Advanced Security Management for Threat Intelligence Integration Training Course

5 days Security Management Certificate on completion
Course codeSD-SM-012
Duration5 days
LevelIntermediate to Advanced
CategorySecurity Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Security managers in high-risk, regulated and operationally complex environments need more than incident reports and periodic risk registers. They must turn fragmented intelligence—security alerts, contractor concerns, regional instability, access-control exceptions, HSE observations, social media indicators and law-enforcement notices—into defensible decisions about people, sites, assets and continuity. This course addresses the gap between collecting threat information and embedding it in routine security management, enterprise risk governance and operational controls.

Participants learn to build a threat-intelligence operating model for corporate, industrial and HSE-sensitive settings. They assess intelligence requirements, evaluate source reliability, apply structured analytic techniques, map threats to vulnerable assets and controls, and produce risk-based intelligence products for different decision-makers. The programme covers intelligence-led security risk assessment, indicator and warning frameworks, collection plans, escalation thresholds, information-sharing protocols, protective-security measures and links to ISO 31000, ISO 45001 and business continuity arrangements.

Instruction combines expert-led briefings with practical analysis of realistic site-security, insider-threat, civil-unrest and contractor-risk scenarios. Participants work with intelligence logs, source-evaluation matrices, threat registers and decision brief templates, using MISP concepts, STIX/TAXII structures and visual link analysis. They leave with a completed Threat Intelligence Integration Plan: a usable package containing intelligence requirements, collection priorities, triage rules, reporting templates, governance roles, escalation pathways and a 90-day implementation roadmap.

The course is designed for experienced security, HSE, resilience and risk professionals who already influence protective controls or incident decisions and now need to establish a repeatable intelligence-to-action process across sites, functions or regions.

Course objectives

By the end of this course, participants will be able to:

  • Design a threat intelligence operating model aligned to security governance, HSE risk controls and business continuity arrangements
  • Define priority intelligence requirements and collection plans for site, personnel, contractor and geopolitical threats
  • Evaluate source reliability and information credibility using structured source-assessment matrices
  • Apply ACH, indicator analysis and link analysis to test competing threat hypotheses
  • Integrate intelligence findings into a security risk register using likelihood, consequence, vulnerability and control-effectiveness criteria
  • Build threat indicators, warning thresholds and escalation triggers for protective-security decision-making
  • Produce executive intelligence briefs, operational alerts and decision logs tailored to defined stakeholder groups
  • Create a 90-day Threat Intelligence Integration Plan with governance roles, workflows, measures and implementation milestones

Benefits of attending

For you

  • Gain a repeatable method for turning scattered threat reporting into risk-based security recommendations
  • Build credibility with executives by presenting concise intelligence assessments with stated confidence and decision implications
  • Develop advanced analytical judgement through competing-hypothesis, indicator and source-reliability techniques
  • Leave with a portfolio-quality Threat Intelligence Integration Plan applicable to a current site, region or business unit
  • Strengthen readiness for senior security, resilience and enterprise-risk roles requiring intelligence-led governance

For your organisation

  • Establish clearer intelligence requirements so collection effort focuses on threats that could affect people, operations and assets
  • Improve early warning of insider, protest, criminal, geopolitical and contractor-related risks through defined indicators and thresholds
  • Reduce inconsistent escalation by introducing documented triage, reporting and decision-accountability workflows
  • Link threat assessments to existing HSE, security risk-register and business-continuity controls rather than creating a parallel process
  • Provide leadership with decision-ready briefs that identify confidence levels, control gaps, response options and ownership

Target competencies

Threat intelligence planningSource reliability assessmentStructured threat analysisIntelligence-led risk assessmentWarning indicator designSecurity governance integration

Who should attend

  • Security Managers — who must convert emerging threats into proportionate site and personnel protection decisions
  • Corporate Security Directors — who need a consistent intelligence-led operating model across multiple locations or regions
  • HSE Managers — who must connect security threats with workforce safety, emergency preparedness and operational risk controls
  • Business Continuity and Resilience Managers — who require earlier warning indicators to activate continuity and crisis arrangements
  • Risk Managers — who need defensible methods for incorporating threat intelligence into enterprise and operational risk registers
  • Security Operations Centre Analysts — who need to turn alerts and external reporting into actionable assessments for business leaders

Requirements and prerequisites

Participants should have practical experience in security operations, HSE risk management, business continuity, investigations or corporate risk. They should already understand basic risk-assessment concepts such as likelihood, consequence, controls and residual risk, and be comfortable reading incident reports, security procedures and risk registers. Familiarity with access control, incident escalation or emergency response is useful. No programming, cyber-forensics qualification or prior use of MISP, STIX/TAXII or i2 Analyst’s Notebook is required; the course explains the relevant tool concepts and uses guided templates rather than requiring technical configuration.

Training methodology

The five days alternate between instructor-led security intelligence frameworks and practical workshops built around a multi-site operating scenario. Participants assess raw reports, score sources, construct link charts, test threat hypotheses and translate findings into risk-register entries and protective-control decisions. Small groups produce operational alerts and executive briefs for different audiences, then challenge each other’s assumptions in facilitated review sessions. The final day is an application lab in which each participant assembles a Threat Intelligence Integration Plan and receives instructor feedback on governance, feasibility and measures.

Course outline

Day 1: Threat intelligence governance for security management

  • Threat intelligence lifecycle in corporate and HSE-sensitive operations
  • Strategic, operational and tactical intelligence product definitions
  • Priority intelligence requirements and key intelligence questions
  • Asset criticality, exposure and vulnerability profiling
  • Security governance roles using RACI decision matrices
  • ISO 31000 and ISO 45001 integration points
  • Intelligence ethics, privacy boundaries and need-to-know handling

Workshop: Participants map a selected site or business unit, identify critical assets and stakeholders, and produce a prioritised set of intelligence requirements.

Day 2: Collection, validation and structured analysis

  • Collection planning across internal, external and partner sources
  • Human reporting, incident data and open-source intelligence collection
  • Source reliability and information credibility scoring
  • STIX 2.1 objects and TAXII information-exchange concepts
  • MISP event, attribute and tag structures
  • Analysis of Competing Hypotheses methodology
  • Link analysis for actors, events, locations and relationships

Workshop: Using a simulated stream of site, contractor and external reports, participants create a source-evaluated intelligence log and test competing threat hypotheses.

Day 3: Intelligence-led security risk assessment

  • Threat actor capability, intent and opportunity assessment
  • Vulnerability analysis of facilities, people and critical processes
  • Threat-to-control mapping and control-effectiveness testing
  • Likelihood and consequence calibration using intelligence evidence
  • Risk-register integration and residual-risk statements
  • Indicator and warning framework design
  • Scenario analysis for civil unrest, insider threat and targeted crime

Workshop: Teams convert an intelligence assessment into a security risk-register entry, control-gap analysis and set of measurable warning indicators.

Day 4: Reporting, escalation and protective action

  • Operational alert formats and time-critical dissemination rules
  • Executive intelligence brief structure and confidence statements
  • Escalation thresholds and decision-authority matrices
  • Protective-security response options and proportionality tests
  • Integration with crisis management and business continuity activation
  • Information-sharing agreements and data-retention controls
  • Lessons-learned loops and intelligence performance measures

Workshop: Participants prepare an executive brief and an operational security alert for an escalating regional disruption, then defend their recommended actions in a decision meeting.

Day 5: Implementation planning and assurance

  • Threat intelligence maturity assessment criteria
  • Target operating model design for central and site teams
  • Workflow design from collection through closure
  • Metrics for timeliness, relevance, accuracy and action uptake
  • MISP and i2 Analyst’s Notebook use-case selection
  • Assurance reviews, audit trails and governance reporting
  • Ninety-day implementation roadmap and stakeholder engagement

Workshop: Each participant completes and presents a Threat Intelligence Integration Plan containing requirements, workflows, reporting templates, governance controls and a 90-day roadmap.

Tools & standards covered

MISP, i2 Analyst's Notebook, STIX 2.1, ISO 31000

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

This is an intermediate-to-advanced course for professionals who already work with security incidents, risk assessments, HSE controls, resilience planning or protective-security decisions. You should understand basic likelihood-and-consequence risk assessment, but you do not need prior intelligence-analysis certification.

A laptop is recommended for working on templates, case materials and your final implementation plan. No software licence is required: MISP, STIX/TAXII and i2 Analyst’s Notebook are taught through guided examples, workflows and structured exercises rather than live system administration.

No. It focuses on integrating intelligence into corporate, site and HSE-sensitive security management, including insider risk, targeted crime, civil unrest, contractor concerns, supply disruption and regional instability. Cyber intelligence is discussed where it affects physical operations, personnel safety or continuity decisions.

A risk assessment course concentrates on identifying hazards, evaluating risks and selecting controls. This course concentrates on the upstream intelligence process: defining what to collect, validating information, analysing indicators, issuing warnings and feeding current threat evidence into those risk decisions.

You can use the collection-plan, source-scoring, intelligence-brief and escalation templates with existing incident, access-control, contractor and external-reporting processes. The final 90-day roadmap is designed to help you sequence implementation without waiting for a major technology programme.

You will leave with a completed Threat Intelligence Integration Plan tailored to a real or representative operating context. It includes priority intelligence requirements, collection sources, triage rules, warning indicators, reporting formats, governance roles and implementation milestones.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Security Management

5 Days Certificate

Crime Prevention Through Environmental Design for Facility Security Training Course

Facilities can be secure on paper yet remain vulnerable because entrances are poorly observed, boundaries are ambiguous, public and staff ro…

5 Days Certificate

Security Management Fundamentals for Organizational Resilience Training Course

Security failures rarely remain isolated. A perimeter breach, protest, theft, insider threat, cyber-enabled disruption, severe weather event…

5 Days Certificate

Security Management Fundamentals for Workplace Protection Training Course

Workplace security managers must protect people, premises, assets and operations while balancing access, service continuity, privacy, budget…

5 Days Certificate

Avigilon Control Center Video Security Management Training Course

Security teams need more than live camera views to manage incidents, protect people, and meet evidential, privacy, and operational requireme…