GCSI — Global Cyber Standards Institute, official PECB Partner, Luxembourg.

Certifications & Training

GCSI’s training programs are organized around the regulatory and governance domains that define today’s cybersecurity landscape in Luxembourg and across Europe. Every certification is delivered under PECB’s internationally recognized framework, by a PECB Platinum Trainer. Most certification tracks follow a progressive path — Foundation, then Lead Implementer/Manager, then Lead Auditor — so organizations can match the training to the role and level of expertise required. Explore each domain below for the certifications offered, who it concerns within your organization, and how it connects to the other domains.

Training sessions are delivered in English or French. Most in-company sessions in Luxembourg are currently delivered in French, while international programmes are generally delivered in English.

Les sessions de formation sont dispensées en anglais ou en français. La majorité des sessions en entreprise au Luxembourg sont actuellement dispensées en français, tandis que les programmes internationaux sont généralement dispensés en anglais.

Cybersecurity

ISO/IEC 27001, 27002 and 27032 — building and operating the Information Security Management System that regulators, insurers and business partners now expect an organization to demonstrate.

Risk Management

ISO 31000, ISO/IEC 27005 and EBIOS Risk Manager — the methods that let an organization show not just what its risks are, but the discipline behind that answer.

Business Continuity

ISO 22301 — the structured capability to keep critical operations running, or resume them quickly, when disruption hits.

Privacy & Data Protection

ISO/IEC 27701 — extending ISO/IEC 27001 and 27002 into a full Privacy Information Management System, for organizations operating under the GDPR and supervised in Luxembourg by the CNPD.

AI Governance

ISO/IEC 42001 — the first international standard for the responsible governance of artificial intelligence, arriving as the EU AI Act moves from legislation to operational obligation.

Regulatory Compliance (NIS2, DORA)

NIS2 and DORA — cybersecurity accountability for governing bodies, and digital operational resilience for financial entities supervised in Luxembourg by the CSSF.

Crypto-Assets & Enterprise

MiCA, stablecoins, tokenized assets and blockchain-based services — governing crypto-asset adoption in a controlled, secure and compliant manner, never on an investment or speculative basis.

Executive & Board Training

The Chief Information Security Officer program — for security leaders holding the full governance scope of the role, and for the executives and board members they report to.

Our expert

Dominique Bourra

PECB Platinum Trainer · Expert in governance, risk and cybersecurity

The training programs and certification paths offered by GCSI are grounded in field-level expertise, a deep command of international standards, and a strategic approach to their implementation.

Discover his background and expertise →

← Back to Home