Advanced Security Management for Enterprise Risk Leaders Training Course
| Course code | SD-SM-002 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Enterprise security leaders are expected to protect people, facilities, information, supply chains and business continuity while giving executives a defensible view of exposure. That requires more than incident response procedures or guard-force oversight. Leaders must translate threat intelligence, operational vulnerabilities and control weaknesses into enterprise risk decisions, prioritised investment cases and measurable assurance. This course addresses the gap between security operations and enterprise risk management, enabling participants to govern security as a business-critical risk discipline.
Participants work through an advanced security management framework aligned to ISO 31000, ISO 31010 and ISO 22301. They learn to define security risk appetite, conduct threat and vulnerability assessments, build risk scenarios, apply bow-tie analysis, evaluate control effectiveness and quantify residual risk. The course also covers security risk registers, key risk indicators, incident escalation thresholds, crisis decision structures, third-party security assurance and executive reporting. Participants practise converting operational security data into risk dashboards, treatment plans and board-ready recommendations.
Delivery combines instructor-led analysis with realistic enterprise cases involving site intrusion, insider threat, civil unrest, critical supplier disruption and crisis escalation. Teams use structured risk assessment templates and BowTieXP to analyse a selected scenario, test controls and identify improvement actions. Each participant leaves with an enterprise security risk management pack: a security risk profile, bow-tie model, control assurance plan, executive dashboard outline and 90-day implementation roadmap for adaptation in their own organisation.
Course objectives
By the end of this course, participants will be able to:
- Design an enterprise security risk governance model with defined accountabilities, escalation routes and decision rights
- Conduct structured threat, vulnerability and consequence assessments using ISO 31010 techniques
- Develop security risk scenarios that connect threats, assets, vulnerabilities, controls and business impacts
- Construct bow-tie analyses to identify preventive controls, recovery controls and control degradation factors
- Evaluate control effectiveness through assurance testing, performance indicators and residual-risk ratings
- Create a prioritised security risk register with risk owners, treatment actions, due dates and escalation criteria
- Produce executive security risk dashboards that communicate exposure, trends, decisions and investment priorities
- Build a 90-day security risk improvement roadmap linked to enterprise risk appetite and business continuity objectives
Benefits of attending
For you
- Gain a board-facing method for explaining security exposure in enterprise-risk and financial-impact terms
- Build confidence using bow-tie analysis to challenge weak or assumed security controls
- Develop evidence for senior security, resilience and integrated-risk leadership roles
- Create a reusable security risk reporting structure for executive committees and risk owners
- Strengthen credibility when proposing security investment, outsourced-service changes or control redesign
For your organisation
- Establish a more consistent method for comparing security risks across sites, functions and third parties
- Improve prioritisation of security expenditure by linking treatments to risk appetite and residual exposure
- Reduce control failure risk through clearer assurance testing, ownership and escalation thresholds
- Provide executives with decision-ready security dashboards instead of isolated incident statistics
- Connect security, business continuity, HSE and enterprise-risk teams through shared risk scenarios and terminology
Target competencies
Who should attend
- Corporate Security Directors — who must align protective security programmes with enterprise risk and executive governance
- Security Risk Managers — who need repeatable methods for assessing, treating and reporting security exposure
- HSE and Integrated Risk Leaders — who oversee connected people, site, operational and business-continuity risks
- Business Continuity Managers — who must coordinate security incidents, crisis escalation and recovery priorities
- Regional Security Managers — who need to justify control improvements across sites, countries and operating environments
- Internal Audit and Risk Assurance Managers — who review security controls and require evidence-based assurance approaches
Requirements and prerequisites
Participants should have practical experience in corporate security, HSE risk, business continuity, facilities protection, emergency management or enterprise risk management. They should already understand basic risk concepts, including likelihood, consequence, inherent risk, residual risk, risk treatment and control ownership. Familiarity with incident reporting, risk registers and security procedures is expected. Participants should be comfortable reviewing spreadsheets and management reports. Prior use of BowTieXP is helpful but not required; the course introduces the required functions. No programming, specialist intelligence-analysis qualification or prior ISO lead-auditor credential is required.
Training methodology
The course uses short instructor-led briefings followed by applied analysis of enterprise security scenarios. Participants work individually and in small groups to define risk appetite, assess threats and vulnerabilities, model critical scenarios in BowTieXP, test controls and prepare executive reporting. Case material includes facility intrusion, insider threat, supplier compromise and civil disturbance, requiring participants to make trade-offs under realistic operational constraints. Facilitated peer review challenges assumptions and strengthens proposed treatments. The final session converts course outputs into a practical 90-day implementation plan for each participant’s workplace.
Course outline
Day 1: Enterprise Security Risk Governance
- Security management within the enterprise risk management framework
- ISO 31000 principles, framework and risk-management process
- Security risk appetite, tolerance statements and escalation thresholds
- Risk governance roles using the three-lines model
- Security risk taxonomy for people, sites, assets, information and supply chains
- Linking security objectives to business continuity and strategic objectives
- Designing risk ownership, committee reporting and decision-rights matrices
Workshop: Participants map their organisation’s current security governance structure and produce a draft RACI and escalation pathway for one material security risk.
Day 2: Threat, Vulnerability and Scenario Assessment
- Threat intelligence requirements and source evaluation
- Asset criticality assessment and consequence definition
- Vulnerability assessment for facilities, personnel, processes and suppliers
- ISO 31010 techniques for structured security risk assessment
- Scenario-based analysis of malicious, accidental and disruptive events
- Likelihood calibration, impact scoring and uncertainty recording
- Security risk-register design and residual-risk rating criteria
Workshop: Using a critical-site disruption case, participants produce a scored risk scenario, supporting assumptions log and security risk-register entry.
Day 3: Bow-Tie Analysis and Control Assurance
- Bow-tie structure: threats, top events, consequences and controls
- Identifying preventive controls and recovery controls
- Control effectiveness, availability, reliability and suitability tests
- Control degradation factors and escalation-factor controls
- BowTieXP model construction and barrier visualisation
- Assurance activities, evidence sources and control-testing schedules
- Defining key control indicators and key risk indicators
Workshop: Participants build a BowTieXP model for an insider-threat or unauthorised-access scenario and produce a control assurance test plan.
Day 4: Treatment, Resilience and Executive Decisions
- Selecting risk treatment options: avoid, reduce, transfer, accept and prepare
- Cost-benefit and risk-reduction analysis for security investments
- Third-party security due diligence and contractual control requirements
- Incident classification, notification thresholds and executive escalation
- Integrating ISO 22301 business continuity objectives with security planning
- Crisis-management decision structures and incident command interfaces
- Developing treatment plans with owners, milestones and assurance measures
Workshop: Teams prepare a prioritised security treatment plan and investment recommendation for a multi-site disruption and supplier-failure case.
Day 5: Security Risk Reporting and Implementation
- Board and executive reporting requirements for security risk
- Security risk-dashboard measures, trend indicators and heat-map limitations
- Writing decision-focused risk narratives and management recommendations
- Presenting uncertainty, control gaps and residual exposure credibly
- Risk acceptance documentation and delegated-authority requirements
- Designing a 90-day security risk improvement roadmap
- Measuring programme maturity and continuous-improvement outcomes
Workshop: Participants present an executive security risk pack containing a risk profile, bow-tie summary, dashboard outline and 90-day implementation roadmap.
Tools & standards covered
ISO 31000:2018, ISO 31010:2019, ISO 22301:2019, BowTieXP
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Dar es Salaam · USD 3,500 -
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Nairobi · USD 3,000 -
12 – 16 Oct 2026Book
Kigali · USD 3,500 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Kigali · USD 3,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Security Management
ASIS Physical Asset Protection Standard Implementation Training Course
Physical asset protection programmes often develop as disconnected projects: a guard contract is renewed, access control is upgraded, CCTV c…
ISO 18788 Security Operations Management System Training Course
Private security operations face heightened scrutiny where services involve guarding, protective security, patrols, access control, secure t…
Crime Prevention Through Environmental Design for Facility Security Training Course
Facilities can be secure on paper yet remain vulnerable because entrances are poorly observed, boundaries are ambiguous, public and staff ro…
ASIS Enterprise Security Risk Management Implementation Training Course
Security teams are increasingly expected to show how physical security, protective services, investigations, travel security and resilience …