Skip to content

GRC Training for MSP vCISOs and Compliance Leads

GRC training for your MSP's vCISO and compliance leads: Empath's MSP courses on CMMC, FTC Safeguards, incident response and Security+, plus Curated Collection CISSP and Microsoft Learn security paths. Every Empath Learn seat includes it.

Emmy the elephant in a diving mask

750+

Cybersecurity Courses in Every Seat

500+

Compliance Courses, Safety to HIPAA

40+

Hands-On Labs in the Collection

60+

Empath Courses in Cybersecurity

Start Here: A New Security Lead's First Three Courses

Start with governance, the Microsoft environment your MSP manages and incident response; vCISO transition training is for existing vCIOs.

  1. Foundations of GRC for MSPs Empath, 89 min Map governance, risk and compliance work.
  2. Mapping M365 to NIST CSF 2.0 Empath, 24 min Apply a framework to Microsoft 365.
  3. Fundamentals of Incident Response Empath, 25 min Prepare a response workflow.

For client-specific controls, use the compliance obligations guide after the lead identifies the applicable rule.

“There's something for everyone here. Every employee needs to speak Cybersecurity.

This includes techs, marketing, finance. I have my whole team signed up as it's great for onboarding new employees. Empath saves us time by unraveling the latest cyber news, like the new FTC safeguard rules. Empath demystifies topics like the NIST Cybersecurity Framework and cyber insurance so newcomers can get into the club.”

Ann Westerheim
President of Ekaru

What Training Does a Security and Compliance Lead Need?

Empath has cybersecurity training courses built for MSP teams, on vCISO services, GRC, CMMC and incident response. Good cybersecurity compliance training starts with the frameworks your clients answer to, then the security work behind them.

Your security and compliance leads need:

  • vCISO skills, from policies and assessments to client conversations
  • Governance, risk and compliance run as a repeatable program
  • The frameworks clients ask about: CMMC, NIST CSF, SOC 2, FTC Safeguards, HIPAA and PCI DSS
  • Incident response, including the forensics, legal and insurance side
  • Courses toward Security+, CISSP and CISM, plus Microsoft security from SC-900 to SC-100

Empath adds new courses every week.

GRC and Security Courses by Skill

A sample from the full course list. All are included in every Empath Learn seat.

SkillCoursesExample
Governance and frameworks150+Foundations of GRC for MSPs
Security operations500+Security Analyst to Security Architect Sandbox Lab
Compliance, from workplace safety to HIPAA500+HIPAA Basics
CMMC and NIST4 by EmpathCMMC 2026: What Every MSP Needs to Know
FTC Safeguards, SOC 2 and FFIEC3 by EmpathSOC2 Compliance for MSPs
Incident response6 by EmpathFundamentals of Incident Response
CompTIA Security+DozensCompTIA Security+: General Security Concepts
CISSP and CISMDozensCISSP 2024: Security Governance & Compliance Issues
Microsoft security400+ itemsDefend against cyberthreats with Microsoft Defender XDR
Hands-on labs, all subjects40+Perform Security Audits on Linux Services Lab [Guided]

A course can count in more than one row. Microsoft Learn items include modules, paths and certifications.

Security and Compliance Courses by Catalog

Every Empath Learn seat has all three catalogs. Each tab shows a sample, in the skill order above.

Empath Courses for vCISO and GRC Work

Courses Empath built for MSPs, from vCISO work and CMMC to Security+ with Professor Messer. Empath's course on the FTC Safeguards Rule is in the full course list.

  • Included in Empath Learn

    Going from vCIO to vCISO, Empath. Policies, assessments and client conversations for a new vCISO. 26 minutes.

  • Included in Empath Learn

    The vCISO Mindset, Empath. Turning regulations into security programs for small and midsize clients. 72 minutes.

  • Included in Empath Learn

    Foundations of GRC for MSPs, Empath. How governance, risk management and compliance build trust with clients. 89 minutes.

  • Included in Empath Learn

    Introduction to Compliance and GRC, Empath. GRC as a repeatable lifecycle. 95 minutes.

  • Included in Empath Learn

    CMMC 2026: What Every MSP Needs to Know, Empath. What the changing CMMC rules mean for MSPs with defense clients. 20 minutes.

  • Included in Empath Learn

    Should My MSP Service CMMC Clients?, Empath. The risks and business impact of working with defense contractors. 76 minutes.

  • Included in Empath Learn

    Introduction to the NIST Cybersecurity Framework, Empath. The NIST CSF from the start, as a base for CMMC and GRC work. 76 minutes.

  • Included in Empath Learn

    Mapping M365 to NIST CSF 2.0, Empath. A self-scoring assessment that maps Microsoft 365 controls to NIST CSF 2.0. 24 minutes.

  • Included in Empath Learn

    SOC2 Compliance for MSPs, Empath. Matching security controls to SOC 2, drafting policies and running audits. 39 minutes.

  • Included in Empath Learn

    Fundamentals of Incident Response, Empath. The life cycle of a cyber attack through NIST, MITRE ATT&CK and the Cyber Kill Chain. 25 minutes.

  • Included in Empath Learn

    What Happens When It Happens: The Role of the Cyber Broker and Cyber Insurance Carrier in IR, Empath. Why the insurer shows up early in an incident, from a five-course series. 35 minutes.

  • Included in Empath Learn

    CompTIA Security+: General Security Concepts, Empath. Security controls, cryptography and zero trust, first of five courses. 152 minutes.

Illustration of a learning pathway in Empath

Microsoft Learn for Security, from SC-900 to SC-100

Microsoft's own security training in the same Empath Learn seat: more than 400 items, including modules, paths and certifications. Microsoft awards the certifications.

  • Microsoft Learn in Empath Learn

    Microsoft Certified: Security, Compliance, and Identity Fundamentals, Microsoft. The SC-900 basics of security, compliance and identity across Microsoft cloud services. Pairs with Empath's SC-900 course.

  • Microsoft Learn in Empath Learn

    Microsoft Certified: Security Operations Analyst Associate, Microsoft. The SC-200 role: triage, incident response and threat hunting with Defender XDR and Sentinel.

  • Microsoft Learn in Empath Learn

    Microsoft Certified: Cybersecurity Architect Expert, Microsoft. The SC-100 role: designing security on Zero Trust principles, including GRC and security operations.

  • Included in Empath Learn

    Defend against cyberthreats with Microsoft Defender XDR, Microsoft. A path toward an Applied Skills credential in Defender XDR threat response. 292 minutes.

  • Included in Empath Learn

    Enforce security governance and regulatory compliance, Microsoft. Azure Policy, Defender for Cloud and Azure RBAC for governance across Azure. 143 minutes.

  • Included in Empath Learn

    Deploy and operate Microsoft Security Copilot, Microsoft. From enabling Security Copilot and writing prompts to managing plugins and agents. 101 minutes.

Illustration of numbered course steps in Empath

Curated Collection Courses and Hands-On Labs

CISSP, CISM, HIPAA and PCI DSS courses, plus more than 40 hands-on labs from Skillsoft on many subjects, security among them.

  • Included in Empath Learn

    CISSP 2024: Security Governance & Compliance Issues, Skillsoft. How leadership sets security direction and manages risk. 42 minutes.

  • Included in Empath Learn

    CISM 2022: Information Security Governance, Skillsoft. Matching information security to business strategy, for a vCISO. 100 minutes.

  • Included in Empath Learn

    CISM 2022: Incident Response, Skillsoft. The parts of an incident response plan and the roles in it. 42 minutes.

  • Included in Empath Learn

    HIPAA Basics, BizLibrary Productions. Lessons on the HIPAA Security, Privacy and Breach Notification Rules. 35 minutes.

  • Included in Empath Learn

    Payment Card Industry Data Security Standard (PCI DSS) Compliance, BizLibrary Productions. Protecting cardholder data. 24 minutes.

  • Included in Empath Learn

    Security Analyst to Security Architect Sandbox Lab, Skillsoft. A live lab with Kali Linux, Windows Server and Ubuntu machines. 240 minutes.

  • Included in Empath Learn

    Perform Security Audits on Linux Services Lab [Guided], Skillsoft. Finding and fixing a firewall misconfiguration and wrong permission settings. 30 minutes.

Illustration of a video course and course progress in Empath

The full course list has more than 750 cybersecurity courses: 500+ on security operations, 150+ on frameworks and governance and over 60 security awareness courses from the Curated Collection. It also has more than 500 on compliance obligations. See every title in the course list.

“It’s been a few weeks since we launched my SOC2 Compliance for MSPs course with Empath, and the feedback has been amazing.

When you help your clients achieve SOC2, everybody wins.”

Jason Rorie
CEO of Triad

Can I Build My Own Pathway for Security and Compliance Leads?

Yes. There is no template for this role, so mix Empath, Microsoft Learn and Curated Collection courses in one pathway and add your own policies and SOPs as courses.

A vCISO pathway could start with Going from vCIO to vCISO and The vCISO Mindset, add Foundations of GRC for MSPs, then end with your own client assessment checklist. Read how to assign a course in Empath.

New-Hire Basics Everyone at Your MSP Takes

Everyone at your MSP can start with these four courses in Empath.

  • New MSP Employee 101: The Essentials for Everyone, Empath. How the MSP business model works, and the terms MSP staff use. 87 minutes.
  • Time Tracking: What Every MSP Employee Needs to Know, Empath. Why accurate time entries matter for profit and client satisfaction. 31 minutes.
  • Introduction to Security Awareness, Empath. Why people are the weak link in security, and how MSPs run security awareness training. 58 minutes.
  • AI Fluency, Empath. How to work with AI in everyday tasks, with videos from Anthropic. 69 minutes.

For more onboarding courses, see new-hire training for MSPs.

Which Courses Fit the Rest of Your Team?

Your security leads work with the help desk techs and with owners and executives, plus the sales team and vCIOs. A new hire in any role can start with the onboarding courses for MSP staff.

For the subjects behind the job, browse all cybersecurity courses, courses on compliance obligations and Empath's courses built for MSPs. Or go back to the Empath course catalog.

Questions About GRC and Security Training

Short answers for MSP owners and the security leads they train.

What training does a vCISO need?

Empath Learn covers vCISO training in security strategy, governance and the frameworks clients answer to. Start with Going from vCIO to vCISO and The vCISO Mindset, then Foundations of GRC for MSPs and Introduction to the NIST Cybersecurity Framework. CISM governance courses from the Curated Collection go further. Select paths for the client's actual obligations.

Is there CMMC training for MSP staff?

Yes, Empath Learn includes CMMC training built for MSPs. CMMC 2026: What Every MSP Needs to Know covers the changing rules and the Phase 2 pause, and Should My MSP Service CMMC Clients? weighs the risks and business impact. Two NIST courses add the framework side. The courses can help meet training requirements; they do not make an MSP compliant.

What is GRC training?

GRC training teaches governance, risk and compliance as one program, and how the three work together. For MSPs, Empath's Foundations of GRC for MSPs and Introduction to Compliance and GRC cover the basics, and courses on third party risk, SOC 2 and FTC Safeguards go further.

Is GRC training included in Empath Learn?

Yes, GRC and security training is included in every Empath Learn seat, on every plan. It covers all three catalogs: Empath's own courses, Microsoft Learn and the Curated Collection with its labs and AI roleplays. Live streams and the tools to build your own courses come too. For plan costs, see empathmsp.com/pricing.

Does Empath award security certifications?

No, Empath does not award certifications; your staff earn them from the bodies that issue them, such as CompTIA, ISC2, ISACA and Microsoft. Empath Learn has courses toward several: Security+ with Professor Messer, CISSP and CISM in the Curated Collection, plus Microsoft security certifications from SC-900 to the Cybersecurity Architect Expert.

How do I assign a vCISO pathway?

Build the pathway, then assign it to your vCISO, and every course in it is assigned. Set a due date and track progress in Empath. There is no template for this role, so you pick from all three catalogs and can add your own policies as courses.

Which cybersecurity training courses are designed specifically for MSP teams?

Empath Learn includes MSP-built security courses such as Foundations of GRC for MSPs, CMMC 2026: What Every MSP Needs to Know, Going from vCIO to vCISO and The vCISO Mindset. A security lead can add Curated Collection labs and governance courses. Choose the path by role and client work; a course does not make the MSP compliant.

Want to See It for Your Security Team?

Book a demo and we will show you the security courses in Empath Learn and how a pathway for your vCISO would look.