Advanced Security Management for Enterprise Risk Leaders Training Course

5 days Security Management Certificate on completion
Course codeSD-SM-002
Duration5 days
LevelIntermediate to Advanced
CategorySecurity Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Enterprise security leaders are expected to protect people, facilities, information, supply chains and business continuity while giving executives a defensible view of exposure. That requires more than incident response procedures or guard-force oversight. Leaders must translate threat intelligence, operational vulnerabilities and control weaknesses into enterprise risk decisions, prioritised investment cases and measurable assurance. This course addresses the gap between security operations and enterprise risk management, enabling participants to govern security as a business-critical risk discipline.

Participants work through an advanced security management framework aligned to ISO 31000, ISO 31010 and ISO 22301. They learn to define security risk appetite, conduct threat and vulnerability assessments, build risk scenarios, apply bow-tie analysis, evaluate control effectiveness and quantify residual risk. The course also covers security risk registers, key risk indicators, incident escalation thresholds, crisis decision structures, third-party security assurance and executive reporting. Participants practise converting operational security data into risk dashboards, treatment plans and board-ready recommendations.

Delivery combines instructor-led analysis with realistic enterprise cases involving site intrusion, insider threat, civil unrest, critical supplier disruption and crisis escalation. Teams use structured risk assessment templates and BowTieXP to analyse a selected scenario, test controls and identify improvement actions. Each participant leaves with an enterprise security risk management pack: a security risk profile, bow-tie model, control assurance plan, executive dashboard outline and 90-day implementation roadmap for adaptation in their own organisation.

Course objectives

By the end of this course, participants will be able to:

  • Design an enterprise security risk governance model with defined accountabilities, escalation routes and decision rights
  • Conduct structured threat, vulnerability and consequence assessments using ISO 31010 techniques
  • Develop security risk scenarios that connect threats, assets, vulnerabilities, controls and business impacts
  • Construct bow-tie analyses to identify preventive controls, recovery controls and control degradation factors
  • Evaluate control effectiveness through assurance testing, performance indicators and residual-risk ratings
  • Create a prioritised security risk register with risk owners, treatment actions, due dates and escalation criteria
  • Produce executive security risk dashboards that communicate exposure, trends, decisions and investment priorities
  • Build a 90-day security risk improvement roadmap linked to enterprise risk appetite and business continuity objectives

Benefits of attending

For you

  • Gain a board-facing method for explaining security exposure in enterprise-risk and financial-impact terms
  • Build confidence using bow-tie analysis to challenge weak or assumed security controls
  • Develop evidence for senior security, resilience and integrated-risk leadership roles
  • Create a reusable security risk reporting structure for executive committees and risk owners
  • Strengthen credibility when proposing security investment, outsourced-service changes or control redesign

For your organisation

  • Establish a more consistent method for comparing security risks across sites, functions and third parties
  • Improve prioritisation of security expenditure by linking treatments to risk appetite and residual exposure
  • Reduce control failure risk through clearer assurance testing, ownership and escalation thresholds
  • Provide executives with decision-ready security dashboards instead of isolated incident statistics
  • Connect security, business continuity, HSE and enterprise-risk teams through shared risk scenarios and terminology

Target competencies

Security risk governanceBow-tie analysisControl assuranceThreat assessmentRisk dashboard designCrisis escalation planning

Who should attend

  • Corporate Security Directors — who must align protective security programmes with enterprise risk and executive governance
  • Security Risk Managers — who need repeatable methods for assessing, treating and reporting security exposure
  • HSE and Integrated Risk Leaders — who oversee connected people, site, operational and business-continuity risks
  • Business Continuity Managers — who must coordinate security incidents, crisis escalation and recovery priorities
  • Regional Security Managers — who need to justify control improvements across sites, countries and operating environments
  • Internal Audit and Risk Assurance Managers — who review security controls and require evidence-based assurance approaches

Requirements and prerequisites

Participants should have practical experience in corporate security, HSE risk, business continuity, facilities protection, emergency management or enterprise risk management. They should already understand basic risk concepts, including likelihood, consequence, inherent risk, residual risk, risk treatment and control ownership. Familiarity with incident reporting, risk registers and security procedures is expected. Participants should be comfortable reviewing spreadsheets and management reports. Prior use of BowTieXP is helpful but not required; the course introduces the required functions. No programming, specialist intelligence-analysis qualification or prior ISO lead-auditor credential is required.

Training methodology

The course uses short instructor-led briefings followed by applied analysis of enterprise security scenarios. Participants work individually and in small groups to define risk appetite, assess threats and vulnerabilities, model critical scenarios in BowTieXP, test controls and prepare executive reporting. Case material includes facility intrusion, insider threat, supplier compromise and civil disturbance, requiring participants to make trade-offs under realistic operational constraints. Facilitated peer review challenges assumptions and strengthens proposed treatments. The final session converts course outputs into a practical 90-day implementation plan for each participant’s workplace.

Course outline

Day 1: Enterprise Security Risk Governance

  • Security management within the enterprise risk management framework
  • ISO 31000 principles, framework and risk-management process
  • Security risk appetite, tolerance statements and escalation thresholds
  • Risk governance roles using the three-lines model
  • Security risk taxonomy for people, sites, assets, information and supply chains
  • Linking security objectives to business continuity and strategic objectives
  • Designing risk ownership, committee reporting and decision-rights matrices

Workshop: Participants map their organisation’s current security governance structure and produce a draft RACI and escalation pathway for one material security risk.

Day 2: Threat, Vulnerability and Scenario Assessment

  • Threat intelligence requirements and source evaluation
  • Asset criticality assessment and consequence definition
  • Vulnerability assessment for facilities, personnel, processes and suppliers
  • ISO 31010 techniques for structured security risk assessment
  • Scenario-based analysis of malicious, accidental and disruptive events
  • Likelihood calibration, impact scoring and uncertainty recording
  • Security risk-register design and residual-risk rating criteria

Workshop: Using a critical-site disruption case, participants produce a scored risk scenario, supporting assumptions log and security risk-register entry.

Day 3: Bow-Tie Analysis and Control Assurance

  • Bow-tie structure: threats, top events, consequences and controls
  • Identifying preventive controls and recovery controls
  • Control effectiveness, availability, reliability and suitability tests
  • Control degradation factors and escalation-factor controls
  • BowTieXP model construction and barrier visualisation
  • Assurance activities, evidence sources and control-testing schedules
  • Defining key control indicators and key risk indicators

Workshop: Participants build a BowTieXP model for an insider-threat or unauthorised-access scenario and produce a control assurance test plan.

Day 4: Treatment, Resilience and Executive Decisions

  • Selecting risk treatment options: avoid, reduce, transfer, accept and prepare
  • Cost-benefit and risk-reduction analysis for security investments
  • Third-party security due diligence and contractual control requirements
  • Incident classification, notification thresholds and executive escalation
  • Integrating ISO 22301 business continuity objectives with security planning
  • Crisis-management decision structures and incident command interfaces
  • Developing treatment plans with owners, milestones and assurance measures

Workshop: Teams prepare a prioritised security treatment plan and investment recommendation for a multi-site disruption and supplier-failure case.

Day 5: Security Risk Reporting and Implementation

  • Board and executive reporting requirements for security risk
  • Security risk-dashboard measures, trend indicators and heat-map limitations
  • Writing decision-focused risk narratives and management recommendations
  • Presenting uncertainty, control gaps and residual exposure credibly
  • Risk acceptance documentation and delegated-authority requirements
  • Designing a 90-day security risk improvement roadmap
  • Measuring programme maturity and continuous-improvement outcomes

Workshop: Participants present an executive security risk pack containing a risk profile, bow-tie summary, dashboard outline and 90-day implementation roadmap.

Tools & standards covered

ISO 31000:2018, ISO 31010:2019, ISO 22301:2019, BowTieXP

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should already work with security, HSE, business continuity, facilities protection or enterprise risk and understand basic likelihood, consequence and control concepts. This is not a foundation course in guarding operations or introductory risk terminology.

A laptop is strongly recommended for exercises, templates and the final implementation pack. BowTieXP activities are guided during the course; prior installation or previous user experience is not required.

The course focuses on enterprise security management, with particular emphasis on people, sites, operations, supply chains and crisis resilience. The methods also apply to cyber-related scenarios where security leaders need to assess business impact, controls and escalation alongside specialist cyber teams.

This course assumes participants can already identify hazards or risks and moves into governance, risk appetite, control assurance, bow-tie modelling and executive decision support. It is designed for leaders who must defend priorities and manage residual exposure across an enterprise.

Participants can use the risk-register structure, bow-tie model, assurance plan and dashboard outline for a live security issue or priority site. The 90-day roadmap identifies the first governance, assessment and reporting actions needed after the course.

You will leave with an enterprise security risk management pack developed through the course exercises. It includes a security risk profile, a bow-tie analysis, control assurance actions, executive dashboard measures and an implementation roadmap.

Upcoming sessions

  • 21 – 25 Sep 2026
    Dar es Salaam · USD 3,500
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Nairobi · USD 3,000
    Book
  • 12 – 16 Oct 2026
    Kigali · USD 3,500
    Book
  • 19 – 23 Oct 2026
    Nairobi · USD 3,000
    Book
  • 19 – 23 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Kigali · USD 3,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Security Management

5 Days Certificate

ASIS Physical Asset Protection Standard Implementation Training Course

Physical asset protection programmes often develop as disconnected projects: a guard contract is renewed, access control is upgraded, CCTV c…

5 Days Certificate

ISO 18788 Security Operations Management System Training Course

Private security operations face heightened scrutiny where services involve guarding, protective security, patrols, access control, secure t…

5 Days Certificate

Crime Prevention Through Environmental Design for Facility Security Training Course

Facilities can be secure on paper yet remain vulnerable because entrances are poorly observed, boundaries are ambiguous, public and staff ro…

5 Days Certificate

ASIS Enterprise Security Risk Management Implementation Training Course

Security teams are increasingly expected to show how physical security, protective services, investigations, travel security and resilience …