The purpose of this study is to develop and validate a role-based cybersecurity training syllabus forVenture Capital (VC) firms using the CIS Critical Security Controls v8.1 (Implementation Group1) and an Outcome-Based Education (OBE) approach grounded in a cybersecurity-adapted TrainingNeeds Assessment (TNA) framework. A mixed-method design was employed. In the qualitativephase, interviews with IT personnel and senior management were conducted to identify dominantcybersecurity risks in VC environments. In the quantitative phase, a structured survey wasdistributed to VC employees to assess the relevance, clarity, and applicability of the proposedsyllabus. Content validity was evaluated through expert judgment using the Content Validity Ratio(CVR), while employee acceptance and internal consistency were examined using Cronbach’sAlpha. The results show that the most critical risks in VC firms are low security awareness, phishingthreats, and compliance-related vulnerabilities. Three CIS IG1 controls—Security AwarenessTraining, Malware Defenses, and Incident Response Management—were prioritized as corecontent. The final syllabus integrates these controls into role-specific learning outcomes andassessment strategies aligned with OBE principles. Validation results indicate strong expertagreement and high employee acceptance, supporting the syllabus as relevant, understandable, andsuitable for implementation in VC firms.
Copyrights © 2026