GCSI — Global Cyber Standards Institute, official PECB Partner, Luxembourg.
Certifications & Training
GCSI’s training programs are organized around the regulatory and governance domains that define today’s cybersecurity landscape in Luxembourg and across Europe. Every certification is delivered under PECB’s internationally recognized framework, by a PECB Platinum Trainer. Most certification tracks follow a progressive path — Foundation, then Lead Implementer/Manager, then Lead Auditor — so organizations can match the training to the role and level of expertise required. Explore each domain below for the certifications offered, who it concerns within your organization, and how it connects to the other domains.
Training sessions are delivered in English or French. Most in-company sessions in Luxembourg are currently delivered in French, while international programmes are generally delivered in English.
Les sessions de formation sont dispensées en anglais ou en français. La majorité des sessions en entreprise au Luxembourg sont actuellement dispensées en français, tandis que les programmes internationaux sont généralement dispensés en anglais.
Cybersecurity
ISO/IEC 27001, 27002 and 27032 — building and operating the Information Security Management System that regulators, insurers and business partners now expect an organization to demonstrate.
Risk Management
ISO 31000, ISO/IEC 27005 and EBIOS Risk Manager — the methods that let an organization show not just what its risks are, but the discipline behind that answer.
Business Continuity
ISO 22301 — the structured capability to keep critical operations running, or resume them quickly, when disruption hits.
Privacy & Data Protection
ISO/IEC 27701 — extending ISO/IEC 27001 and 27002 into a full Privacy Information Management System, for organizations operating under the GDPR and supervised in Luxembourg by the CNPD.
AI Governance
ISO/IEC 42001 — the first international standard for the responsible governance of artificial intelligence, arriving as the EU AI Act moves from legislation to operational obligation.
Regulatory Compliance (NIS2, DORA)
NIS2 and DORA — cybersecurity accountability for governing bodies, and digital operational resilience for financial entities supervised in Luxembourg by the CSSF.
Crypto-Assets & Enterprise
MiCA, stablecoins, tokenized assets and blockchain-based services — governing crypto-asset adoption in a controlled, secure and compliant manner, never on an investment or speculative basis.
Executive & Board Training
The Chief Information Security Officer program — for security leaders holding the full governance scope of the role, and for the executives and board members they report to.
Our expert
Dominique Bourra
PECB Platinum Trainer · Expert in governance, risk and cybersecurity
The training programs and certification paths offered by GCSI are grounded in field-level expertise, a deep command of international standards, and a strategic approach to their implementation.
Discover his background and expertise →