IBACTP® — International Board of AI, Cybersecurity & Technology Professionals
CCDM®

Certified Cyber Defense Manager

Anticipate Threats. Govern Defense. Lead Cyber Crises. Build Enterprise Resilience.

Cyber-defense leadership is no longer limited to managing a Security Operations Center or purchasing security technologies.

A security analyst monitoring code on dark screens
Cyber Defense
CCDM® Certified Cyber Defense Manager badge

Command Detection, Response and Cyber Resilience.

Advanced Manager Level For cyber defense leaders, managers and decision-makers
Vendor-Neutral Skills and knowledge that apply across platforms and tools
Global Recognition Recognized internationally across industries and regions
Digital Credential Shareable, verifiable credential and certificate

What You Will Learn

Master the core areas of cyber defense.

  • 8 Advanced Cyber Defense Management Modules

Module 1 — Enterprise Cyber Defense Strategy and Governance

  • Cyber-defense maturity and readiness
  • Enterprise strategy and priorities
  • Governance and accountability
  • Operating models and strategic roadmaps

Module 2 — SOC, Detection, and Security Operations Leadership

  • SOC strategy and operating models
  • Detection and monitoring governance
  • Threat intelligence and automation
  • Staffing, sourcing, escalation, and performance

Module 3 — Threat, Vulnerability, and Exposure Governance

  • Enterprise threat landscape
  • Vulnerability-program governance
  • Exposure and attack-surface management
  • Risk-based remediation prioritization

Module 4 — Incident Response and Cyber Crisis Leadership

  • Incident governance and severity
  • Command, escalation, and decision authority
  • Major incident and crisis leadership
  • Executive and stakeholder communication

Module 5 — Recovery, Continuity, and Enterprise Cyber Resilience

  • Cyber-recovery strategy
  • Business continuity and disaster recovery
  • Critical-service restoration
  • Exercises, lessons learned, and resilience improvement

Module 6 — Cyber Defense Investment, Technology, and Performance

  • Business cases and investment prioritization
  • Technology and vendor governance
  • KPIs, KRIs, and performance measurement
  • Capability maturity and enterprise value

Module 7 — AI-Enabled Defense and Emerging Cyber Risk

  • AI-assisted detection and response
  • AI-enabled attack risks
  • Automation governance and human oversight
  • Cloud, OT, IoT, supply-chain, and emerging threats

Module 8 — Workforce, Executive Leadership, and Transformation

  • Workforce and capability planning
  • Cyber-defense leadership and culture
  • Executive and board communication
  • Organizational transformation and continuous improvement
About the credential

Become a Cyber Defense professional the market trusts.

When a major cyberattack occurs, leaders must rapidly determine

What happened? What is at risk? How serious is it? What should be contained? Who has decision authority? Which operations must recover first? What should executives know? What investment is required to prevent recurrence?

The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral professional certification designed to validate management and leadership competency across enterprise cyber-defense strategy, SOC governance, threat and exposure management, incident and crisis leadership, recovery, resilience, investment, technology governance, workforce leadership, AI-enabled defense, and executive decision-making.

Offered by the: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

CCDM® represents the advanced management level of the IBACTP® cyber-defense certification pathway.

Lead Cyber Defense as an Enterprise Capability

  • Strategy
  • Governance
  • SOC Leadership
  • Threat Management
  • Exposure Governance
  • Incident Leadership
  • Crisis Management
  • Recovery
  • Cyber Resilience
  • Investment
  • AI Defense
  • Executive Leadership
A security analyst monitoring code on dark screens

Advanced Manager level — Three-year certification cycle with continuing professional education

CCDM® Leadership Objective

Anticipate Threats → Govern Defense → Lead Response → Restore Operations → Strengthen Resilience → Protect Enterprise Value

Modern cyber-defense leadership extends far beyond managing security tools, reviewing alerts, or supervising technical teams. Today’s cyber-defense managers must be prepared to anticipate threats, govern enterprise defensive capabilities, prioritize exposures, direct security operations, lead major incidents, coordinate crisis response, restore critical services, measure resilience, evaluate technology investments, develop cyber-defense teams, and communicate effectively with executives and boards.

The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral management certification offered by the International Board of AI, Cybersecurity & Technology Professionals (IBACTP®).

CCDM® is designed for experienced professionals responsible for the strategy, governance, leadership, performance, investment, risk, and transformation of enterprise cyber-defense capabilities.

The certification moves beyond operational cyber defense and focuses on a critical leadership question

“Can the organization detect the threats that matter, respond effectively when attacks occur, restore critical operations, and continuously strengthen its resilience?”

A security analyst monitoring code on dark screens
CCDM®

Why Earn CCDM®?

A technically sophisticated security program can still fail if the organization cannot make effective decisions during a crisis.

Cyber-defense managers must connect:

Technology + Threats + Risk + Operations + People + Business Priorities + Executive Decisions

CCDM® develops leadership competency to answer questions such as:

  • Which threats present the greatest enterprise risk?
  • Can existing defenses detect those threats?
  • Where are the largest exposure gaps?
  • Is the SOC performing effectively?
  • Are critical alerts being escalated appropriately?
  • Which vulnerabilities require executive attention?
  • When does an incident become an enterprise crisis?
  • Who can authorize major containment actions?
  • What happens if containment disrupts critical operations?
  • Which business services must recover first?
  • Are backup and recovery capabilities dependable?
  • How resilient is the organization?
  • Which security investments should receive priority?
  • Are security vendors delivering sufficient value?
  • How should AI-enabled defense be governed?
  • What should senior executives know?
  • What should the board know?
  • What must change after a major incident?
CCDM®

Who Should Earn CCDM®?

CCDM® is designed for experienced professionals moving into or currently serving in cyber-defense management and leadership roles.

Relevant Roles

CCDM® can also support senior technical professionals preparing for management, director, or enterprise leadership responsibilities.

Absolutely. Below is a comprehensive, executive-level version for CCDM®, written to distinguish the course description, course learning outcomes, and certification testing outcomes clearly.

  • Cyber Defense Manager
  • SOC Manager
  • Security Operations Manager
  • Cybersecurity Manager
  • Incident Response Manager
  • Cyber Incident Manager
  • Cyber Resilience Manager
  • Threat Management Manager
  • Vulnerability and Exposure Manager
  • Information Security Manager
  • Cybersecurity Program Manager
  • Technology Risk Manager
  • Security Operations Lead
  • Cybersecurity Director
  • Cyber Defense Director
  • Head of Security Operations
  • Cybersecurity Consultant
  • Cyber Resilience Leader
Learning outcomes

CCDM® Course Learning Outcomes

Upon successful completion of the Certified Cyber Defense Manager (CCDM®) program, participants will be able to demonstrate advanced competency across eight integrated cyber-defense management domains.

1. Develop Enterprise Cyber Defense Strategy and Governance

Assess cyber-defense maturity, identify capability gaps, establish strategic priorities, define governance structures, develop operating models and roadmaps, and align defensive capabilities with enterprise risk and business objectives.

2. Lead SOC, Detection, and Security Operations

Govern SOC strategy, monitoring, detection, threat intelligence, threat hunting, automation, escalation, staffing, sourcing, service levels, and operational performance.

3. Govern Threat, Vulnerability, and Exposure Management

Evaluate threat conditions, attack surfaces, vulnerabilities, exploitability, asset criticality, business impact, remediation priorities, and enterprise exposure to support risk-based defensive decisions.

4. Direct Incident Response and Cyber Crisis Management

Establish incident-governance structures, severity models, escalation criteria, command responsibilities, containment priorities, cross-functional coordination, executive decisions, and crisis communication.

5. Lead Recovery, Continuity, and Cyber Resilience

Integrate incident response with technical recovery, business continuity, disaster recovery, critical-service restoration, resilience testing, lessons learned, and continuous improvement.

6. Manage Cyber Defense Investment, Technology, Vendors, and Performance

Develop business cases, evaluate defensive technologies, prioritize resources, govern vendors and managed services, establish KPIs and KRIs, and measure defensive effectiveness, maturity, and value.

7. Govern AI-Enabled Defense and Emerging Cyber Risk

Evaluate AI-assisted security, defensive automation, Generative AI, AI-enabled attacks, cloud-native risks, IoT, OT, APIs, software supply chains, and emerging technologies while maintaining appropriate governance and human oversight.

8. Lead Cyber Defense Workforce, Executive Communication, and Transformation

Build cyber-defense teams, identify skills gaps, develop workforce capabilities, strengthen organizational readiness, communicate cyber risk and resilience to executives and boards, and lead enterprise transformation.

Learning outcomes

CCDM® Integrated Learning Outcome

Upon completion of the program, participants will be prepared to connect:

  • Assess Readiness → Establish Strategy → Govern Cyber Defense → Lead Major Incidents → Restore Critical Operations → Measure Resilience → Drive Continuous Improvement

Threat Intelligence + Enterprise Exposure + Security Operations + Incident Leadership + Recovery + Resilience + Investment + Technology + People + Executive Decision-Making

The ultimate course learning objective is to enable participants to:

What is assessed

CCDM® Certification Testing Outcomes

The CCDM® certification assessment evaluates whether candidates can apply advanced cyber-defense management knowledge, interpret enterprise risk and technical evidence, prioritize defensive actions, and exercise sound managerial and executive judgment across eight competency domains.

The certification assessment emphasizes application, analysis, evaluation, prioritization, governance, leadership, and scenario-based decision-making rather than memorization alone.

What is assessed

CCDM® Certification Testing Outcomes — Skills and Competencies Tested

The CCDM® certification assessment evaluates whether candidates can demonstrate advanced managerial skill, professional judgment, governance capability, and leadership competency across eight enterprise cyber-defense domains.

Candidates are expected to demonstrate competency in:

CCDM®

CCDM® Assessment Cognitive Standard

CCDM® evaluates advanced professional judgment across the following levels:

Understand

Interpret relevant cyber-defense concepts, risks, technologies, governance structures, and management practices.

Apply

Apply management principles to realistic enterprise cyber-defense situations.

Analyze

Interpret threat intelligence, operational information, incident evidence, exposure data, resilience information, and performance metrics.

Evaluate

Compare alternatives, assess tradeoffs, evaluate risk, and determine appropriate management responses.

Prioritize

Determine which threats, incidents, exposures, investments, or recovery actions require the greatest attention.

Decide

Select defensible management actions under conditions of uncertainty, operational pressure, and competing business priorities.

Lead

Determine how people, processes, technologies, governance, communication, and executive oversight should be coordinated.

CCDM®

CCDM® Certification Competency Standard

CCDM® assesses more than knowledge of cyber-defense management terminology.

Successful candidates demonstrate the ability to integrate:

Strategy + Governance + Threat Judgment + SOC Leadership + Exposure Prioritization + Incident Leadership + Recovery + Resilience + Investment + Technology + Workforce + Executive Judgment

The CCDM® certification competency progression is:

Assess → Strategize → Govern → Prioritize → Decide → Lead → Recover → Measure → Transform

The ultimate certification testing objective is to validate whether a candidate can:

Interpret Threat and Risk Information → Establish Priorities → Govern Cyber Defense → Lead Major Incidents → Direct Recovery → Measure Resilience → Advise Executives → Protect Enterprise Value

A successful CCDM® candidate demonstrates the advanced managerial competency necessary to lead cyber defense as a strategic, measurable, resilient, and enterprise-wide capability.

CCDM®

The CCDM®–IBACTP® Cyber Defense Management Competency Model

CCDM® develops advanced competency across eight integrated management dimensions.

1. Enterprise Cyber Defense Strategy and Governance

Assess defensive maturity, establish priorities, define governance, develop operating models, establish roadmaps, and align cyber defense with enterprise risk.

2. SOC, Detection, and Security Operations Leadership

Govern SOC strategy, monitoring, detection, intelligence, automation, escalation, staffing, service providers, and performance.

3. Threat, Vulnerability, and Exposure Governance

Prioritize threats and enterprise exposures according to exploitability, intelligence, asset criticality, business impact, and organizational risk.

4. Incident Response and Cyber Crisis Leadership

Establish incident governance, severity models, command structures, decision authorities, escalation criteria, containment priorities, and crisis communication.

5. Recovery, Continuity, and Cyber Resilience

Integrate incident response with business continuity, disaster recovery, critical-service restoration, exercises, lessons learned, and resilience improvement.

6. Cyber Defense Investment, Technology, and Performance

Evaluate business cases, technologies, vendors, resource priorities, KPIs, KRIs, capability maturity, and defensive value.

7. AI-Enabled Defense and Emerging Cyber Risk Governance

Evaluate AI-assisted defense, automation, AI-enabled attacks, cloud-native risks, OT, IoT, software supply chains, and emerging defensive technologies.

8. Workforce, Executive Communication, and Transformation

Build cyber-defense teams, develop organizational capabilities, communicate readiness and risk to executives and boards, and lead transformation.

CCDM®

Option 2 — Enterprise Cyber Defense Management Capstone

Eligible instructor-led candidates may demonstrate competency through a structured three-part management Capstone.

Part 1 — Strategy, Readiness, and Investment Roadmap

Assess enterprise cyber-defense maturity, threats, exposure, capabilities, governance, technology, and workforce.

Develop:

Current State → Capability Gaps → Target State → Priorities → Investment Roadmap

Part 2 — Major Incident and Cyber Crisis Leadership

Manage a simulated enterprise cyber incident involving technical, operational, business, regulatory, and executive decisions.

Demonstrate:

Assess → Escalate → Decide → Contain → Coordinate → Communicate

Part 3 — Recovery, Resilience, and Executive Recommendations

Develop recovery priorities, resilience improvements, metrics, investments, and executive recommendations.

Conclude with an executive-level presentation:

What Happened → Why It Matters → What Was Done → What Remains at Risk → What Must Improve → What Decision Is Required

CCDM®

What Is CCDM®?

The Certified Cyber Defense Manager (CCDM®) is an advanced professional certification for managers and leaders responsible for building, governing, directing, measuring, and continuously improving enterprise cyber-defense capabilities.

CCDM® moves beyond the question:

“How do we detect and respond to an attack?”

It develops competency to address the broader leadership question:

“Is the enterprise prepared to anticipate, withstand, respond to, recover from, and learn from a significant cyberattack?”

The certification addresses:

  • Enterprise cyber-defense strategy
  • Cyber-defense governance
  • SOC strategy and operating models
  • Security monitoring
  • Detection strategy
  • Threat intelligence
  • Threat hunting governance
  • Vulnerability management
  • Exposure management
  • Incident governance
  • Major incident leadership
  • Cyber crisis management
  • Digital-investigation oversight
  • Business continuity
  • Disaster recovery
  • Cyber resilience
  • Technology investment
  • Vendor governance
  • Cyber-defense metrics
  • AI-enabled defense
  • Workforce leadership
  • Executive reporting
  • Board communication
  • Organizational transformation
Applied practice

Applied Management Labs

Cyber Defense

Standards and International Framework Alignment

The CCDM® Body of Knowledge incorporates relevant principles from:

ISO/IEC 27001 • ISO/IEC 27002 • ISO/IEC 27005 • ISO/IEC 27701 • ISO 22301 • ISO 31000 • ISO/IEC 42001 • ISO/IEC 23894 • NIST Cybersecurity Framework • NIST NICE Workforce Framework • NIST AI RMF • Relevant NIST Cybersecurity and Incident-Response Guidance • CISA Guidance

The management progression is:

Cyber Defense

Global and Vendor-Neutral by Design

CCDM® is not tied to one:

SIEM • SOAR • EDR/XDR • Firewall • Cloud Provider • Vulnerability Platform • Threat-Intelligence Vendor • Forensic Product • Incident Platform • AI Security Vendor

Managers learn to evaluate technologies based on:

Capability • Integration • Performance • Risk Reduction • Cost • Scalability • Governance • Resilience • Enterprise Value

CCDM®

Recommended Pathway · CCDM® Leadership Progression

Recommended Pathway

The recommended IBACTP® progression is:

CCDM® Leadership Progression

The curriculum develops managerial capability through:

CCDM®

CCDM® Course Description

The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral professional certification designed to develop and validate the management, governance, strategic, analytical, and leadership competencies required to direct enterprise cyber-defense capabilities.

CCDM® prepares experienced cybersecurity and technology professionals to move beyond operational cyber-defense tasks and lead integrated programs involving Security Operations Centers, threat detection, threat intelligence, vulnerability and exposure management, incident response, cyber crisis management, digital investigation oversight, recovery, business continuity, cyber resilience, security investment, workforce leadership, AI-enabled defense, and executive communication.

The program emphasizes the management decisions required to ensure that cyber-defense capabilities are aligned with enterprise risk, business priorities, critical services, regulatory expectations, technology dependencies, and organizational resilience objectives.

Participants learn how to evaluate whether an organization can:

CCDM® integrates:

  • Detect significant cyber threats
  • Prioritize critical vulnerabilities and exposures
  • Escalate incidents appropriately
  • Coordinate technical and business response
  • Lead major cyber incidents and crises
  • Restore critical services securely
  • Measure defensive readiness and resilience
  • Prioritize cybersecurity investments
  • Govern defensive technologies and service providers
  • Build capable cyber-defense teams
  • Communicate risk and readiness to executives and boards
  • Govern AI-assisted defense and emerging cyber risks
  • CCDM® Leadership Progression
  • Anticipate Threats → Govern Defense → Lead Response → Restore Operations → Strengthen Resilience → Protect Enterprise Value

Cyber Defense Strategy + Governance + SOC Leadership + Threat Management + Exposure Governance + Incident Leadership + Crisis Management + Recovery + Cyber Resilience + Technology Investment + AI-Enabled Defense + Workforce Leadership + Executive Decision-Making

The program places particular emphasis on transforming cyber defense from a collection of technical tools and operational activities into a measurable, governed, and resilient enterprise capability.

Assess → Strategize → Govern → Prioritize → Defend → Respond → Recover → Measure → Lead → Transform

The central management objective is:

CCDM®
  • CCDP®
  • CCDM®

CCDP®

Build professional competency in:

Monitoring • Detection • Analysis • Investigation • Response • Recovery

CCDM®

Advance into management competency in:

Strategy • Governance • Prioritization • Leadership • Measurement • Transformation

Equivalent qualifying cybersecurity, cyber-defense, SOC, incident-response, technology-risk, continuity, resilience, or security-management experience may satisfy applicable IBACTP® eligibility requirements.

CCDM®
  • Assess
  • Strategize
  • Govern
  • Prioritize
  • Defend
  • Respond
  • Recover
  • Measure
  • Transform

Assess

Understand the organization's threats, exposure, maturity, readiness, and resilience.

Strategize

Determine where the organization needs to go and establish a defensible roadmap.

Govern

Define accountability, authority, operating models, policies, and decision rights.

Prioritize

Direct attention and resources toward the threats and exposures that matter most.

Defend

Ensure security operations possess effective visibility, detection, intelligence, and defensive capabilities.

Respond

Lead coordinated organizational action during significant cyber incidents.

Recover

Restore critical operations securely and connect technical recovery with business priorities.

Measure

Evaluate performance using meaningful KPIs, KRIs, maturity measures, exposure trends, and resilience indicators.

Transform

Use evidence, incidents, exercises, investments, workforce development, and emerging technologies to continuously improve enterprise cyber defense.

CCDM®

Flexible CCDM® Certification Assessment

Option 1 — CCDM® Certification Examination

100 Questions

90 Minutes

Advanced Multiple-Choice + Scenario-Based Questions

Closed Book

Secure Online Proctoring or Approved Testing Center

Recommended Passing Score: 70%

Assessment emphasizes:

Strategy • Governance • Threat Judgment • Exposure Prioritization • Incident Decisions • Crisis Leadership • Recovery • Resilience • Investment • Executive Judgment

CCDM®

Technologies Managers Need to Understand

CCDM® remains vendor-neutral while developing management competency across technology categories such as:

Security Operations

SIEM • SOAR • EDR/XDR • Threat Intelligence • Security Analytics • Monitoring Platforms

Vulnerability and Exposure

Vulnerability Scanners • Asset Discovery • Attack-Surface Management • Exposure Management • Configuration Management

Network and Cloud Defense

Firewalls • IDS/IPS • Segmentation • Zero Trust • Cloud Security • Secure Access

Incident and Resilience

Incident Platforms • Digital Forensics • Backup & Recovery • Continuity Technologies • Crisis-Management Platforms

AI-Enabled Security

AI-Assisted Detection • Security Automation • AI Analytics • Automated Response • AI Threat Analysis

CCDM® focuses on:

Selection → Integration → Governance → Cost → Performance → Risk → Enterprise Value

—not simply operation of individual products.

CCDM®

From Cyber Incident to Enterprise Crisis

One of the defining CCDM® competencies is determining when a technical security event requires enterprise leadership.

CCDM® examines the progression:

CCDM®

Security Event → Cyber Incident → Major Incident → Enterprise Cyber Crisis

Managers develop competency to determine:

  • Severity
  • Business impact
  • Escalation requirements
  • Decision authority
  • Containment implications
  • Legal and regulatory involvement
  • Executive involvement
  • Crisis communication
  • Recovery priorities
CCDM®

Executive and Board Communication

CCDM® prepares cyber-defense managers to translate technical conditions into executive decisions.

Effective leadership communication answers:

What Is Happening? → Why Does It Matter? → What Is at Risk? → What Are We Doing? → What Decision Is Required?

Relevant reporting may include:

The goal is not to overwhelm executives with technical information.

The goal is to provide the right information for the right decision at the right time.

  • Significant threats
  • Enterprise exposure
  • Defensive readiness
  • Major incidents
  • Business impact
  • Recovery status
  • Resilience gaps
  • KPIs and KRIs
  • Investment priorities
  • Strategic recommendations
CCDM®

Measuring Cyber Defense

CCDM® emphasizes evidence-based management.

Managers learn to evaluate measures involving:

CCDM® develops the ability to move from:

  • Detection coverage
  • Detection effectiveness
  • Mean time to detect
  • Mean time to respond
  • Mean time to contain
  • Vulnerability remediation
  • Exposure reduction
  • Incident severity
  • Incident recurrence
  • Recovery performance
  • Exercise performance
  • SOC effectiveness
  • Resilience maturity
CCDM®
  • Understand
  • Interpret
  • Assess
  • Prioritize
  • Govern
  • Measure
  • Improve

CCDM® teaches frameworks as management and decision-support resources, rather than simple memorization requirements.

Framework alignment does not constitute accreditation, recognition, approval, or endorsement by the referenced organizations.

CCDM®

CCDM® Credentialing Quality

The CCDM® framework incorporates credentialing-quality principles associated with:

ISO/IEC 17024 • ANAB • NCCA • I.C.E. • International Personnel-Certification and Conformity-Assessment Practices

The certification framework encompasses:

Job Task Analysis • Defined Management Competencies • Eligibility Standards • Validated Body of Knowledge • Examination Blueprint • SME Participation • Psychometric Principles • Examination Security • Identity Verification • Impartial Certification Decisions • Appeals and Complaints • Ethics • Continuing Education • Recertification • Credential Verification • Periodic Review • Continuous Improvement

The CCDM® credentialing-quality lifecycle is:

Define → Validate → Assess → Certify → Maintain → Verify → Review → Improve

Alignment does not constitute formal accreditation, recognition, approval, endorsement, or affiliation. Such status is represented only after officially awarded by the applicable independent organization.

CCDM®
  • CCDP®
  • CCDM®: Build Your Cyber Defense Career

CCDP® — Professional Level

Certified Cyber Defense Professional

Primary emphasis:

Monitor • Detect • Analyze • Investigate • Respond • Recover

Professional objective:

Defend the Environment. Respond Effectively. Strengthen Cyber Resilience.

CCDM® — Advanced Management Level

Certified Cyber Defense Manager

Primary emphasis:

Assess • Strategize • Govern • Prioritize • Direct • Measure • Transform

Leadership objective:

Govern Enterprise Defense. Lead Cyber Crises. Build Resilience. Protect Enterprise Value.

Below is a more comprehensive, polished, and marketable FAQ section for the CCDM® webpage, with stronger emphasis on management, executive decision-making, incident leadership, and enterprise resilience.

CCDM®

CCDM® Leadership Value

CCDM® develops the ability to connect:

  • Threats
  • Exposure
  • Detection
  • Incident Decisions
  • Business Impact
  • Recovery
  • Resilience
  • Executive Action

The certification moves professionals from managing individual defensive activities toward governing cyber defense as an integrated enterprise capability.

CCDM®

CCDM® Leadership Objective

  • Anticipate Threats
  • Govern Defense
  • Lead Cyber Crises
  • Restore Critical Operations
  • Strengthen Resilience
  • Protect Enterprise Value

CCDM® — Lead the Defense. Direct the Response. Strengthen the Enterprise.

CCDM®

Cyber Defense Is More Than a Technology Function · Threat Intelligence + Detection + Exposure Management + Incident Leadership + Recovery + Resilience + People + Investment + Executive Decisions

Cyber Defense Is More Than a Technology Function

The strongest cyber-defense organizations connect:

Threat Intelligence + Detection + Exposure Management + Incident Leadership + Recovery + Resilience + People + Investment + Executive Decisions

CCDM® develops managers capable of bringing those capabilities together.

CCDM®

Ready to Lead Enterprise Cyber Defense?

APPLY FOR CCDM® CERTIFICATION

Advance your professional journey into enterprise cyber-defense leadership.

APPLY NOW →

REGISTER FOR THE CCDM® EXAM

Ready to demonstrate advanced management competency?

REGISTER FOR THE EXAM →

ENROLL IN ADVANCED CCDM® TRAINING

Develop advanced competency across strategy, operations, incident leadership, recovery, resilience, investment, and executive decision-making.

ENROLL NOW →

CHOOSE THE ENTERPRISE MANAGEMENT CAPSTONE

Demonstrate advanced competency through an instructor-led enterprise cyber-defense management project.

EXPLORE THE CAPSTONE →

DOWNLOAD THE CCDM® CERTIFICATION GUIDE

Review eligibility, competencies, Body of Knowledge, assessment pathways, standards alignment, and certification requirements.

DOWNLOAD PROGRAM GUIDE →

CCDM®

Who Should Earn CCDM®?

CCDM® is designed for experienced professionals and current or aspiring leaders such as:

  • Cyber Defense Manager
  • SOC Manager
  • Security Operations Manager
  • Cybersecurity Manager
  • Incident Response Manager
  • Cyber Incident Manager
  • Cyber Crisis Manager
  • Threat Management Leader
  • Vulnerability Management Leader
  • Exposure Management Manager
  • Cyber Resilience Manager
  • Security Engineering Manager
  • Director of Security Operations
  • Director of Cyber Defense
  • Deputy CISO
  • Cybersecurity Program Manager
  • Technology Risk Manager
  • Security Consultant
  • Cybersecurity Leader
CCDM®

CCDM® Body of Knowledge

Module 6 — Cyber Defense Investment, Technology & Performance

Module 8 — Workforce, Executive Communication & Transformation

  • Module 1 — Enterprise Cyber Defense Strategy & Governance
  • Module 2 — SOC, Detection & Security Operations Leadership
  • Module 3 — Threat, Vulnerability & Exposure Governance
  • Module 4 — Incident Response & Cyber Crisis Management
  • Module 5 — Recovery, Continuity & Cyber Resilience
  • Module 7 — AI-Enabled Defense & Emerging Cyber Risk
Learning outcomes

CCDM® Course Learning Outcomes

Upon successful completion, participants will be able to:

1. Develop Enterprise Cyber Defense Strategy and Governance

Assess defensive maturity, establish strategic priorities, design operating models, develop roadmaps, and align cyber defense with enterprise risk.

2. Lead SOC, Detection and Security Operations

Govern monitoring, detection, intelligence, automation, escalation, staffing, sourcing, and operational performance.

3. Govern Threat, Vulnerability and Exposure Management

Prioritize exposures using threat intelligence, exploitability, asset criticality, business impact, and risk.

4. Direct Incident Response and Cyber Crisis Management

Establish command structures, escalation criteria, severity models, containment priorities, executive decision processes, and crisis communication.

5. Lead Recovery, Continuity and Cyber Resilience

Integrate technical recovery with business continuity, disaster recovery, critical-service restoration, exercises, and resilience improvement.

6. Manage Cyber Defense Investment, Technology and Performance

Develop business cases, evaluate technologies, manage vendors, prioritize resources, and measure effectiveness through KPIs and KRIs.

7. Govern AI-Enabled Defense and Emerging Cyber Risk

Evaluate AI-assisted defense, automation, AI-enabled attacks, cloud, OT, IoT, supply-chain, and emerging risks.

8. Lead Workforce, Executive Communication and Transformation

Build cyber-defense teams, develop capabilities, communicate with executives and boards, and lead organizational transformation.

What is assessed

CCDM® Skills & Competencies Tested

CCDM® assesses management competency—not merely knowledge recall.

Candidates demonstrate the ability to:

CCDM®

The CCDM® Enterprise Cyber Defense Competency Model

CCDM® is organized around eight integrated management dimensions.

1. Enterprise Cyber Defense Strategy and Governance

Develop the ability to assess defensive maturity, identify capability gaps, establish strategic priorities, define governance structures, develop operating models, and align cyber defense with enterprise objectives.

Managers evaluate:

  • Current defensive maturity
  • Critical capabilities
  • Threat environment
  • Risk priorities
  • Governance structures
  • Decision authority
  • Operating models
  • Strategic roadmaps
  • Resource requirements
  • Target-state capabilities

Management Objective

Align cyber-defense capabilities with enterprise risk, business priorities, and organizational resilience objectives.

2. SOC, Detection, and Security Operations Leadership

The effectiveness of cyber defense depends heavily on the organization’s ability to achieve meaningful visibility and detection.

CCDM® addresses management of:

Managers must determine whether security operations are producing useful defensive outcomes.

The central question becomes:

  • SOC strategy
  • Internal, outsourced, and hybrid SOC models
  • Monitoring coverage
  • Detection engineering
  • SIEM
  • SOAR
  • EDR/XDR
  • Network monitoring
  • Threat intelligence
  • Threat hunting
  • Alert triage
  • Escalation
  • Automation
  • Staffing
  • Service levels
  • SOC performance
CCDM®

CCDM® Enterprise Cyber Defense Competency Model

01 — Enterprise Cyber Defense Strategy & Governance

Assess maturity, establish priorities, design operating models, define accountability, develop roadmaps, and align defensive capabilities with enterprise objectives.

02 — SOC, Detection & Security Operations Leadership

Govern SOC strategy, monitoring, detection engineering, intelligence, automation, escalation, sourcing, staffing, and performance.

03 — Threat, Vulnerability & Exposure Governance

Prioritize enterprise exposures using threat intelligence, exploitability, asset criticality, business impact, attack paths, and risk.

04 — Incident Response & Cyber Crisis Leadership

Establish command structures, severity models, escalation criteria, containment authority, executive decision processes, and crisis communication.

05 — Recovery, Continuity & Cyber Resilience

Integrate technical recovery with business continuity, disaster recovery, critical-service restoration, exercises, lessons learned, and resilience improvement.

06 — Cyber Defense Investment, Technology & Performance

Develop business cases, evaluate defensive technologies, manage service providers, allocate resources, and measure effectiveness.

07 — AI-Enabled Defense & Emerging Cyber Risk

Govern AI-assisted detection, automation, AI-enabled attacks, cloud, OT, IoT, software supply chains, and emerging defensive technologies.

08 — Workforce, Executive Communication & Transformation

Build teams, develop capabilities, communicate readiness and risk to executives and boards, and lead enterprise transformation.

CCDM®

What Is CCDM®?

The Certified Cyber Defense Manager (CCDM®) is an advanced professional certification that validates the managerial and leadership competencies required to govern cyber defense as an integrated enterprise capability.

CCDM® focuses on the progression from:

Threat Awareness → Defensive Strategy → Governance → Incident Leadership → Recovery → Resilience → Enterprise Value

The certification prepares managers to lead capabilities involving:

  • Cyber-defense strategy
  • Defensive maturity assessment
  • Security operations
  • SOC governance
  • Threat detection
  • Threat intelligence
  • Threat hunting
  • Vulnerability management
  • Exposure management
  • Incident response
  • Cyber crisis management
  • Digital-forensics oversight
  • Recovery
  • Business continuity
  • Disaster recovery
  • Cyber resilience
  • Security technologies
  • Managed security providers
  • Cyber-defense investment
  • Performance measurement
  • AI-enabled defense
  • Workforce leadership
  • Executive communication
  • Organizational transformation
Cyber Defense

Standards & International Framework Alignment

CCDM® incorporates principles relevant to:

ISO/IEC 27001 • ISO/IEC 27002 • ISO/IEC 27005 • ISO/IEC 27701 • ISO 22301 • ISO 31000 • ISO/IEC 42001 • ISO/IEC 23894 • NIST CSF • NIST NICE • NIST AI RMF • Relevant NIST Incident-Response Guidance • CISA Guidance

NIST’s current enterprise guidance reinforces the connection between cybersecurity risk, enterprise risk management, senior leadership, and workforce planning—an important foundation for the management-level orientation of CCDM®.

  • CCDM® Framework Application Progression
CCDM®

CCDM® Leadership Progression

The complete CCDM® management lifecycle is:

  • Assess → Strategize → Govern → Prioritize → Direct → Recover → Measure → Communicate → Transform

Assess

Understand threats, exposure, defensive maturity, and organizational readiness.

Strategize

Establish priorities, operating models, capabilities, and roadmaps.

Govern

Define accountability, policies, decision rights, escalation, and oversight.

Prioritize

Direct resources toward the threats, vulnerabilities, incidents, and capabilities that matter most.

Direct

Lead SOC operations, major incidents, containment decisions, and cyber crises.

Recover

Restore critical operations securely and validate recovery.

Measure

Evaluate defensive performance, risk reduction, and resilience.

Communicate

Translate technical conditions into executive and board-level decisions.

Transform

Use lessons learned, emerging technologies, and performance insights to strengthen enterprise capability.

CCDM®

CCDP® vs. CCDM® — Choose Your Path

AreaCCDP® ProfessionalCCDM® Advanced Manager
Primary Focus Cyber-defense execution Enterprise cyber-defense leadership
SOC Monitor and analyze Strategize and govern
Threat Intelligence Analyze and apply Govern and prioritize
Vulnerabilities Identify and assess Prioritize enterprise exposure
Incidents Triage and respond Direct and govern
Cyber Crisis Support response Lead executive response
Forensics Preserve and analyze Govern investigations
Recovery Support restoration Direct enterprise recovery
Resilience Apply practices Establish strategy
Technology Use and interpret Evaluate and govern
Metrics Operational measures KPIs, KRIs and executive measures
AI Defense Apply and evaluate Govern and invest
Workforce Professional contribution Team and capability leadership
Communication Technical reporting Executive and board reporting
Objective Defend the Environment Govern Defense & Resilience
CCDM®

One Cyber Defense Career Pathway

Start with CCDP®

Build the professional capability to:

Monitor → Detect → Analyze → Investigate → Respond → Recover

Advance to CCDM®

Develop the leadership capability to:

Assess → Strategize → Govern → Prioritize → Lead → Measure → Transform

CCDM®

CCDP® vs. CCDM® at a Glance

AreaCCDP®CCDM®
Level Professional Advanced / Management
Primary Focus Perform cyber defense Govern cyber defense
SOC Monitor and analyze Lead and measure
Threat Intelligence Analyze and apply Govern and prioritize
Vulnerabilities Identify and assess Prioritize exposure
Incident Response Triage and respond Direct and govern
Cyber Crisis Support Lead
Forensics Preserve and analyze Govern investigation
Recovery Support restoration Direct recovery
Resilience Apply practices Establish strategy
Technology Use and interpret Evaluate and govern
Metrics Operational Executive KPIs/KRIs
AI Defense Apply and evaluate Govern and invest
Workforce Professional contribution Team leadership
Communication Technical Executive and board
Objective Defend the Environment Govern Defense and Resilience
CCDM®

The IBACTP® Cyber Defense Pathway

CCDP® — Defend the Environment

Monitor → Detect → Analyze → Investigate → Respond → Recover

CCDM® — Govern the Defense

Assess → Strategize → Govern → Prioritize → Lead → Measure → Transform

CCDM®

IBACTP® Cyber Defense Pathway

CCDM®

Why CCDM®?

Cyber Defense Is Now an Enterprise Leadership Responsibility

A significant cybersecurity incident rarely remains a technical problem.

A compromised endpoint can become an identity compromise.

An identity compromise can become lateral movement.

Lateral movement can affect cloud systems, applications, data, operational environments, or critical services.

A major cyber incident can quickly create:

For this reason, modern cyber-defense leadership requires much more than understanding security technologies.

Managers must determine:

CCDM® is designed around these management decisions.

  • Operational disruption
  • Financial loss
  • Regulatory exposure
  • Legal obligations
  • Customer impact
  • Third-party dependencies
  • Reputational consequences
  • Executive decisions
  • Board-level concerns
  • Which threats create the greatest enterprise risk?
  • Can the organization detect those threats early enough?
  • Does the SOC have sufficient visibility?
  • Are alerts producing meaningful defensive outcomes?
  • Which vulnerabilities or exposures require immediate action?
  • When does a technical event become a significant incident?
  • When does an incident become an enterprise crisis?
  • Who has authority to make containment decisions?
  • Which services must be restored first?
  • How resilient is the organization if defensive controls fail?
  • Which cyber-defense capabilities require additional investment?
  • Are security technologies delivering measurable value?
  • Are external providers and managed security services effective?
  • Are teams adequately staffed and skilled?
  • How should AI-assisted defense be governed?
  • What should executives and boards know about defensive readiness?
CCDM®

From Security Operations to Enterprise Decision-Making

A cyber-defense professional may ask:

“What does this alert indicate?”

A cyber-defense manager must also ask:

“Does this threat matter to the enterprise, what decision is required, who needs to act, and what business consequence are we trying to avoid?”

CCDM® develops this broader management perspective.

The certification prepares leaders to connect:

CCDM®

CCDM® Integrated Leadership Framework

CCDM® integrates twelve critical areas of modern cyber-defense management:

Cyber Defense Strategy

Establish enterprise defensive priorities, target capabilities, operating models, and roadmaps.

SOC Leadership

Govern monitoring, detection, investigation, escalation, automation, staffing, sourcing, and performance.

Threat Management

Use threat intelligence and adversary information to guide defensive priorities.

Exposure Governance

Prioritize vulnerabilities and attack surfaces according to exploitability, asset criticality, threat activity, and business impact.

Incident Leadership

Establish severity models, escalation, decision authority, containment priorities, and response governance.

Cyber Crisis Management

Coordinate executives, legal, communications, technology, business leaders, and external stakeholders during major cyber events.

Recovery

Direct secure restoration of systems and critical services.

Cyber Resilience

Ensure the organization can withstand disruption, recover effectively, learn from incidents, and strengthen future readiness.

Technology Investment

Evaluate security capabilities based on risk reduction, integration, cost, scalability, performance, and value.

Performance Measurement

Use KPIs, KRIs, maturity indicators, readiness measures, and executive reporting to evaluate effectiveness.

AI-Enabled Defense

Govern AI-assisted detection, automation, intelligence, investigation, and emerging AI-related cyber risks.

Workforce & Executive Leadership

Develop teams, strengthen security culture, communicate risk, and translate technical conditions into executive decisions.

CCDM®

“Are we detecting the threats that matter—and can we respond fast enough when we find them?”

3. Threat, Vulnerability, and Exposure Governance

CCDM® moves managers beyond traditional vulnerability-count reporting.

Managers develop competency in prioritizing exposure using:

Threat Activity + Exploitability + Exposure + Asset Criticality + Business Impact + Existing Controls

Relevant management areas include:

The objective is to direct resources toward the weaknesses most likely to create material organizational risk.

  • Threat intelligence
  • Vulnerability management
  • Attack-surface management
  • External exposure
  • Asset criticality
  • Exploitability
  • Remediation priorities
  • Compensating controls
  • Risk acceptance
  • Exposure trends

4. Incident Response and Cyber Crisis Leadership

CCDM® places major emphasis on incident leadership.

Managers must understand how to move from operational incident response into enterprise crisis decision-making.

Relevant competencies include:

  • Incident governance
  • Severity models
  • Escalation thresholds
  • Incident command
  • Decision authority
  • Containment priorities
  • Investigation coordination
  • Digital-forensics oversight
  • Internal communications
  • Executive escalation
  • External communication
  • Regulatory coordination
  • Crisis leadership
  • Recovery decisions

Incident Leadership Progression

Event → Incident → Major Incident → Enterprise Crisis

CCDM® prepares managers to recognize when this escalation should occur and what leadership structures are required at each stage.

CCDM®

When Does a Cyber Incident Become a Business Crisis?

This is one of the defining questions addressed by CCDM®.

An incident may require enterprise crisis management when it materially affects:

At this point, cyber defense must connect with broader organizational leadership.

The manager’s role shifts from:

  • Critical business services
  • Customer operations
  • Financial systems
  • Sensitive data
  • Regulatory obligations
  • Safety
  • Supply chains
  • Third parties
  • Business continuity
  • Reputation
  • Executive accountability

“How do we contain the attack?”

to:

CCDM®

“How do we protect the enterprise while technical response continues?”

5. Recovery, Continuity, and Cyber Resilience

Containment is not the end of a major cyber incident.

Organizations must restore operations without reintroducing the attacker, spreading compromise, or creating unnecessary business risk.

CCDM® develops management competency involving:

The management objective is not simply:

  • Recovery priorities
  • Critical-service dependencies
  • Backup and restoration
  • Disaster recovery
  • Business continuity
  • Recovery objectives
  • System validation
  • Credential recovery
  • Restoration sequencing
  • Post-recovery monitoring
  • Recovery exercises
  • Lessons learned
  • Resilience improvement

Restore as Fast as Possible

It is:

Restore the Right Services, in the Right Order, with Confidence That the Environment Is Secure.

CCDM®

Cyber Resilience as a Management Capability

CCDM® treats cyber resilience as a defining enterprise capability.

Resilience means being prepared to:

  • CCDM® Technology Management Progression

Anticipate → Withstand → Respond → Recover → Adapt

A resilient organization does not assume that every attack will be prevented.

Instead, it develops the capability to:

The ultimate goal is to reduce both the likelihood and business impact of major cyber disruption.

  • Maintain critical services during disruption
  • Limit the blast radius of incidents
  • Make timely decisions
  • Recover priority operations
  • Validate restored environments
  • Learn from incidents
  • Improve controls
  • Strengthen future response capability

6. Cyber Defense Technology, Investment, and Performance

Cyber-defense leaders must determine not only which technologies are available, but which capabilities actually deserve investment.

CCDM® addresses management of technologies such as:

SIEM • SOAR • EDR/XDR • Threat Intelligence • IDS/IPS • Network Detection • Vulnerability Management • Exposure Management • Cloud Security • Identity Security • Digital Forensics • Incident Management • Backup & Recovery • AI-Assisted Security

Managers evaluate technology based on:

  • Capability
  • Risk reduction
  • Integration
  • Coverage
  • Reliability
  • Scalability
  • Cost
  • Vendor support
  • Operational burden
  • Skills requirements
  • Security
  • Resilience
  • Performance
  • Business value
CCDM®

Measuring Cyber Defense

Cyber-defense management requires meaningful measurement.

CCDM® addresses performance indicators such as:

Detection

  • Monitoring coverage
  • Detection gaps
  • Detection quality
  • Alert accuracy
  • Detection trends

Response

  • Incident volume
  • Escalation performance
  • Containment performance
  • Investigation duration
  • Response consistency

Exposure

  • Critical vulnerabilities
  • Exploitable exposures
  • Remediation trends
  • Attack-surface changes
  • Risk concentration

Recovery

  • Restoration performance
  • Recovery readiness
  • Backup validation
  • Critical-service recovery
  • Exercise results

Resilience

CCDM® emphasizes the difference between measuring security activity and measuring defensive effectiveness.

  • Readiness gaps
  • Control improvements
  • Repeat incidents
  • Maturity trends
  • Corrective-action completion

7. AI-Enabled Defense and Emerging Cyber Risk

Artificial intelligence is transforming both defensive capability and adversary behavior.

CCDM® prepares managers to evaluate:

AI-Assisted Defense

  • Automated alert triage
  • Behavioral analytics
  • Threat detection
  • Threat-intelligence enrichment
  • Threat hunting
  • Exposure prioritization
  • Incident investigation
  • Response automation

AI-Enabled Threats

  • AI-assisted social engineering
  • Automated attack activity
  • Adversarial AI
  • Deepfake-enabled deception
  • AI-assisted malware development
  • GenAI-related information exposure

AI Governance Considerations

  • Reliability
  • False positives and false negatives
  • Human oversight
  • Data exposure
  • Explainability
  • Model risk
  • Vendor dependence
  • Accountability
  • Validation

CCDM® AI Defense Principle

Automate Where Appropriate → Validate Performance → Maintain Human Authority → Govern the Risk

CCDM® also addresses emerging defensive considerations involving:

Cloud-Native Systems • APIs • Containers • IoT • OT • DevSecOps • Software Supply Chains • Automation • Emerging Attack Techniques

8. Workforce Leadership, Executive Communication, and Transformation

Technology alone cannot create effective cyber defense.

CCDM® prepares managers to build and lead the human capability behind enterprise defense.

Relevant areas include:

  • Workforce strategy
  • Organizational structure
  • SOC staffing
  • Skills assessments
  • Capability development
  • Training
  • Professional certifications
  • Cross-functional collaboration
  • Succession planning
  • Managed services
  • External specialists
  • Leadership development
  • Security culture
  • Transformation
CCDM®

Executive and Board Communication

One of the most important CCDM® competencies is the ability to translate cyber-defense information into business decision language.

Executives generally do not need a list of thousands of alerts.

They need answers to questions such as:

CCDM® develops the communication progression:

  • What is the risk?
  • What happened?
  • What is affected?
  • How confident are we?
  • Is the threat contained?
  • What business operations are at risk?
  • What must leadership decide?
  • What resources are required?
  • When can operations safely resume?
  • Could this happen again?
  • What must change?
CCDM®

What Makes CCDM® Different?

CCDM® is designed around five critical leadership transitions.

From Technology to Capability

The question is not merely:

“Which tools do we own?”

It becomes:

“What defensive capabilities do those technologies actually provide?”

From Vulnerabilities to Exposure

The question is not:

“How many vulnerabilities exist?”

It becomes:

“Which exposures could materially affect the enterprise?”

From Alerts to Readiness

The question is not:

“How many alerts did the SOC process?”

It becomes:

“Can we reliably detect and respond to the threats that matter?”

From Incident Response to Crisis Leadership

The question is not:

“Did we follow the incident playbook?”

It becomes:

“Did leadership make the right decisions quickly enough to protect critical operations?”

From Recovery to Resilience

The question is not:

“Did the systems come back online?”

It becomes:

“Did we restore operations securely—and are we better prepared for the next incident?”

CCDM®

CCDM® Management Questions

Throughout the program, candidates learn to address realistic management questions such as:

  • Which cyber-defense capabilities are most critical?
  • How should defensive maturity be assessed?
  • Is SOC coverage sufficient?
  • Which detection gaps create the greatest risk?
  • How should threat intelligence influence investment?
  • Which vulnerabilities require immediate remediation?
  • When should risk be accepted?
  • When should an incident escalate?
  • Who should authorize containment?
  • How should an enterprise cyber crisis be managed?
  • What operations should recover first?
  • Are backup and restoration capabilities trustworthy?
  • What does cyber resilience actually mean for the organization?
  • Which technologies should be replaced or consolidated?
  • Should security operations be internal, outsourced, or hybrid?
  • Are vendors meeting expectations?
  • Which KPIs and KRIs matter?
  • How should AI-assisted defense be governed?
  • Does the organization have the right workforce?
  • What should the board know?
CCDM®

CCDM® Is About Leadership, Not Tool Operation

CCDM® does not require managers to personally operate every SIEM, EDR/XDR platform, vulnerability scanner, cloud-security platform, or forensic technology.

Instead, managers must understand enough to determine:

  • What capability is needed
  • What the technology provides
  • Whether it integrates effectively
  • Whether the output is trustworthy
  • Whether the organization has sufficient skills
  • Whether the cost is justified
  • Whether risk is reduced
  • Whether performance can be measured
  • Whether the capability supports resilience
  • Understand the Capability → Govern the Technology → Measure the Outcome → Protect the Enterprise
CCDM®

CCDM® Leadership Objective

The central management objective of the Certified Cyber Defense Manager is:

CCDM®
  • Anticipate Threats
  • Govern Defense
  • Lead Response
  • Restore Operations
  • Strengthen Resilience
  • Protect Enterprise Value

CCDM® prepares professionals to transform cyber defense from a collection of security tools and operational activities into a:

  • Strategic • Governed • Integrated • Measurable • Resilient Enterprise Capability
CCDM®

The CCDM® Leadership Promise

A successful CCDM® professional understands that cyber defense is ultimately about more than protecting technology.

It is about protecting the organization’s ability to operate, serve customers, manage risk, recover from disruption, and continue creating value in the face of cyber threats.

Govern the Defense. Lead the Response. Restore the Enterprise. Build Resilience. Protect Value.

  • Threat Activity → Technical Exposure → Business Impact → Enterprise Risk → Leadership Decision → Recovery Priority

Cyber Defense Is a Business Leadership Responsibility

A major cyber incident rarely remains confined to the Security Operations Center.

What begins as a technical event can rapidly evolve into an enterprise-wide business disruption affecting operations, finances, customers, regulatory obligations, third parties, reputation, and executive decision-making.

A ransomware infection may disrupt critical services. A compromised identity may expose sensitive information. A cloud breach may interrupt customer-facing platforms. A supply-chain compromise may affect business partners. A destructive attack may require disaster recovery, legal coordination, executive communication, and board oversight.

Cyber incidents can therefore become:

An Operational Problem • A Financial Problem • A Legal and Regulatory Problem • A Customer Problem • A Supply-Chain Problem • A Reputational Problem • An Executive and Board-Level Problem

This changes the role of cyber-defense leadership.

Organizations need leaders who can connect what is happening inside the technical environment with what it means for the enterprise.

The cyber-defense manager must be capable of translating:

From Technical Response to Enterprise Leadership

Security analysts may determine what happened technically.

Cyber-defense managers must determine what the organization should do about it.

This requires leaders to answer broader questions such as:

These are no longer purely technical questions.

They are enterprise leadership decisions informed by cyber-defense evidence.

  • How serious is the incident?
  • Which critical business services are affected?
  • Is the threat contained?
  • What additional systems or identities may be at risk?
  • Should business operations be interrupted to contain the threat?
  • Who has authority to make that decision?
  • When should executive leadership become involved?
  • Does the incident require legal, privacy, regulatory, or communications escalation?
  • Which services must be restored first?
  • What is the financial and operational impact of continued disruption?
  • What risk remains after containment?
  • Are recovery systems and backups trustworthy?
  • What should customers, partners, regulators, or other stakeholders be told?
  • What decisions must executives make immediately?
  • What should the board understand about the organization’s exposure and resilience?
  • What controls, technologies, processes, or investments must change after the incident?
CCDM®

Cyber Defense Must Connect to Enterprise Risk

Effective cyber-defense leadership requires understanding that security risk does not exist independently of organizational risk.

A technical vulnerability becomes important because of what it could enable.

A security incident becomes material because of what it could disrupt.

A defensive capability becomes valuable because of the business consequences it can prevent, reduce, or help the organization recover from.

Cyber-defense managers must therefore connect:

Assets → Threats → Vulnerabilities → Exposure → Business Services → Enterprise Risk

For example:

Technical Perspective

Critical vulnerability identified on an internet-facing system

Cyber-Defense Perspective

Active exploitation is possible and existing controls may not sufficiently reduce exposure

Enterprise Perspective

Compromise could disrupt a critical customer service and expose regulated information

Leadership Decision

Immediate remediation, compensating controls, enhanced monitoring, executive visibility, and contingency planning are required

CCDM® develops this ability to move from technical information to enterprise action.

CCDM®

When Does an Incident Become a Cyber Crisis?

Not every security incident requires executive or board involvement.

A defining responsibility of cyber-defense leadership is understanding when escalation is necessary.

An incident may become an enterprise cyber crisis when it begins to materially affect areas such as:

At this point, incident response must expand beyond the security organization.

The management progression becomes:

  • Critical business operations
  • Revenue-generating services
  • Customer services
  • Sensitive or regulated information
  • Financial systems
  • Safety-related systems
  • Critical infrastructure
  • Business continuity
  • Supply chains
  • Key third parties
  • Regulatory obligations
  • Litigation exposure
  • Reputation
  • Public confidence
CCDM®
  • Security Event
  • Confirmed Incident
  • Major Incident
  • Enterprise Cyber Crisis

As severity increases, leadership requirements expand from technical containment toward enterprise coordination, risk acceptance, business continuity, communications, legal decisions, recovery prioritization, and executive governance.

CCDM®

Cyber-Defense Leaders Must Bridge Two Worlds

CCDM® prepares managers to operate between the technical and executive environments.

  • CCDM® Executive Translation Model

The Technical Environment

Cyber-defense teams work with:

SIEM • SOAR • EDR/XDR • Network Telemetry • Threat Intelligence • Vulnerability Data • Cloud Logs • Identity Events • Forensic Evidence • Incident Information

These technologies provide evidence.

But evidence alone does not make an enterprise decision.

The Executive Environment

Executives and boards need to understand:

The cyber-defense manager must bridge these environments.

  • What happened?
  • What is affected?
  • How serious is it?
  • What is the potential business impact?
  • Is the situation contained?
  • What remains uncertain?
  • Which decisions are required?
  • What resources are needed?
  • What risks are being accepted?
  • When can critical operations safely resume?
  • Could the organization experience the same event again?
  • What must change?
CCDM®

Governance Changes the Cyber-Defense Conversation

The question is no longer simply:

“Did our security technology detect the attack?”

Management must also ask:

“Did our governance model enable the organization to respond effectively?”

That includes questions such as:

Cyber-defense effectiveness therefore depends on:

  • Were responsibilities clear?
  • Was escalation timely?
  • Did the right individuals have decision authority?
  • Was containment delayed because approval was unclear?
  • Were legal and privacy teams engaged appropriately?
  • Were business leaders prepared?
  • Were communications coordinated?
  • Could critical operations continue?
  • Was recovery tested?
  • Were executive decisions supported by reliable information?
CCDM®

Cyber Resilience Is the Business Outcome

Organizations cannot reasonably expect to prevent every cyberattack.

The stronger objective is to ensure that the enterprise can:

  • Anticipate
  • Withstand
  • Respond
  • Recover
  • Adapt

This is cyber resilience.

Cyber-defense leadership must ensure that the organization can continue operating—or restore critical operations rapidly—when preventive controls fail.

That requires coordination across:

The cyber-defense manager therefore becomes a critical link between security operations and organizational resilience.

  • Cybersecurity
  • Information Technology
  • Business continuity
  • Disaster recovery
  • Risk management
  • Legal
  • Privacy
  • Compliance
  • Communications
  • Business leadership
  • Executive management
CCDM®

From Security Metrics to Business Decisions

Cyber-defense leaders must also move reporting beyond technical activity measures.

Traditional reports may focus on:

Alerts • Vulnerabilities • Incidents • Tickets • Patches

These metrics may be useful operationally, but senior leaders need additional context.

Executive-level reporting should help answer:

The management progression becomes:

  • Are our most important services adequately protected?
  • Are we detecting the threats most likely to affect us?
  • Is enterprise exposure increasing or decreasing?
  • Can we contain major incidents quickly?
  • Can critical services recover within acceptable timeframes?
  • Are investments reducing meaningful risk?
  • Are our defensive capabilities improving?
  • Where are the most significant readiness gaps?
  • Security Activity → Defensive Performance → Enterprise Risk → Executive Decision
CCDM®

NIST and Enterprise Cyber-Risk Leadership

The broader direction of the NIST Cybersecurity Framework 2.0 reinforces the importance of governance and organizational leadership in cybersecurity risk management.

The framework places Govern alongside Identify, Protect, Detect, Respond, and Recover, emphasizing that cybersecurity risk management is connected to organizational strategy, roles, responsibilities, policies, oversight, and enterprise risk.

For CCDM®, this reinforces a central leadership principle:

  • Cyber Defense Must Be Governed as an Enterprise Risk and Resilience Capability—not managed only as a technical security function.
CCDM®

The CCDM® Leadership Environment

CCDM® is designed for this expanded leadership responsibility.

The certification develops professionals capable of connecting:

Threat Intelligence

What threats should concern the organization?

Exposure

Where is the organization most vulnerable?

Detection

Can those threats be identified quickly?

Incident Leadership

Can the organization make the right decisions under pressure?

Recovery

Can critical services be restored securely?

Resilience

Can the enterprise continue operating and become stronger after disruption?

Executive Governance

Can leadership understand the risk and make informed decisions?

CCDM®

CCDM® Leadership Principle

A cyber-defense manager is not simply responsible for whether security controls are operating.

The manager is responsible for helping answer a much larger question:

CCDM®

“Is the enterprise prepared to withstand, respond to, recover from, and learn from a major cyber incident?”

That is the leadership environment the Certified Cyber Defense Manager (CCDM®) is designed to address.

  • Govern the Defense. Lead the Response. Restore Critical Operations. Build Enterprise Resilience.
CCDM®

From Technical Defense to Enterprise Leadership

CCDM® develops competency across six management transitions:

From Alerts → To Readiness

Managers must determine whether the organization can detect material threats—not simply whether security tools produce alerts.

From Vulnerabilities → To Enterprise Exposure

Managers must determine which weaknesses create material business risk.

From Incidents → To Crisis Leadership

Managers must know when technical response requires executive command and business-level decisions.

From Recovery → To Resilience

Restoring systems is not enough. Organizations must maintain critical operations and become stronger after incidents.

From Tools → To Investment

Managers must evaluate capability, cost, integration, risk, performance, and value.

From Security Reporting → To Executive Decision Support

Senior leaders need business-relevant information, not technical dashboards without context.

CCDM®

Tools, Technologies & Enterprise Security Environments

CCDM® managers are not expected to operate every security product.

They are expected to evaluate and govern technology capabilities.

SIEM • SOAR • EDR/XDR • Threat Intelligence • Security Analytics • Monitoring

IAM • MFA • SSO • PAM • Federation • Identity Governance

Firewalls • IDS/IPS • Segmentation • Secure Access • Zero Trust • Network Detection

Scanners • Asset Discovery • Attack-Surface Management • Exposure Management • Configuration Management

Cloud Security • CSPM Concepts • API Security • Application Security • DevSecOps • Container Security

Incident Management • Forensic Technologies • Backup & Recovery • Continuity • Crisis Management

AI-Assisted Detection • Automated Triage • Security Automation • AI Analytics • Intelligent Response

  • Security Operations
  • Identity
  • Network & Infrastructure
  • Vulnerability & Exposure
  • Cloud & Applications
  • Incident & Resilience
  • AI-Enabled Defense
  • CCDM® Technology Leadership Model
CCDM®

Flexible CCDM® Assessment

Option 1 — CCDM® Certification Examination

100 Questions

90 Minutes

Advanced Multiple-Choice + Scenario-Based Questions

Closed Book

Secure Online Proctoring or Approved Testing Center

Recommended Passing Score: 70%

Assessment emphasis:

Strategy • Governance • Threat Judgment • Incident Decisions • Crisis Leadership • Recovery • Resilience • Investment • Executive Judgment

Option 2 — Enterprise Cyber Defense Management Capstone

Eligible instructor-led candidates may demonstrate advanced competency through the structured Enterprise Cyber Defense Management Capstone.

Candidates address realistic management scenarios requiring integration of:

CCDM®
  • Understand
  • Interpret
  • Assess
  • Prioritize
  • Govern
  • Measure
  • Improve

Alignment does not constitute external accreditation or endorsement.

CCDM®

Credentialing Quality Alignment

The CCDP® and CCDM® certification frameworks may incorporate credentialing-quality principles associated with:

ISO/IEC 17024 • ANAB • NCCA • I.C.E. • International Personnel-Certification Practices

Program quality areas include:

Job Task Analysis • Defined Competencies • Eligibility • Body of Knowledge • Examination Blueprint • SME Review • Psychometric Principles • Examination Security • Identity Verification • Impartial Decisions • Appeals • Ethics • Continuing Education • Recertification • Credential Verification • Periodic Review • Continuous Improvement

Any such alignment should be described as alignment only. It does not constitute formal accreditation, recognition, approval, or endorsement unless officially awarded by the applicable independent organization.

CCDM®
  • CCDP®
  • CCDM®
  • From Cyber Defense Practice to Enterprise Cyber Defense Leadership

What is CCDP®?

The Certified Cyber Defense Professional (CCDP®) is a vendor-neutral professional certification designed to validate practical competency across the modern cyber-defense lifecycle.

CCDP® focuses on:

Security Monitoring • Threat Detection • SOC Operations • Threat Intelligence • Threat Hunting • Vulnerability Management • Exposure Management • Incident Response • Digital Forensics • Recovery • Cyber Resilience • AI-Enabled Defense

The certification is designed for professionals who must interpret security information, recognize threats, investigate suspicious activity, prioritize defensive actions, support containment and eradication, preserve relevant evidence, contribute to secure recovery, and strengthen organizational resilience.

CCDP® Professional Progression

Monitor → Detect → Analyze → Investigate → Respond → Recover → Improve

How is CCDP® different from CCDM®?

The primary difference is the level of responsibility and decision-making.

CCDP® focuses on performing cyber defense.

A CCDP® professional may:

  • Monitor security environments
  • Analyze alerts
  • Interpret telemetry
  • Apply threat intelligence
  • Investigate suspicious activity
  • Assess vulnerabilities
  • Support containment
  • Preserve evidence
  • Assist with recovery

CCDM® focuses on governing and leading cyber defense.

A CCDM® manager may:

  • Establish cyber-defense strategy
  • Govern SOC operations
  • Prioritize enterprise exposure
  • Establish incident decision authority
  • Lead major cyber incidents
  • Direct cyber crisis response
  • Prioritize recovery
  • Evaluate security investments
  • Measure defensive effectiveness
  • Communicate with executives and boards

Simple Comparison

CCDP® asks:

“What is happening, and what defensive action should we take?”

CCDM® asks:

“What does this mean for the enterprise, what should we prioritize, who must decide, and how should the organization respond?”

Do I need CCDP® before pursuing CCDM®?

CCDP® is the recommended professional progression into CCDM®.

The recommended pathway is:

CCDM®
  • CCDP®
  • CCDM®

However, CCDP® may not be the only qualifying route.

Equivalent professional experience, education, training, or other relevant qualifications in areas such as:

may satisfy applicable IBACTP® eligibility requirements.

Candidates should review the current eligibility requirements applicable to CCDM® before applying.

  • Cybersecurity
  • Cyber defense
  • SOC operations
  • Security operations
  • Incident response
  • Threat management
  • Vulnerability management
  • Cyber resilience
  • Technology risk
  • Security management
  • Cybersecurity leadership

Who should consider CCDP®?

CCDP® is particularly relevant for professionals working in or preparing for roles such as:

CCDP® is also suitable for IT professionals seeking to transition into cyber-defense or security-operations roles.

  • Cyber Defense Analyst
  • SOC Analyst
  • Security Operations Analyst
  • Cybersecurity Analyst
  • Threat Analyst
  • Threat Hunter
  • Incident Response Analyst
  • Cyber Incident Responder
  • Vulnerability Analyst
  • Exposure Management Analyst
  • Security Engineer
  • Cloud Security Analyst
  • Network Security Analyst
  • Digital Forensics Analyst
  • Cyber Resilience Analyst
  • Cybersecurity Consultant

Who should consider CCDM®?

CCDM® is intended for experienced practitioners, managers, and professionals preparing for leadership responsibilities such as:

CCDM® is particularly relevant for professionals who must translate technical cyber-defense information into business risk, investment priorities, recovery decisions, and executive recommendations.

  • Cyber Defense Manager
  • SOC Manager
  • Security Operations Manager
  • Cybersecurity Manager
  • Incident Response Manager
  • Cyber Incident Manager
  • Cyber Crisis Manager
  • Threat Management Leader
  • Vulnerability or Exposure Manager
  • Cyber Resilience Manager
  • Security Engineering Manager
  • Cybersecurity Program Manager
  • Director of Security Operations
  • Director of Cyber Defense
  • Technology Risk Manager
  • Deputy CISO
  • Senior Cybersecurity Consultant

Are CCDP® and CCDM® vendor-neutral?

Yes.

Both certifications are designed around transferable professional competencies rather than dependence on a particular vendor, security product, or technology ecosystem.

Programs may reference technologies such as:

SIEM • SOAR • EDR/XDR • IDS/IPS • Firewalls • Threat Intelligence • Vulnerability Management • Attack-Surface Management • Cloud Security • Digital Forensics • Incident Management • Backup & Recovery • AI-Assisted Security

However, certification competency is based on understanding:

Purpose → Application → Interpretation → Integration → Risk → Decision

rather than demonstrating proficiency with one commercial product.

Does CCDP® cover SOC operations?

Yes.

SOC operations are a major part of CCDP®.

Candidates develop competency in areas such as:

CCDP® focuses on understanding how security telemetry becomes an informed defensive decision.

  • Security monitoring
  • SIEM
  • EDR/XDR telemetry
  • Alert triage
  • Event correlation
  • Network monitoring
  • Threat intelligence
  • Detection
  • Escalation
  • Security analytics
  • Incident investigation

Does CCDM® cover SOC leadership?

Yes. SOC leadership is a core CCDM® management competency.

Managers evaluate:

The management question is not simply:

“How many alerts did the SOC process?”

It is:

  • SOC strategy
  • Operating models
  • Internal versus outsourced SOC structures
  • Monitoring coverage
  • Detection effectiveness
  • Threat-intelligence integration
  • Alert quality
  • Escalation models
  • Automation
  • Staffing
  • Skills
  • Service levels
  • Technology integration
  • Performance measurement
  • Continuous improvement
CCDM®

“Is the SOC detecting and responding to the threats that matter?”

Do the certifications cover threat intelligence?

Yes.

CCDP®

Candidates learn to apply threat intelligence to:

  • Indicators of compromise
  • Adversary behavior
  • Threat hunting
  • Security monitoring
  • Vulnerability prioritization
  • Incident investigation
  • Defensive analysis

CCDM®

Managers learn to use threat intelligence to guide:

The progression is:

CCDP® — Analyze and Apply Intelligence

CCDM® — Govern and Prioritize with Intelligence

  • Enterprise priorities
  • Defensive strategy
  • Exposure management
  • SOC direction
  • Investment decisions
  • Incident readiness
  • Executive risk awareness

Do CCDP® and CCDM® cover vulnerability and exposure management?

Yes.

Both certifications address vulnerability and exposure management, but at different levels.

CCDP®

Professionals evaluate:

  • Vulnerabilities
  • Exploitability
  • Asset criticality
  • Threat activity
  • Attack surfaces
  • Remediation priorities
  • Technical exposure

CCDM®

Managers govern:

CCDM® emphasizes moving from traditional severity-only thinking toward:

  • Enterprise exposure
  • Remediation priorities
  • Risk acceptance
  • Compensating controls
  • Resource allocation
  • Exposure trends
  • Executive escalation
  • Investment priorities
CCDM®

Threat Activity + Exploitability + Exposure + Asset Criticality + Business Impact

Do CCDP® and CCDM® cover incident response?

Yes. Incident response is one of the defining elements of the entire pathway.

CCDP® — Professional Incident Response

Candidates develop competency in:

  • Incident identification
  • Triage
  • Severity assessment
  • Escalation
  • Investigation
  • Containment
  • Eradication
  • Evidence preservation
  • Documentation
  • Recovery support
  • Lessons learned

CCDM® — Incident Leadership

Managers develop competency in:

  • Incident governance
  • Severity frameworks
  • Decision authority
  • Escalation models
  • Incident command
  • Containment decisions
  • Cross-functional coordination
  • Executive escalation
  • Crisis management
  • Recovery priorities
  • Executive communication

Progression

CCDP®: Detect → Investigate → Respond

CCDM®: Govern → Direct → Lead

Does CCDM® cover cyber crisis management?

Yes.

Cyber crisis management is a defining leadership component of CCDM®.

Candidates learn to evaluate when an operational cyber incident requires broader enterprise escalation.

This may occur when an incident materially affects:

CCDM® prepares managers to understand the progression:

  • Critical business operations
  • Sensitive data
  • Financial systems
  • Customer services
  • Regulatory requirements
  • Supply-chain operations
  • Third parties
  • Business continuity
  • Reputation
  • Executive accountability
CCDM®
  • Security Event
  • Incident
  • Major Incident
  • Enterprise Cyber Crisis

Do the certifications include digital forensics?

Yes, but at different levels.

CCDP®

Candidates learn relevant forensic concepts including:

  • Evidence identification
  • Evidence preservation
  • Chain of custody
  • Endpoint evidence
  • Network evidence
  • Logs
  • Cloud evidence
  • Timeline analysis
  • Artifact correlation
  • Investigation support

CCDM®

Managers focus on:

Candidates seeking deeper specialization specifically in digital forensics may also consider the IBACTP® CDFOP® → CDFOM® Digital Forensics pathway.

  • Forensic readiness
  • Investigation governance
  • Evidence-management oversight
  • Forensic escalation
  • External specialists
  • Investigation quality
  • Legal coordination
  • Findings and root-cause oversight

Does CCDP® cover recovery and cyber resilience?

Yes. Recovery and resilience are defining elements of CCDP®.

Candidates learn how to support:

The objective is not simply:

“Bring the system back online.”

It is:

  • Secure restoration
  • Recovery validation
  • Backup and recovery
  • Critical-service restoration
  • Business continuity
  • Disaster recovery
  • Post-recovery monitoring
  • Lessons learned
  • Control improvement
CCDM®

“Recover Securely and Strengthen Future Readiness.”

Does CCDM® cover enterprise cyber resilience?

Yes. Cyber resilience is a central management objective of CCDM®.

Managers learn to connect:

Incident Response + Business Continuity + Disaster Recovery + Critical-Service Restoration + Lessons Learned + Enterprise Risk

CCDM® treats resilience as the organization’s ability to:

CCDM®
  • Anticipate
  • Withstand
  • Respond
  • Recover
  • Adapt

Do CCDP® and CCDM® cover AI-enabled cyber defense?

Yes.

CCDP®

Candidates evaluate:

  • AI-assisted threat detection
  • Automated alert triage
  • Security analytics
  • AI-assisted threat hunting
  • AI-supported investigations
  • AI-enabled attacks
  • GenAI-related cyber risks
  • Defensive automation
  • Emerging threat techniques

CCDM®

Managers evaluate:

The management principle is:

  • AI security investments
  • Automation strategy
  • AI-assisted SOC capabilities
  • Reliability
  • False positives and false negatives
  • Human oversight
  • Data exposure
  • Model risk
  • AI vendor risk
  • Explainability
  • Accountability
  • Performance
CCDM®
  • Automate Where Appropriate
  • Validate Performance
  • Maintain Human Authority
  • Govern the Risk
  • Enterprise Defensive Effectiveness
  • Risk Reduction + Capability + Integration + Performance + Cost + Resilience + Enterprise Value

Does CCDM® cover cybersecurity metrics and performance?

Yes.

CCDM® emphasizes measuring whether cyber-defense capabilities are actually effective.

Relevant measures may include:

Candidates learn to distinguish between:

  • Detection coverage
  • Detection gaps
  • Alert quality
  • Incident trends
  • Escalation performance
  • Containment performance
  • Exposure trends
  • Remediation performance
  • Recovery performance
  • Readiness indicators
  • Cyber-resilience measures
  • SOC performance
  • Vendor performance
  • Capability maturity

Security Activity Metrics

and

Does CCDM® cover cybersecurity investment decisions?

Yes.

Cyber-defense leaders must determine where limited resources create the greatest defensive value.

CCDM® addresses:

Managers evaluate investments based on:

  • Business cases
  • Technology investments
  • SOC investments
  • Staffing
  • Managed security services
  • Threat-intelligence capabilities
  • Detection technologies
  • Exposure-management technologies
  • Incident-response capabilities
  • Recovery technologies
  • AI-assisted defense
  • Resource prioritization

Does CCDM® cover security vendors and managed service providers?

Yes.

Managers develop competency in evaluating and governing:

Relevant considerations include:

Capability • Contracts • Service Levels • Integration • Data Handling • Escalation • Performance • Dependency • Risk • Cost

  • Managed Security Service Providers
  • Managed Detection and Response
  • SOC providers
  • Incident-response retainers
  • Threat-intelligence providers
  • Security technology vendors
  • Cloud-security services
  • Forensic providers
  • Recovery providers

Does CCDM® prepare professionals for executive and board communication?

Yes. This is a major CCDM® competency.

Managers must translate technical security information into language that supports organizational decision-making.

The communication progression is:

CCDM®
  • Security Evidence
  • Cyber Risk
  • Business Impact
  • Management Options
  • Executive Decision

Candidates develop competency in communicating:

The objective is to provide executives and boards with decision-relevant information rather than unnecessary technical complexity.

  • Significant threats
  • Enterprise exposure
  • Major incidents
  • Business impact
  • Recovery status
  • Defensive readiness
  • Investment requirements
  • Performance
  • Resilience
  • Strategic priorities
  • How is CCDM® assessed?
  • CCDP® Competency Standard

How is CCDP® assessed?

Candidates may demonstrate competency through an applicable certification pathway.

Option 1 — CCDP® Certification Examination

Recommended structure:

Assessment emphasizes:

Knowledge • Detection • Analysis • Threat Recognition • Incident Judgment • Investigation • Recovery • Resilience

  • 100 questions
  • Multiple-choice and scenario-based questions
  • 90 minutes
  • Closed book
  • Secure online proctoring or approved testing center
  • Recommended passing score: 70%

Option 2 — Applied Cyber Defense Capstone

Eligible candidates participating in an approved instructor-led pathway may demonstrate competency through a structured CCDP® Applied Cyber Defense Capstone.

Option 1 — CCDM® Certification Examination

Recommended structure:

Assessment emphasizes:

Strategy • Governance • Threat Judgment • Exposure Prioritization • Incident Decisions • Crisis Leadership • Recovery • Resilience • Investment • Executive Judgment

  • 100 questions
  • Advanced multiple-choice and scenario-based questions
  • 90 minutes
  • Closed book
  • Secure online proctoring or approved testing center
  • Recommended passing score: 70%

Option 2 — Enterprise Cyber Defense Management Capstone

Eligible candidates in an approved instructor-led pathway may demonstrate advanced management competency through the Enterprise Cyber Defense Management Capstone.

What skills does CCDP® test?

CCDP® evaluates professional competency across areas including:

Cyber Defense Architecture • Security Monitoring • Threat Detection • Threat Intelligence • Threat Hunting • Exposure Management • Incident Response • Digital Forensics • Recovery • Cyber Resilience • AI-Enabled Defense

CCDM®
  • Detect
  • Analyze
  • Prioritize
  • Contain
  • Investigate
  • Recover
  • Improve
  • CCDM® Competency Standard

What skills does CCDM® test?

CCDM® evaluates management competency across areas including:

Cyber Defense Strategy • SOC Leadership • Threat Governance • Exposure Prioritization • Incident Leadership • Cyber Crisis Management • Recovery • Resilience • Technology Investment • Performance Measurement • AI Governance • Workforce Leadership • Executive Communication

CCDM®
  • Assess
  • Strategize
  • Govern
  • Prioritize
  • Decide
  • Lead
  • Recover
  • Measure
  • Transform

How long is the recommended training?

Recommended training may vary according to delivery model and candidate background.

A general program range is:

CCDP®

Approximately 40–60 instructional hours

CCDM®

Approximately 50–60 instructional hours

Training may include instructor-led instruction, scenarios, applied activities, practical exercises, simulations, case studies, and Capstone work where applicable.

How long are CCDP® and CCDM® certifications valid?

The recommended credential cycle for both certifications is:

CCDM®

Three Years

Credential holders maintain professional competence through applicable IBACTP® Continuing Professional Education (CPE), professional ethics, certification-maintenance, and recertification requirements.

Final requirements are governed by current IBACTP® certification policies.

What comes after CCDP®?

The recommended advanced progression is:

CCDM®
  • CCDP®
  • CCDM®

CCDP® develops professional cyber-defense competency.

CCDM® advances that capability into enterprise strategy, governance, leadership, investment, performance, crisis management, and resilience.

CCDM®

Choose Your Cyber Defense Path

CCDM®

The Threat Will Not Wait. Neither Should Your Cyber Defense Capability.

Organizations need professionals who can detect and respond.

They also need leaders who can govern, prioritize, recover, and build resilience.

  • Choose Your Level.

CCDP® — Certified Cyber Defense Professional

Detect Earlier. Analyze Accurately. Respond Effectively. Recover Securely.

[EXPLORE CCDP®] [ENROLL NOW] [REGISTER FOR CCDP® EXAM]

CCDM® — Certified Cyber Defense Manager

Anticipate Threats. Govern Defense. Lead Cyber Crises. Build Resilience.

[EXPLORE CCDM®] [ENROLL NOW] [REGISTER FOR CCDM® EXAM]

CCDM®

CCDM®

Certified Cyber Defense Manager

Assess • Strategize • Govern • Prioritize • Lead • Measure • Transform

The examination

Exam & Certification Details

Everything you need to plan your sitting.

CCDM-200

Exam code for the Advanced Manager-level Cyber Defense credential.

100 questions (maximum)

Multiple choice, completed in 120 minutes.

700 out of 1000

Passing score. Delivered in English.

Recommended experience

A minimum of five years of experience, including two years in a supervisory, lead or management role.

Where you sit it

IBACTP® approved testing centers and online proctored delivery

Staying certified

Three-year certification cycle with continuing professional education

Choose your route

Four ways to enroll. One credential.

Every route leads to the same CCDM® examination and the same designation.

Option 1

Self-Paced Learning

Self-study
$400 USD
  • Exam fee only
  • Complimentary course materials provided
Option 2

Virtual Instructor-Led Training

4 days
$1,200 USD
  • 4 days, 2 hours daily online
  • Includes all course materials + Exam
Select a Date and Purchase
Option 3

Bootcamps & Intensives

10 days
$1,800 USD
  • 10 days, 2 hours daily
  • Includes all course materials + Exam
Select a Date and Purchase
Option 4

Corporate Training

Your schedule
Fees negotiable
  • Certify a whole team on a schedule that suits your organization
  • Fees depend on the team's size / number
Request a Team Quote
Questions

Frequently Asked Questions — CCDM®

Explore frequently asked questions about the Certified Cyber Defense Manager (CCDM®) certification, eligibility, leadership competencies, assessment pathways, technology coverage, and professional progression.

The IBACTP® Cyber Defense Certification Pathway is designed to support professionals at two distinct career levels:

What is CCDM®?

The Certified Cyber Defense Manager (CCDM®) is an advanced, vendor-neutral professional certification designed for cybersecurity professionals responsible for leading, governing, measuring, resourcing, and transforming enterprise cyber-defense capabilities.

CCDM® focuses on:

Cyber Defense Strategy • SOC Leadership • Threat Management • Exposure Governance • Incident Leadership • Cyber Crisis Management • Recovery • Cyber Resilience • Technology Investment • Performance Measurement • AI-Enabled Defense • Workforce Leadership • Executive Communication

The certification moves beyond performing individual cyber-defense activities and focuses on the management decisions required to ensure that an organization can anticipate threats, detect attacks, respond effectively, restore critical operations, and continuously strengthen resilience.

Who is CCDM® designed for?

CCDM® is designed for experienced cybersecurity, cyber-defense, security-operations, incident-response, risk, resilience, and technology professionals seeking advanced management and leadership responsibilities.

Relevant roles may include:

CCDM® is particularly relevant for professionals who must translate technical security conditions into management priorities, investment decisions, operational actions, and executive recommendations.

  • Cyber Defense Managers
  • Cybersecurity Managers
  • SOC Managers
  • Security Operations Managers
  • Incident Response Managers
  • Cyber Incident Managers
  • Threat Management Leaders
  • Vulnerability and Exposure Managers
  • Security Engineering Managers
  • Cyber Resilience Managers
  • Technology Risk Managers
  • Cybersecurity Program Managers
  • Security Directors
  • Information Security Leaders
  • Aspiring CISOs and senior security leaders
How is CCDM® different from CCDP®?

The two credentials represent different levels of the IBACTP® cyber-defense pathway.

CCDP® — Professional Level

CCDP® focuses primarily on performing and supporting cyber-defense activities:

Monitor → Detect → Analyze → Investigate → Respond → Recover

CCDM® — Advanced Management Level

CCDM® focuses on governing and leading enterprise cyber-defense capabilities:

Assess → Strategize → Govern → Prioritize → Lead → Measure → Transform

A CCDP® professional may investigate an incident and recommend containment.

A CCDM® manager determines whether the incident requires enterprise escalation, establishes decision authority, evaluates business consequences, coordinates leadership response, directs recovery priorities, and communicates readiness and risk to executives.

Do I need CCDP® before pursuing CCDM®?

The recommended progression is:

CCDP® is the recommended professional pathway into CCDM®.

CCDP® → CCDM®

However, professionals with equivalent qualifying experience in cybersecurity, cyber defense, SOC operations, incident response, technology risk, business continuity, cyber resilience, security management, or related leadership responsibilities may satisfy applicable IBACTP® eligibility requirements.

Candidates should review current certification eligibility policies before applying.

Is CCDM® vendor-neutral?

CCDM® develops transferable management and leadership competencies rather than expertise with one specific security vendor, technology platform, cloud provider, or security product.

Managers learn to evaluate technologies according to factors such as:

Capability • Integration • Risk Reduction • Performance • Cost • Scalability • Resilience • Governance • Operational Value

This allows CCDM® competencies to remain relevant across different industries and technology environments.

Yes.

Does CCDM® cover SOC leadership?

Candidates evaluate areas including:

The management objective is not simply to operate a SOC, but to determine:

Yes. SOC leadership is a major CCDM® competency.

  • SOC strategy
  • SOC operating models
  • Monitoring coverage
  • Detection engineering
  • Alert management
  • Threat intelligence
  • Threat hunting
  • Escalation models
  • Automation
  • Staffing
  • Skills and competencies
  • Internal versus outsourced operations
  • Managed security services
  • Service levels
  • SOC metrics
  • Detection performance
  • Continuous improvement
Does CCDM® cover threat intelligence?

CCDM® addresses threat intelligence from a management and decision-making perspective.

Managers evaluate how intelligence supports:

The emphasis is on converting intelligence into defensive priorities and management decisions.

Yes.

  • Strategic threat awareness
  • Detection priorities
  • Vulnerability prioritization
  • Threat hunting
  • Incident preparation
  • Executive risk awareness
  • Defensive investment
  • Emerging-threat planning
Does CCDM® cover vulnerability and exposure management?

CCDM® moves beyond simply reviewing vulnerability severity scores.

Candidates learn to govern enterprise exposure using factors such as:

Yes.

Threat Activity + Exploitability + Exposure + Asset Criticality + Business Impact + Existing Controls

Managers evaluate which weaknesses require immediate remediation, which can be mitigated through compensating controls, and which risks may require formal treatment or executive attention.

Does CCDM® cover incident response?

CCDM® addresses incident response from a management and leadership perspective.

Candidates evaluate:

The emphasis is on ensuring that technical response activities are supported by effective leadership, governance, accountability, communication, and decision-making.

Yes.

  • Incident governance
  • Severity classification
  • Escalation criteria
  • Decision authority
  • Incident command
  • Containment priorities
  • Investigation coordination
  • Internal and external stakeholders
  • Recovery decisions
  • Documentation
  • Post-incident review
Does CCDM® cover cyber crisis management?

Not every cybersecurity incident becomes an enterprise crisis.

CCDM® prepares managers to evaluate when an incident requires broader organizational escalation because of factors such as:

Candidates learn to connect:

Yes. Cyber crisis leadership is a defining CCDM® competency.

  • Critical-service disruption
  • Significant data exposure
  • Financial impact
  • Operational interruption
  • Legal or regulatory implications
  • Customer impact
  • Third-party dependencies
  • Reputational consequences
  • Executive decision requirements
Does CCDM® cover digital forensics?

CCDM® does not focus primarily on performing detailed forensic examinations.

Instead, managers develop competency in overseeing:

The focus is on ensuring that investigations are properly governed and support defensible organizational decisions.

Yes, from a management and governance perspective.

  • Forensic readiness
  • Evidence preservation
  • Investigation scope
  • Chain-of-custody requirements
  • Internal and external investigators
  • Investigation priorities
  • Documentation
  • Legal and regulatory considerations
  • Root-cause findings
  • Post-incident corrective actions
Does CCDM® cover business continuity and disaster recovery?

CCDM® integrates cyber incident management with business continuity, disaster recovery, critical-service restoration, and organizational resilience.

Candidates evaluate:

This enables managers to connect technical cybersecurity recovery with enterprise operational requirements.

Yes.

  • Critical business services
  • Technology dependencies
  • Recovery priorities
  • Recovery objectives
  • Backup and restoration capabilities
  • Disaster-recovery strategies
  • Continuity arrangements
  • Recovery validation
  • Exercises and simulations
  • Post-recovery monitoring
Why is cyber resilience a major focus of CCDM®?

Organizations cannot assume that every attack will be prevented.

Cyber-defense leadership must therefore prepare the organization to:

Anticipate → Withstand → Respond → Recover → Adapt

CCDM® treats resilience as a measurable enterprise capability involving technology, people, processes, governance, continuity, recovery, exercises, and continuous improvement.

The goal is not simply to restore technology after an incident.

The goal is to restore critical operations securely and emerge better prepared for the next disruption.

Does CCDM® cover cyber-defense technologies?

CCDM® addresses management and governance considerations involving technology categories such as:

SIEM • SOAR • EDR/XDR • IDS/IPS • Threat Intelligence • Vulnerability Management • Attack-Surface Management • Cloud Security • Identity Security • Digital Forensics • Incident Management • Backup and Recovery • AI-Assisted Security

Managers are expected to understand how to evaluate:

Selection • Integration • Governance • Cost • Performance • Scalability • Risk • Vendor Capability • Business Value

The certification does not require mastery of one specific commercial product.

Yes.

Does CCDM® cover AI-enabled cyber defense?

CCDM® examines both the opportunities and risks created by artificial intelligence.

Management considerations include:

The management principle is:

Yes.

  • AI-assisted detection
  • AI-supported threat intelligence
  • Automated alert analysis
  • AI-assisted threat hunting
  • AI-supported incident response
  • Security automation
  • Generative AI
  • AI-enabled attacks
  • Sensitive-data exposure
  • Adversarial manipulation
  • AI supply-chain risk
  • Human oversight
  • AI governance
  • Performance validation
Does CCDM® cover cybersecurity metrics and performance measurement?

Managers must be able to demonstrate whether defensive capabilities are actually improving.

CCDM® addresses:

The objective is to move cyber-defense reporting from:

Yes.

  • Key Performance Indicators (KPIs)
  • Key Risk Indicators (KRIs)
  • Detection coverage
  • Alert quality
  • Incident trends
  • Detection and response performance
  • Exposure trends
  • Remediation performance
  • Recovery performance
  • Resilience indicators
  • Capability maturity
  • Service-provider performance
“How much security activity occurred?”

toward:

Does CCDM® address cybersecurity investment decisions?

CCDM® prepares managers to evaluate cyber-defense investments based on risk, capability requirements, cost, performance, operational impact, and enterprise value.

Candidates examine areas such as:

The objective is to ensure that cyber-defense resources are directed toward the capabilities that matter most.

Yes.

  • Business cases
  • Budget priorities
  • Technology investments
  • Staffing investments
  • Managed security services
  • Capability gaps
  • Risk reduction
  • Technology consolidation
  • Vendor selection
  • Performance expectations
  • Investment tradeoffs
Does CCDM® address vendors and managed security providers?

Modern cyber defense frequently depends on external technology providers, Managed Security Service Providers, cloud providers, consultants, incident-response partners, and other third parties.

CCDM® addresses management considerations involving:

Managers must understand that outsourcing a security capability does not eliminate organizational accountability for cyber risk.

Yes.

  • Provider selection
  • Service requirements
  • Security responsibilities
  • Performance expectations
  • Escalation
  • Integration
  • Service levels
  • Risk
  • Dependency
  • Oversight
  • Incident coordination
Does CCDM® cover workforce leadership?

Technology alone cannot create an effective cyber-defense capability.

CCDM® addresses:

Managers learn to align people, processes, technologies, and governance around enterprise defensive objectives.

Yes.

  • Workforce planning
  • Organizational structures
  • Roles and responsibilities
  • Skills assessment
  • Capability gaps
  • Professional development
  • Staffing models
  • Team readiness
  • Leadership
  • Succession considerations
  • Cross-functional collaboration
  • Security culture
Does CCDM® prepare professionals for executive and board communication?

Senior cyber-defense leaders must translate complex technical information into language that supports business decisions.

Candidates develop competency in communicating:

The communication progression is:

Yes. This is a major competency of CCDM®.

  • Enterprise cyber risk
  • Significant threats
  • Major exposures
  • Incident severity
  • Business impact
  • Defensive readiness
  • Recovery capability
  • Investment requirements
  • Performance trends
  • Resilience
  • Strategic priorities
Technical Evidence → Cyber Risk → Business Impact → Management Options → Executive Decision

The objective is not to overwhelm executives with technical detail, but to provide the information necessary for informed governance and decision-making.

How is CCDM® assessed?

CCDM® provides two assessment pathways.

Option 1 — CCDM® Certification Examination

The recommended structure includes:

100 Questions • 90 Minutes • Advanced Multiple-Choice and Scenario-Based Questions • Closed Book • Secure Proctoring • Recommended Passing Score: 70%

The assessment emphasizes:

Option 2 — Enterprise Cyber Defense Management Capstone

Eligible candidates participating in an approved instructor-led pathway may demonstrate advanced competency through the CCDM® Enterprise Cyber Defense Management Capstone.

The Capstone integrates multiple management competencies within realistic enterprise cyber-defense situations.

What skills and competencies does the CCDM® certification test?

The CCDM® assessment evaluates advanced managerial competency across eight integrated domains:

The CCDM® competency standard is:

  • Cyber Defense Strategy and Governance
  • SOC, Detection, and Security Operations Leadership
  • Threat, Vulnerability, and Exposure Governance
  • Incident Response and Cyber Crisis Leadership
  • Recovery, Continuity, and Cyber Resilience
  • Cyber Defense Investment, Technology, Vendor, and Performance Management
  • AI-Enabled Defense and Emerging Cyber Risk
  • Leadership, Workforce, Executive Communication, and Transformation
Is CCDM® suitable for executive-level cybersecurity responsibilities?

CCDM® is designed to develop the connection between operational cyber defense and senior organizational decision-making.

The credential is particularly relevant for professionals who must advise senior management or boards regarding:

CCDM® therefore prepares professionals not only to manage security operations, but also to communicate cyber-defense readiness as an enterprise risk and resilience issue.

Yes.

  • Cyber threats
  • Enterprise exposure
  • Incident readiness
  • Major cyber incidents
  • Recovery capability
  • Cyber resilience
  • Investment priorities
  • Technology strategy
  • Workforce capability
  • AI-enabled security
  • Defensive performance
How long is CCDM® valid?

The recommended CCDM® certification cycle is:

Three Years

Credential holders maintain professional competency through applicable IBACTP® Continuing Professional Education (CPE), professional ethics, certification-maintenance, and recertification requirements.

Credential holders should consult current IBACTP® policies for specific requirements applicable to their certification cycle.

CCDM® — Advanced / Management Level

Develop and validate enterprise cyber-defense strategy, governance, incident leadership, resilience, investment, workforce, and executive decision-making competencies.

Together, the certifications create a structured progression:

CCDM®

Ready to Lead Enterprise Cyber Defense?

Become CCDM® Certified

Move beyond managing individual tools and security activities.

Anticipate Threats. Govern Defense. Lead Cyber Crises. Build Resilience. Protect Enterprise Value.

  • Set Cyber Defense Strategy
  • Govern SOC and Detection Capabilities
  • Prioritize Enterprise Cyber Exposure
  • Lead Major Cyber Incidents
  • Direct Cyber Crisis Response
  • Restore Critical Operations
  • Build Enterprise Cyber Resilience
  • Prioritize Defensive Investments
  • Govern AI-Enabled Defense
  • Build High-Performance Cyber Defense Teams
  • Advise Executives and Boards

Certified Cyber Defense Manager (CCDM®) · International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

28+ Certifications
14 Technology Disciplines
Global Recognition
Industry Validated
Your Career Our Mission