Build a Risk Register for a Cross-Border Healthcare Provider
Overview
What this challenge is about.
Conduct 8 interviews to build a 25-risk register for a cross-border healthcare provider. Earn a verifiable certificate.
The scenario
The healthcare group (around EUR 320M revenue, 220k patient records, EHR system shared across 14 clinics) has a CISO of 7 months trying to professionalize a previously ad-hoc security function — the board is paying attention for the first time.
The Brief
What you'll do, and what you'll demonstrate.
Build a 25-risk NIST-aligned register + 60-day remediation roadmap that the audit committee accepts as the new security baseline.
Earning criteria — what you'll demonstrate
- Apply NIST SP 800-30 to a real enterprise risk-assessment exercise
- Map sector-specific threats (healthcare) onto a general-purpose risk framework
- Score risks defensibly using explicit thresholds
- Communicate enterprise risk to a non-technical board audience
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Risk Management
Identify, assess, and mitigate risks across business operations and projects.
- Nist Sp 800 30
Apply nist sp 800 30 to solve real industry problems and demonstrate production-level capability.
- Security Governance
Apply security governance to solve real industry problems and demonstrate production-level capability.
- Compliance
Apply compliance to solve real industry problems and demonstrate production-level capability.
- Stakeholder Communication
Apply stakeholder communication to solve real industry problems and demonstrate production-level capability.
- Remediation Planning
Apply remediation planning to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Product Manager
PMs in regulated industries who can read a risk register price compliance work into their roadmaps without being told to.
This challenge sharpens
- risk-management
- compliance
- remediation-planning