GRC Training for MSP vCISOs and Compliance Leads
GRC training for your MSP's vCISO and compliance leads: Empath's MSP courses on CMMC, FTC Safeguards, incident response and Security+, plus Curated Collection CISSP and Microsoft Learn security paths. Every Empath Learn seat includes it.
750+
Cybersecurity Courses in Every Seat
500+
Compliance Courses, Safety to HIPAA
40+
Hands-On Labs in the Collection
60+
Empath Courses in Cybersecurity
Start Here: A New Security Lead's First Three Courses
Start with governance, the Microsoft environment your MSP manages and incident response; vCISO transition training is for existing vCIOs.
- Foundations of GRC for MSPs Empath, 89 min Map governance, risk and compliance work.
- Mapping M365 to NIST CSF 2.0 Empath, 24 min Apply a framework to Microsoft 365.
- Fundamentals of Incident Response Empath, 25 min Prepare a response workflow.
For client-specific controls, use the compliance obligations guide after the lead identifies the applicable rule.
“There's something for everyone here. Every employee needs to speak Cybersecurity.
This includes techs, marketing, finance. I have my whole team signed up as it's great for onboarding new employees. Empath saves us time by unraveling the latest cyber news, like the new FTC safeguard rules. Empath demystifies topics like the NIST Cybersecurity Framework and cyber insurance so newcomers can get into the club.”
What Training Does a Security and Compliance Lead Need?
Empath has cybersecurity training courses built for MSP teams, on vCISO services, GRC, CMMC and incident response. Good cybersecurity compliance training starts with the frameworks your clients answer to, then the security work behind them.
Your security and compliance leads need:
- vCISO skills, from policies and assessments to client conversations
- Governance, risk and compliance run as a repeatable program
- The frameworks clients ask about: CMMC, NIST CSF, SOC 2, FTC Safeguards, HIPAA and PCI DSS
- Incident response, including the forensics, legal and insurance side
- Courses toward Security+, CISSP and CISM, plus Microsoft security from SC-900 to SC-100
Empath adds new courses every week.
GRC and Security Courses by Skill
A sample from the full course list. All are included in every Empath Learn seat.
| Skill | Courses | Example |
|---|---|---|
| Governance and frameworks | 150+ | Foundations of GRC for MSPs |
| Security operations | 500+ | Security Analyst to Security Architect Sandbox Lab |
| Compliance, from workplace safety to HIPAA | 500+ | HIPAA Basics |
| CMMC and NIST | 4 by Empath | CMMC 2026: What Every MSP Needs to Know |
| FTC Safeguards, SOC 2 and FFIEC | 3 by Empath | SOC2 Compliance for MSPs |
| Incident response | 6 by Empath | Fundamentals of Incident Response |
| CompTIA Security+ | Dozens | CompTIA Security+: General Security Concepts |
| CISSP and CISM | Dozens | CISSP 2024: Security Governance & Compliance Issues |
| Microsoft security | 400+ items | Defend against cyberthreats with Microsoft Defender XDR |
| Hands-on labs, all subjects | 40+ | Perform Security Audits on Linux Services Lab [Guided] |
A course can count in more than one row. Microsoft Learn items include modules, paths and certifications.
Security and Compliance Courses by Catalog
Every Empath Learn seat has all three catalogs. Each tab shows a sample, in the skill order above.
Empath Courses for vCISO and GRC Work
Courses Empath built for MSPs, from vCISO work and CMMC to Security+ with Professor Messer. Empath's course on the FTC Safeguards Rule is in the full course list.
-
Going from vCIO to vCISO, Empath. Policies, assessments and client conversations for a new vCISO. 26 minutes.
-
The vCISO Mindset, Empath. Turning regulations into security programs for small and midsize clients. 72 minutes.
-
Foundations of GRC for MSPs, Empath. How governance, risk management and compliance build trust with clients. 89 minutes.
-
Introduction to Compliance and GRC, Empath. GRC as a repeatable lifecycle. 95 minutes.
-
CMMC 2026: What Every MSP Needs to Know, Empath. What the changing CMMC rules mean for MSPs with defense clients. 20 minutes.
-
Should My MSP Service CMMC Clients?, Empath. The risks and business impact of working with defense contractors. 76 minutes.
-
Introduction to the NIST Cybersecurity Framework, Empath. The NIST CSF from the start, as a base for CMMC and GRC work. 76 minutes.
-
Mapping M365 to NIST CSF 2.0, Empath. A self-scoring assessment that maps Microsoft 365 controls to NIST CSF 2.0. 24 minutes.
-
SOC2 Compliance for MSPs, Empath. Matching security controls to SOC 2, drafting policies and running audits. 39 minutes.
-
Fundamentals of Incident Response, Empath. The life cycle of a cyber attack through NIST, MITRE ATT&CK and the Cyber Kill Chain. 25 minutes.
-
What Happens When It Happens: The Role of the Cyber Broker and Cyber Insurance Carrier in IR, Empath. Why the insurer shows up early in an incident, from a five-course series. 35 minutes.
-
CompTIA Security+: General Security Concepts, Empath. Security controls, cryptography and zero trust, first of five courses. 152 minutes.
Microsoft Learn for Security, from SC-900 to SC-100
Microsoft's own security training in the same Empath Learn seat: more than 400 items, including modules, paths and certifications. Microsoft awards the certifications.
-
Microsoft Certified: Security, Compliance, and Identity Fundamentals, Microsoft. The SC-900 basics of security, compliance and identity across Microsoft cloud services. Pairs with Empath's SC-900 course.
-
Microsoft Certified: Security Operations Analyst Associate, Microsoft. The SC-200 role: triage, incident response and threat hunting with Defender XDR and Sentinel.
-
Microsoft Certified: Cybersecurity Architect Expert, Microsoft. The SC-100 role: designing security on Zero Trust principles, including GRC and security operations.
-
Defend against cyberthreats with Microsoft Defender XDR, Microsoft. A path toward an Applied Skills credential in Defender XDR threat response. 292 minutes.
-
Enforce security governance and regulatory compliance, Microsoft. Azure Policy, Defender for Cloud and Azure RBAC for governance across Azure. 143 minutes.
-
Deploy and operate Microsoft Security Copilot, Microsoft. From enabling Security Copilot and writing prompts to managing plugins and agents. 101 minutes.
Curated Collection Courses and Hands-On Labs
CISSP, CISM, HIPAA and PCI DSS courses, plus more than 40 hands-on labs from Skillsoft on many subjects, security among them.
-
CISSP 2024: Security Governance & Compliance Issues, Skillsoft. How leadership sets security direction and manages risk. 42 minutes.
-
CISM 2022: Information Security Governance, Skillsoft. Matching information security to business strategy, for a vCISO. 100 minutes.
-
CISM 2022: Incident Response, Skillsoft. The parts of an incident response plan and the roles in it. 42 minutes.
-
HIPAA Basics, BizLibrary Productions. Lessons on the HIPAA Security, Privacy and Breach Notification Rules. 35 minutes.
-
Payment Card Industry Data Security Standard (PCI DSS) Compliance, BizLibrary Productions. Protecting cardholder data. 24 minutes.
-
Security Analyst to Security Architect Sandbox Lab, Skillsoft. A live lab with Kali Linux, Windows Server and Ubuntu machines. 240 minutes.
-
Perform Security Audits on Linux Services Lab [Guided], Skillsoft. Finding and fixing a firewall misconfiguration and wrong permission settings. 30 minutes.
The full course list has more than 750 cybersecurity courses: 500+ on security operations, 150+ on frameworks and governance and over 60 security awareness courses from the Curated Collection. It also has more than 500 on compliance obligations. See every title in the course list.
“It’s been a few weeks since we launched my SOC2 Compliance for MSPs course with Empath, and the feedback has been amazing.
When you help your clients achieve SOC2, everybody wins.”
Can I Build My Own Pathway for Security and Compliance Leads?
Yes. There is no template for this role, so mix Empath, Microsoft Learn and Curated Collection courses in one pathway and add your own policies and SOPs as courses.
A vCISO pathway could start with Going from vCIO to vCISO and The vCISO Mindset, add Foundations of GRC for MSPs, then end with your own client assessment checklist. Read how to assign a course in Empath.
New-Hire Basics Everyone at Your MSP Takes
Everyone at your MSP can start with these four courses in Empath.
- New MSP Employee 101: The Essentials for Everyone, Empath. How the MSP business model works, and the terms MSP staff use. 87 minutes.
- Time Tracking: What Every MSP Employee Needs to Know, Empath. Why accurate time entries matter for profit and client satisfaction. 31 minutes.
- Introduction to Security Awareness, Empath. Why people are the weak link in security, and how MSPs run security awareness training. 58 minutes.
- AI Fluency, Empath. How to work with AI in everyday tasks, with videos from Anthropic. 69 minutes.
For more onboarding courses, see new-hire training for MSPs.
Which Courses Fit the Rest of Your Team?
Your security leads work with the help desk techs and with owners and executives, plus the sales team and vCIOs. A new hire in any role can start with the onboarding courses for MSP staff.
For the subjects behind the job, browse all cybersecurity courses, courses on compliance obligations and Empath's courses built for MSPs. Or go back to the Empath course catalog.
Questions About GRC and Security Training
Short answers for MSP owners and the security leads they train.
What training does a vCISO need?
Empath Learn covers vCISO training in security strategy, governance and the frameworks clients answer to. Start with Going from vCIO to vCISO and The vCISO Mindset, then Foundations of GRC for MSPs and Introduction to the NIST Cybersecurity Framework. CISM governance courses from the Curated Collection go further. Select paths for the client's actual obligations.
Is there CMMC training for MSP staff?
Yes, Empath Learn includes CMMC training built for MSPs. CMMC 2026: What Every MSP Needs to Know covers the changing rules and the Phase 2 pause, and Should My MSP Service CMMC Clients? weighs the risks and business impact. Two NIST courses add the framework side. The courses can help meet training requirements; they do not make an MSP compliant.
What is GRC training?
GRC training teaches governance, risk and compliance as one program, and how the three work together. For MSPs, Empath's Foundations of GRC for MSPs and Introduction to Compliance and GRC cover the basics, and courses on third party risk, SOC 2 and FTC Safeguards go further.
Is GRC training included in Empath Learn?
Yes, GRC and security training is included in every Empath Learn seat, on every plan. It covers all three catalogs: Empath's own courses, Microsoft Learn and the Curated Collection with its labs and AI roleplays. Live streams and the tools to build your own courses come too. For plan costs, see empathmsp.com/pricing.
Does Empath award security certifications?
No, Empath does not award certifications; your staff earn them from the bodies that issue them, such as CompTIA, ISC2, ISACA and Microsoft. Empath Learn has courses toward several: Security+ with Professor Messer, CISSP and CISM in the Curated Collection, plus Microsoft security certifications from SC-900 to the Cybersecurity Architect Expert.
How do I assign a vCISO pathway?
Build the pathway, then assign it to your vCISO, and every course in it is assigned. Set a due date and track progress in Empath. There is no template for this role, so you pick from all three catalogs and can add your own policies as courses.
Which cybersecurity training courses are designed specifically for MSP teams?
Empath Learn includes MSP-built security courses such as Foundations of GRC for MSPs, CMMC 2026: What Every MSP Needs to Know, Going from vCIO to vCISO and The vCISO Mindset. A security lead can add Curated Collection labs and governance courses. Choose the path by role and client work; a course does not make the MSP compliant.