management of:
Managers must determine whether security operations are producing useful defensive outcomes.
The central question becomes:
01 — Enterprise Cyber Defense Strategy & Governance
Assess maturity, establish priorities, design operating models, define accountability, develop roadmaps, and align defensive capabilities with enterprise objectives.
02 — SOC, Detection & Security Operations Leadership
Govern SOC strategy, monitoring, detection engineering, intelligence, automation, escalation, sourcing, staffing, and performance.
03 — Threat, Vulnerability & Exposure Governance
Prioritize enterprise exposures using threat intelligence, exploitability, asset criticality, business impact, attack paths, and risk.
04 — Incident Response & Cyber Crisis Leadership
Establish command structures, severity models, escalation criteria, containment authority, executive decision processes, and crisis communication.
05 — Recovery, Continuity & Cyber Resilience
Integrate technical recovery with business continuity, disaster recovery, critical-service restoration, exercises, lessons learned, and resilience improvement.
06 — Cyber Defense Investment, Technology & Performance
Develop business cases, evaluate defensive technologies, manage service providers, allocate resources, and measure effectiveness.
07 — AI-Enabled Defense & Emerging Cyber Risk
Govern AI-assisted detection, automation, AI-enabled attacks, cloud, OT, IoT, software supply chains, and emerging defensive technologies.
08 — Workforce, Executive Communication & Transformation
Build teams, develop capabilities, communicate readiness and risk to executives and boards, and lead enterprise transformation.
The Certified Cyber Defense Manager (CCDM®) is an advanced professional certification that validates the managerial and leadership competencies required to govern cyber defense as an integrated enterprise capability.
CCDM® focuses on the progression from:
The certification prepares managers to lead capabilities involving:
CCDM® incorporates principles relevant to:
ISO/IEC 27001 • ISO/IEC 27002 • ISO/IEC 27005 • ISO/IEC 27701 • ISO 22301 • ISO 31000 • ISO/IEC 42001 • ISO/IEC 23894 • NIST CSF • NIST NICE • NIST AI RMF • Relevant NIST Incident-Response Guidance • CISA Guidance
NIST’s current enterprise guidance reinforces the connection between cybersecurity risk, enterprise risk management, senior leadership, and workforce planning—an important foundation for the management-level orientation of CCDM®.
The complete CCDM® management lifecycle is:
Understand threats, exposure, defensive maturity, and organizational readiness.
Establish priorities, operating models, capabilities, and roadmaps.
Define accountability, policies, decision rights, escalation, and oversight.
Direct resources toward the threats, vulnerabilities, incidents, and capabilities that matter most.
Lead SOC operations, major incidents, containment decisions, and cyber crises.
Restore critical operations securely and validate recovery.
Evaluate defensive performance, risk reduction, and resilience.
Translate technical conditions into executive and board-level decisions.
Use lessons learned, emerging technologies, and performance insights to strengthen enterprise capability.
| Area | CCDP® Professional | CCDM® Advanced Manager |
|---|---|---|
| Primary Focus | Cyber-defense execution | Enterprise cyber-defense leadership |
| SOC | Monitor and analyze | Strategize and govern |
| Threat Intelligence | Analyze and apply | Govern and prioritize |
| Vulnerabilities | Identify and assess | Prioritize enterprise exposure |
| Incidents | Triage and respond | Direct and govern |
| Cyber Crisis | Support response | Lead executive response |
| Forensics | Preserve and analyze | Govern investigations |
| Recovery | Support restoration | Direct enterprise recovery |
| Resilience | Apply practices | Establish strategy |
| Technology | Use and interpret | Evaluate and govern |
| Metrics | Operational measures | KPIs, KRIs and executive measures |
| AI Defense | Apply and evaluate | Govern and invest |
| Workforce | Professional contribution | Team and capability leadership |
| Communication | Technical reporting | Executive and board reporting |
| Objective | Defend the Environment | Govern Defense & Resilience |
Build the professional capability to:
Monitor → Detect → Analyze → Investigate → Respond → Recover
↓
Develop the leadership capability to:
Assess → Strategize → Govern → Prioritize → Lead → Measure → Transform
| Area | CCDP® | CCDM® |
|---|---|---|
| Level | Professional | Advanced / Management |
| Primary Focus | Perform cyber defense | Govern cyber defense |
| SOC | Monitor and analyze | Lead and measure |
| Threat Intelligence | Analyze and apply | Govern and prioritize |
| Vulnerabilities | Identify and assess | Prioritize exposure |
| Incident Response | Triage and respond | Direct and govern |
| Cyber Crisis | Support | Lead |
| Forensics | Preserve and analyze | Govern investigation |
| Recovery | Support restoration | Direct recovery |
| Resilience | Apply practices | Establish strategy |
| Technology | Use and interpret | Evaluate and govern |
| Metrics | Operational | Executive KPIs/KRIs |
| AI Defense | Apply and evaluate | Govern and invest |
| Workforce | Professional contribution | Team leadership |
| Communication | Technical | Executive and board |
| Objective | Defend the Environment | Govern Defense and Resilience |
Monitor → Detect → Analyze → Investigate → Respond → Recover
↓
Assess → Strategize → Govern → Prioritize → Lead → Measure → Transform
A significant cybersecurity incident rarely remains a technical problem.
A compromised endpoint can become an identity compromise.
An identity compromise can become lateral movement.
Lateral movement can affect cloud systems, applications, data, operational environments, or critical services.
A major cyber incident can quickly create:
For this reason, modern cyber-defense leadership requires much more than understanding security technologies.
Managers must determine:
CCDM® is designed around these management decisions.
A cyber-defense professional may ask:
A cyber-defense manager must also ask:
CCDM® develops this broader management perspective.
The certification prepares leaders to connect:
CCDM® integrates twelve critical areas of modern cyber-defense management:
Establish enterprise defensive priorities, target capabilities, operating models, and roadmaps.
Govern monitoring, detection, investigation, escalation, automation, staffing, sourcing, and performance.
Use threat intelligence and adversary information to guide defensive priorities.
Prioritize vulnerabilities and attack surfaces according to exploitability, asset criticality, threat activity, and business impact.
Establish severity models, escalation, decision authority, containment priorities, and response governance.
Coordinate executives, legal, communications, technology, business leaders, and external stakeholders during major cyber events.
Direct secure restoration of systems and critical services.
Ensure the organization can withstand disruption, recover effectively, learn from incidents, and strengthen future readiness.
Evaluate security capabilities based on risk reduction, integration, cost, scalability, performance, and value.
Use KPIs, KRIs, maturity indicators, readiness measures, and executive reporting to evaluate effectiveness.
Govern AI-assisted detection, automation, intelligence, investigation, and emerging AI-related cyber risks.
Develop teams, strengthen security culture, communicate risk, and translate technical conditions into executive decisions.
CCDM® moves managers beyond traditional vulnerability-count reporting.
Managers develop competency in prioritizing exposure using:
Relevant management areas include:
The objective is to direct resources toward the weaknesses most likely to create material organizational risk.
CCDM® places major emphasis on incident leadership.
Managers must understand how to move from operational incident response into enterprise crisis decision-making.
Relevant competencies include:
Event → Incident → Major Incident → Enterprise Crisis
CCDM® prepares managers to recognize when this escalation should occur and what leadership structures are required at each stage.
This is one of the defining questions addressed by CCDM®.
An incident may require enterprise crisis management when it materially affects:
At this point, cyber defense must connect with broader organizational leadership.
The manager’s role shifts from:
to:
Containment is not the end of a major cyber incident.
Organizations must restore operations without reintroducing the attacker, spreading compromise, or creating unnecessary business risk.
CCDM® develops management competency involving:
The management objective is not simply:
It is:
Restore the Right Services, in the Right Order, with Confidence That the Environment Is Secure.
CCDM® treats cyber resilience as a defining enterprise capability.
Resilience means being prepared to:
A resilient organization does not assume that every attack will be prevented.
Instead, it develops the capability to:
The ultimate goal is to reduce both the likelihood and business impact of major cyber disruption.
Cyber-defense leaders must determine not only which technologies are available, but which capabilities actually deserve investment.
CCDM® addresses management of technologies such as:
SIEM • SOAR • EDR/XDR • Threat Intelligence • IDS/IPS • Network Detection • Vulnerability Management • Exposure Management • Cloud Security • Identity Security • Digital Forensics • Incident Management • Backup & Recovery • AI-Assisted Security
Managers evaluate technology based on:
Cyber-defense management requires meaningful measurement.
CCDM® addresses performance indicators such as:
CCDM® emphasizes the difference between measuring security activity and measuring defensive effectiveness.
Artificial intelligence is transforming both defensive capability and adversary behavior.
CCDM® prepares managers to evaluate:
Automate Where Appropriate → Validate Performance → Maintain Human Authority → Govern the Risk
CCDM® also addresses emerging defensive considerations involving:
Cloud-Native Systems • APIs • Containers • IoT • OT • DevSecOps • Software Supply Chains • Automation • Emerging Attack Techniques
Technology alone cannot create effective cyber defense.
CCDM® prepares managers to build and lead the human capability behind enterprise defense.
Relevant areas include:
One of the most important CCDM® competencies is the ability to translate cyber-defense information into business decision language.
Executives generally do not need a list of thousands of alerts.
They need answers to questions such as:
CCDM® develops the communication progression:
CCDM® is designed around five critical leadership transitions.
The question is not merely:
“Which tools do we own?”
It becomes:
“What defensive capabilities do those technologies actually provide?”
The question is not:
“How many vulnerabilities exist?”
It becomes:
“Which exposures could materially affect the enterprise?”
The question is not:
“How many alerts did the SOC process?”
It becomes:
“Can we reliably detect and respond to the threats that matter?”
The question is not:
“Did we follow the incident playbook?”
It becomes:
“Did leadership make the right decisions quickly enough to protect critical operations?”
The question is not:
“Did the systems come back online?”
It becomes:
“Did we restore operations securely—and are we better prepared for the next incident?”
Throughout the program, candidates learn to address realistic management questions such as:
CCDM® does not require managers to personally operate every SIEM, EDR/XDR platform, vulnerability scanner, cloud-security platform, or forensic technology.
Instead, managers must understand enough to determine:
The central management objective of the Certified Cyber Defense Manager is:
CCDM® prepares professionals to transform cyber defense from a collection of security tools and operational activities into a:
A successful CCDM® professional understands that cyber defense is ultimately about more than protecting technology.
It is about protecting the organization’s ability to operate, serve customers, manage risk, recover from disruption, and continue creating value in the face of cyber threats.
Govern the Defense. Lead the Response. Restore the Enterprise. Build Resilience. Protect Value.
A major cyber incident rarely remains confined to the Security Operations Center.
What begins as a technical event can rapidly evolve into an enterprise-wide business disruption affecting operations, finances, customers, regulatory obligations, third parties, reputation, and executive decision-making.
A ransomware infection may disrupt critical services. A compromised identity may expose sensitive information. A cloud breach may interrupt customer-facing platforms. A supply-chain compromise may affect business partners. A destructive attack may require disaster recovery, legal coordination, executive communication, and board oversight.
Cyber incidents can therefore become:
An Operational Problem • A Financial Problem • A Legal and Regulatory Problem • A Customer Problem • A Supply-Chain Problem • A Reputational Problem • An Executive and Board-Level Problem
This changes the role of cyber-defense leadership.
Organizations need leaders who can connect what is happening inside the technical environment with what it means for the enterprise.
The cyber-defense manager must be capable of translating:
Security analysts may determine what happened technically.
Cyber-defense managers must determine what the organization should do about it.
This requires leaders to answer broader questions such as:
These are no longer purely technical questions.
They are enterprise leadership decisions informed by cyber-defense evidence.
Effective cyber-defense leadership requires understanding that security risk does not exist independently of organizational risk.
A technical vulnerability becomes important because of what it could enable.
A security incident becomes material because of what it could disrupt.
A defensive capability becomes valuable because of the business consequences it can prevent, reduce, or help the organization recover from.
Cyber-defense managers must therefore connect:
Assets → Threats → Vulnerabilities → Exposure → Business Services → Enterprise Risk
For example:
Critical vulnerability identified on an internet-facing system
↓
Active exploitation is possible and existing controls may not sufficiently reduce exposure
↓
Compromise could disrupt a critical customer service and expose regulated information
↓
Immediate remediation, compensating controls, enhanced monitoring, executive visibility, and contingency planning are required
CCDM® develops this ability to move from technical information to enterprise action.
Not every security incident requires executive or board involvement.
A defining responsibility of cyber-defense leadership is understanding when escalation is necessary.
An incident may become an enterprise cyber crisis when it begins to materially affect areas such as:
At this point, incident response must expand beyond the security organization.
The management progression becomes:
As severity increases, leadership requirements expand from technical containment toward enterprise coordination, risk acceptance, business continuity, communications, legal decisions, recovery prioritization, and executive governance.
CCDM® prepares managers to operate between the technical and executive environments.
Cyber-defense teams work with:
SIEM • SOAR • EDR/XDR • Network Telemetry • Threat Intelligence • Vulnerability Data • Cloud Logs • Identity Events • Forensic Evidence • Incident Information
These technologies provide evidence.
But evidence alone does not make an enterprise decision.
Executives and boards need to understand:
The cyber-defense manager must bridge these environments.
The question is no longer simply:
Management must also ask:
That includes questions such as:
Cyber-defense effectiveness therefore depends on:
Organizations cannot reasonably expect to prevent every cyberattack.
The stronger objective is to ensure that the enterprise can:
This is cyber resilience.
Cyber-defense leadership must ensure that the organization can continue operating—or restore critical operations rapidly—when preventive controls fail.
That requires coordination across:
The cyber-defense manager therefore becomes a critical link between security operations and organizational resilience.
Cyber-defense leaders must also move reporting beyond technical activity measures.
Traditional reports may focus on:
Alerts • Vulnerabilities • Incidents • Tickets • Patches
These metrics may be useful operationally, but senior leaders need additional context.
Executive-level reporting should help answer:
The management progression becomes:
The broader direction of the NIST Cybersecurity Framework 2.0 reinforces the importance of governance and organizational leadership in cybersecurity risk management.
The framework places Govern alongside Identify, Protect, Detect, Respond, and Recover, emphasizing that cybersecurity risk management is connected to organizational strategy, roles, responsibilities, policies, oversight, and enterprise risk.
For CCDM®, this reinforces a central leadership principle:
CCDM® is designed for this expanded leadership responsibility.
The certification develops professionals capable of connecting:
What threats should concern the organization?
↓
Where is the organization most vulnerable?
↓
Can those threats be identified quickly?
↓
Can the organization make the right decisions under pressure?
↓
Can critical services be restored securely?
↓
Can the enterprise continue operating and become stronger after disruption?
↓
Can leadership understand the risk and make informed decisions?
A cyber-defense manager is not simply responsible for whether security controls are operating.
The manager is responsible for helping answer a much larger question:
That is the leadership environment the Certified Cyber Defense Manager (CCDM®) is designed to address.
CCDM® develops competency across six management transitions:
Managers must determine whether the organization can detect material threats—not simply whether security tools produce alerts.
Managers must determine which weaknesses create material business risk.
Managers must know when technical response requires executive command and business-level decisions.
Restoring systems is not enough. Organizations must maintain critical operations and become stronger after incidents.
Managers must evaluate capability, cost, integration, risk, performance, and value.
Senior leaders need business-relevant information, not technical dashboards without context.
CCDM® managers are not expected to operate every security product.
They are expected to evaluate and govern technology capabilities.
SIEM • SOAR • EDR/XDR • Threat Intelligence • Security Analytics • Monitoring
IAM • MFA • SSO • PAM • Federation • Identity Governance
Firewalls • IDS/IPS • Segmentation • Secure Access • Zero Trust • Network Detection
Scanners • Asset Discovery • Attack-Surface Management • Exposure Management • Configuration Management
Cloud Security • CSPM Concepts • API Security • Application Security • DevSecOps • Container Security
Incident Management • Forensic Technologies • Backup & Recovery • Continuity • Crisis Management
AI-Assisted Detection • Automated Triage • Security Automation • AI Analytics • Intelligent Response
100 Questions
90 Minutes
Advanced Multiple-Choice + Scenario-Based Questions
Closed Book
Secure Online Proctoring or Approved Testing Center
Recommended Passing Score: 70%
Assessment emphasis:
Strategy • Governance • Threat Judgment • Incident Decisions • Crisis Leadership • Recovery • Resilience • Investment • Executive Judgment
Eligible instructor-led candidates may demonstrate advanced competency through the structured Enterprise Cyber Defense Management Capstone.
Candidates address realistic management scenarios requiring integration of:
Alignment does not constitute external accreditation or endorsement.
The CCDP® and CCDM® certification frameworks may incorporate credentialing-quality principles associated with:
ISO/IEC 17024 • ANAB • NCCA • I.C.E. • International Personnel-Certification Practices
Program quality areas include:
Job Task Analysis • Defined Competencies • Eligibility • Body of Knowledge • Examination Blueprint • SME Review • Psychometric Principles • Examination Security • Identity Verification • Impartial Decisions • Appeals • Ethics • Continuing Education • Recertification • Credential Verification • Periodic Review • Continuous Improvement
Any such alignment should be described as alignment only. It does not constitute formal accreditation, recognition, approval, or endorsement unless officially awarded by the applicable independent organization.
The Certified Cyber Defense Professional (CCDP®) is a vendor-neutral professional certification designed to validate practical competency across the modern cyber-defense lifecycle.
CCDP® focuses on:
Security Monitoring • Threat Detection • SOC Operations • Threat Intelligence • Threat Hunting • Vulnerability Management • Exposure Management • Incident Response • Digital Forensics • Recovery • Cyber Resilience • AI-Enabled Defense
The certification is designed for professionals who must interpret security information, recognize threats, investigate suspicious activity, prioritize defensive actions, support containment and eradication, preserve relevant evidence, contribute to secure recovery, and strengthen organizational resilience.
Monitor → Detect → Analyze → Investigate → Respond → Recover → Improve
The primary difference is the level of responsibility and decision-making.
A CCDP® professional may:
A CCDM® manager may:
CCDP® asks:
“What is happening, and what defensive action should we take?”
CCDM® asks:
“What does this mean for the enterprise, what should we prioritize, who must decide, and how should the organization respond?”
CCDP® is the recommended professional progression into CCDM®.
The recommended pathway is:
However, CCDP® may not be the only qualifying route.
Equivalent professional experience, education, training, or other relevant qualifications in areas such as:
may satisfy applicable IBACTP® eligibility requirements.
Candidates should review the current eligibility requirements applicable to CCDM® before applying.
CCDP® is particularly relevant for professionals working in or preparing for roles such as:
CCDP® is also suitable for IT professionals seeking to transition into cyber-defense or security-operations roles.
CCDM® is intended for experienced practitioners, managers, and professionals preparing for leadership responsibilities such as:
CCDM® is particularly relevant for professionals who must translate technical cyber-defense information into business risk, investment priorities, recovery decisions, and executive recommendations.
Yes.
Both certifications are designed around transferable professional competencies rather than dependence on a particular vendor, security product, or technology ecosystem.
Programs may reference technologies such as:
SIEM • SOAR • EDR/XDR • IDS/IPS • Firewalls • Threat Intelligence • Vulnerability Management • Attack-Surface Management • Cloud Security • Digital Forensics • Incident Management • Backup & Recovery • AI-Assisted Security
However, certification competency is based on understanding:
rather than demonstrating proficiency with one commercial product.
Yes.
SOC operations are a major part of CCDP®.
Candidates develop competency in areas such as:
CCDP® focuses on understanding how security telemetry becomes an informed defensive decision.
Yes. SOC leadership is a core CCDM® management competency.
Managers evaluate:
The management question is not simply:
“How many alerts did the SOC process?”
It is:
Yes.
Candidates learn to apply threat intelligence to:
Managers learn to use threat intelligence to guide:
The progression is:
CCDP® — Analyze and Apply Intelligence
↓
CCDM® — Govern and Prioritize with Intelligence
Yes.
Both certifications address vulnerability and exposure management, but at different levels.
Professionals evaluate:
Managers govern:
CCDM® emphasizes moving from traditional severity-only thinking toward:
Yes. Incident response is one of the defining elements of the entire pathway.
Candidates develop competency in:
Managers develop competency in:
CCDP®: Detect → Investigate → Respond
CCDM®: Govern → Direct → Lead
Yes.
Cyber crisis management is a defining leadership component of CCDM®.
Candidates learn to evaluate when an operational cyber incident requires broader enterprise escalation.
This may occur when an incident materially affects:
CCDM® prepares managers to understand the progression:
Yes, but at different levels.
Candidates learn relevant forensic concepts including:
Managers focus on:
Candidates seeking deeper specialization specifically in digital forensics may also consider the IBACTP® CDFOP® → CDFOM® Digital Forensics pathway.
Yes. Recovery and resilience are defining elements of CCDP®.
Candidates learn how to support:
The objective is not simply:
“Bring the system back online.”
It is:
Yes. Cyber resilience is a central management objective of CCDM®.
Managers learn to connect:
Incident Response + Business Continuity + Disaster Recovery + Critical-Service Restoration + Lessons Learned + Enterprise Risk
CCDM® treats resilience as the organization’s ability to:
Yes.
Candidates evaluate:
Managers evaluate:
The management principle is:
Yes.
CCDM® emphasizes measuring whether cyber-defense capabilities are actually effective.
Relevant measures may include:
Candidates learn to distinguish between:
and
Yes.
Cyber-defense leaders must determine where limited resources create the greatest defensive value.
CCDM® addresses:
Managers evaluate investments based on:
Yes.
Managers develop competency in evaluating and governing:
Relevant considerations include:
Capability • Contracts • Service Levels • Integration • Data Handling • Escalation • Performance • Dependency • Risk • Cost
Yes. This is a major CCDM® competency.
Managers must translate technical security information into language that supports organizational decision-making.
The communication progression is:
Candidates develop competency in communicating:
The objective is to provide executives and boards with decision-relevant information rather than unnecessary technical complexity.
Candidates may demonstrate competency through an applicable certification pathway.
Recommended structure:
Assessment emphasizes:
Knowledge • Detection • Analysis • Threat Recognition • Incident Judgment • Investigation • Recovery • Resilience
Eligible candidates participating in an approved instructor-led pathway may demonstrate competency through a structured CCDP® Applied Cyber Defense Capstone.
Recommended structure:
Assessment emphasizes:
Strategy • Governance • Threat Judgment • Exposure Prioritization • Incident Decisions • Crisis Leadership • Recovery • Resilience • Investment • Executive Judgment
Eligible candidates in an approved instructor-led pathway may demonstrate advanced management competency through the Enterprise Cyber Defense Management Capstone.
CCDP® evaluates professional competency across areas including:
Cyber Defense Architecture • Security Monitoring • Threat Detection • Threat Intelligence • Threat Hunting • Exposure Management • Incident Response • Digital Forensics • Recovery • Cyber Resilience • AI-Enabled Defense
CCDM® evaluates management competency across areas including:
Cyber Defense Strategy • SOC Leadership • Threat Governance • Exposure Prioritization • Incident Leadership • Cyber Crisis Management • Recovery • Resilience • Technology Investment • Performance Measurement • AI Governance • Workforce Leadership • Executive Communication
Recommended training may vary according to delivery model and candidate background.
A general program range is:
Approximately 40–60 instructional hours
Approximately 50–60 instructional hours
Training may include instructor-led instruction, scenarios, applied activities, practical exercises, simulations, case studies, and Capstone work where applicable.
The recommended credential cycle for both certifications is:
Credential holders maintain professional competence through applicable IBACTP® Continuing Professional Education (CPE), professional ethics, certification-maintenance, and recertification requirements.
Final requirements are governed by current IBACTP® certification policies.
The recommended advanced progression is:
CCDP® develops professional cyber-defense competency.
CCDM® advances that capability into enterprise strategy, governance, leadership, investment, performance, crisis management, and resilience.
Organizations need professionals who can detect and respond.
They also need leaders who can govern, prioritize, recover, and build resilience.
Detect Earlier. Analyze Accurately. Respond Effectively. Recover Securely.
[EXPLORE CCDP®] [ENROLL NOW] [REGISTER FOR CCDP® EXAM]
Anticipate Threats. Govern Defense. Lead Cyber Crises. Build Resilience.
[EXPLORE CCDM®] [ENROLL NOW] [REGISTER FOR CCDM® EXAM]
Certified Cyber Defense Manager
Assess • Strategize • Govern • Prioritize • Lead • Measure • Transform
Everything you need to plan your sitting.
Exam code for the Advanced Manager-level Cyber Defense credential.
Multiple choice, completed in 120 minutes.
Passing score. Delivered in English.
A minimum of five years of experience, including two years in a supervisory, lead or management role.
IBACTP® approved testing centers and online proctored delivery
Three-year certification cycle with continuing professional education
Every route leads to the same CCDM® examination and the same designation.
Start as a Professional. Advance as a Leader.
Exam fee only, with complimentary course materials provided — $400 USD.
4 days, 2 hours daily online. All course materials + Exam — $1,200 USD.
10 days, 2 hours daily. All course materials + Exam — $1,800 USD.
Certify a whole team on a schedule that suits your organization. Fees negotiable.
Explore frequently asked questions about the Certified Cyber Defense Manager (CCDM®) certification, eligibility, leadership competencies, assessment pathways, technology coverage, and professional progression.
The IBACTP® Cyber Defense Certification Pathway is designed to support professionals at two distinct career levels:
The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral professional certification designed for cybersecurity professionals responsible for leading, governing, measuring, resourcing, and transforming enterprise cyber-defense capabilities.
CCDM® focuses on:
Cyber Defense Strategy • SOC Leadership • Threat Management • Exposure Governance • Incident Leadership • Cyber Crisis Management • Recovery • Cyber Resilience • Technology Investment • Performance Measurement • AI-Enabled Defense • Workforce Leadership • Executive Communication
The certification moves beyond performing individual cyber-defense activities and focuses on the management decisions required to ensure that an organization can anticipate threats, detect attacks, respond effectively, restore critical operations, and continuously strengthen resilience.
CCDM® is designed for experienced cybersecurity, cyber-defense, security-operations, incident-response, risk, resilience, and technology professionals seeking advanced management and leadership responsibilities.
Relevant roles may include:
CCDM® is particularly relevant for professionals who must translate technical security conditions into management priorities, investment decisions, operational actions, and executive recommendations.
The two credentials represent different levels of the IBACTP® cyber-defense pathway.
CCDP® focuses primarily on performing and supporting cyber-defense activities:
Monitor → Detect → Analyze → Investigate → Respond → Recover
CCDM® focuses on governing and leading enterprise cyber-defense capabilities:
Assess → Strategize → Govern → Prioritize → Lead → Measure → Transform
A CCDP® professional may investigate an incident and recommend containment.
A CCDM® manager determines whether the incident requires enterprise escalation, establishes decision authority, evaluates business consequences, coordinates leadership response, directs recovery priorities, and communicates readiness and risk to executives.
The recommended progression is:
CCDP® is the recommended professional pathway into CCDM®.
However, professionals with equivalent qualifying experience in cybersecurity, cyber defense, SOC operations, incident response, technology risk, business continuity, cyber resilience, security management, or related leadership responsibilities may satisfy applicable IBACTP® eligibility requirements.
Candidates should review current certification eligibility policies before applying.
CCDM® develops transferable management and leadership competencies rather than expertise with one specific security vendor, technology platform, cloud provider, or security product.
Managers learn to evaluate technologies according to factors such as:
Capability • Integration • Risk Reduction • Performance • Cost • Scalability • Resilience • Governance • Operational Value
This allows CCDM® competencies to remain relevant across different industries and technology environments.
Yes.
Candidates evaluate areas including:
The management objective is not simply to operate a SOC, but to determine:
Yes. SOC leadership is a major CCDM® competency.
CCDM® addresses threat intelligence from a management and decision-making perspective.
Managers evaluate how intelligence supports:
The emphasis is on converting intelligence into defensive priorities and management decisions.
Yes.
CCDM® moves beyond simply reviewing vulnerability severity scores.
Candidates learn to govern enterprise exposure using factors such as:
Yes.
Managers evaluate which weaknesses require immediate remediation, which can be mitigated through compensating controls, and which risks may require formal treatment or executive attention.
CCDM® addresses incident response from a management and leadership perspective.
Candidates evaluate:
The emphasis is on ensuring that technical response activities are supported by effective leadership, governance, accountability, communication, and decision-making.
Yes.
Not every cybersecurity incident becomes an enterprise crisis.
CCDM® prepares managers to evaluate when an incident requires broader organizational escalation because of factors such as:
Candidates learn to connect:
Yes. Cyber crisis leadership is a defining CCDM® competency.
CCDM® does not focus primarily on performing detailed forensic examinations.
Instead, managers develop competency in overseeing:
The focus is on ensuring that investigations are properly governed and support defensible organizational decisions.
Yes, from a management and governance perspective.
CCDM® integrates cyber incident management with business continuity, disaster recovery, critical-service restoration, and organizational resilience.
Candidates evaluate:
This enables managers to connect technical cybersecurity recovery with enterprise operational requirements.
Yes.
Organizations cannot assume that every attack will be prevented.
Cyber-defense leadership must therefore prepare the organization to:
CCDM® treats resilience as a measurable enterprise capability involving technology, people, processes, governance, continuity, recovery, exercises, and continuous improvement.
The goal is not simply to restore technology after an incident.
The goal is to restore critical operations securely and emerge better prepared for the next disruption.
CCDM® addresses management and governance considerations involving technology categories such as:
SIEM • SOAR • EDR/XDR • IDS/IPS • Threat Intelligence • Vulnerability Management • Attack-Surface Management • Cloud Security • Identity Security • Digital Forensics • Incident Management • Backup and Recovery • AI-Assisted Security
Managers are expected to understand how to evaluate:
Selection • Integration • Governance • Cost • Performance • Scalability • Risk • Vendor Capability • Business Value
The certification does not require mastery of one specific commercial product.
Yes.
CCDM® examines both the opportunities and risks created by artificial intelligence.
Management considerations include:
The management principle is:
Yes.
Managers must be able to demonstrate whether defensive capabilities are actually improving.
CCDM® addresses:
The objective is to move cyber-defense reporting from:
Yes.
toward:
CCDM® prepares managers to evaluate cyber-defense investments based on risk, capability requirements, cost, performance, operational impact, and enterprise value.
Candidates examine areas such as:
The objective is to ensure that cyber-defense resources are directed toward the capabilities that matter most.
Yes.
Modern cyber defense frequently depends on external technology providers, Managed Security Service Providers, cloud providers, consultants, incident-response partners, and other third parties.
CCDM® addresses management considerations involving:
Managers must understand that outsourcing a security capability does not eliminate organizational accountability for cyber risk.
Yes.
Technology alone cannot create an effective cyber-defense capability.
CCDM® addresses:
Managers learn to align people, processes, technologies, and governance around enterprise defensive objectives.
Yes.
Senior cyber-defense leaders must translate complex technical information into language that supports business decisions.
Candidates develop competency in communicating:
The communication progression is:
Yes. This is a major competency of CCDM®.
The objective is not to overwhelm executives with technical detail, but to provide the information necessary for informed governance and decision-making.
CCDM® provides two assessment pathways.
The recommended structure includes:
100 Questions • 90 Minutes • Advanced Multiple-Choice and Scenario-Based Questions • Closed Book • Secure Proctoring • Recommended Passing Score: 70%
The assessment emphasizes:
Eligible candidates participating in an approved instructor-led pathway may demonstrate advanced competency through the CCDM® Enterprise Cyber Defense Management Capstone.
The Capstone integrates multiple management competencies within realistic enterprise cyber-defense situations.
The CCDM® assessment evaluates advanced managerial competency across eight integrated domains:
The CCDM® competency standard is:
CCDM® is designed to develop the connection between operational cyber defense and senior organizational decision-making.
The credential is particularly relevant for professionals who must advise senior management or boards regarding:
CCDM® therefore prepares professionals not only to manage security operations, but also to communicate cyber-defense readiness as an enterprise risk and resilience issue.
Yes.
The recommended CCDM® certification cycle is:
Credential holders maintain professional competency through applicable IBACTP® Continuing Professional Education (CPE), professional ethics, certification-maintenance, and recertification requirements.
Credential holders should consult current IBACTP® policies for specific requirements applicable to their certification cycle.
Develop and validate enterprise cyber-defense strategy, governance, incident leadership, resilience, investment, workforce, and executive decision-making competencies.
Together, the certifications create a structured progression:
Become CCDM® Certified
Move beyond managing individual tools and security activities.
Anticipate Threats. Govern Defense. Lead Cyber Crises. Build Resilience. Protect Enterprise Value.
Certified Cyber Defense Manager (CCDM®) · International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)