Advanced Security Management for Threat Intelligence Integration Training Course
| Course code | SD-SM-012 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security managers in high-risk, regulated and operationally complex environments need more than incident reports and periodic risk registers. They must turn fragmented intelligence—security alerts, contractor concerns, regional instability, access-control exceptions, HSE observations, social media indicators and law-enforcement notices—into defensible decisions about people, sites, assets and continuity. This course addresses the gap between collecting threat information and embedding it in routine security management, enterprise risk governance and operational controls.
Participants learn to build a threat-intelligence operating model for corporate, industrial and HSE-sensitive settings. They assess intelligence requirements, evaluate source reliability, apply structured analytic techniques, map threats to vulnerable assets and controls, and produce risk-based intelligence products for different decision-makers. The programme covers intelligence-led security risk assessment, indicator and warning frameworks, collection plans, escalation thresholds, information-sharing protocols, protective-security measures and links to ISO 31000, ISO 45001 and business continuity arrangements.
Instruction combines expert-led briefings with practical analysis of realistic site-security, insider-threat, civil-unrest and contractor-risk scenarios. Participants work with intelligence logs, source-evaluation matrices, threat registers and decision brief templates, using MISP concepts, STIX/TAXII structures and visual link analysis. They leave with a completed Threat Intelligence Integration Plan: a usable package containing intelligence requirements, collection priorities, triage rules, reporting templates, governance roles, escalation pathways and a 90-day implementation roadmap.
The course is designed for experienced security, HSE, resilience and risk professionals who already influence protective controls or incident decisions and now need to establish a repeatable intelligence-to-action process across sites, functions or regions.
Course objectives
By the end of this course, participants will be able to:
- Design a threat intelligence operating model aligned to security governance, HSE risk controls and business continuity arrangements
- Define priority intelligence requirements and collection plans for site, personnel, contractor and geopolitical threats
- Evaluate source reliability and information credibility using structured source-assessment matrices
- Apply ACH, indicator analysis and link analysis to test competing threat hypotheses
- Integrate intelligence findings into a security risk register using likelihood, consequence, vulnerability and control-effectiveness criteria
- Build threat indicators, warning thresholds and escalation triggers for protective-security decision-making
- Produce executive intelligence briefs, operational alerts and decision logs tailored to defined stakeholder groups
- Create a 90-day Threat Intelligence Integration Plan with governance roles, workflows, measures and implementation milestones
Benefits of attending
For you
- Gain a repeatable method for turning scattered threat reporting into risk-based security recommendations
- Build credibility with executives by presenting concise intelligence assessments with stated confidence and decision implications
- Develop advanced analytical judgement through competing-hypothesis, indicator and source-reliability techniques
- Leave with a portfolio-quality Threat Intelligence Integration Plan applicable to a current site, region or business unit
- Strengthen readiness for senior security, resilience and enterprise-risk roles requiring intelligence-led governance
For your organisation
- Establish clearer intelligence requirements so collection effort focuses on threats that could affect people, operations and assets
- Improve early warning of insider, protest, criminal, geopolitical and contractor-related risks through defined indicators and thresholds
- Reduce inconsistent escalation by introducing documented triage, reporting and decision-accountability workflows
- Link threat assessments to existing HSE, security risk-register and business-continuity controls rather than creating a parallel process
- Provide leadership with decision-ready briefs that identify confidence levels, control gaps, response options and ownership
Target competencies
Who should attend
- Security Managers — who must convert emerging threats into proportionate site and personnel protection decisions
- Corporate Security Directors — who need a consistent intelligence-led operating model across multiple locations or regions
- HSE Managers — who must connect security threats with workforce safety, emergency preparedness and operational risk controls
- Business Continuity and Resilience Managers — who require earlier warning indicators to activate continuity and crisis arrangements
- Risk Managers — who need defensible methods for incorporating threat intelligence into enterprise and operational risk registers
- Security Operations Centre Analysts — who need to turn alerts and external reporting into actionable assessments for business leaders
Requirements and prerequisites
Participants should have practical experience in security operations, HSE risk management, business continuity, investigations or corporate risk. They should already understand basic risk-assessment concepts such as likelihood, consequence, controls and residual risk, and be comfortable reading incident reports, security procedures and risk registers. Familiarity with access control, incident escalation or emergency response is useful. No programming, cyber-forensics qualification or prior use of MISP, STIX/TAXII or i2 Analyst’s Notebook is required; the course explains the relevant tool concepts and uses guided templates rather than requiring technical configuration.
Training methodology
The five days alternate between instructor-led security intelligence frameworks and practical workshops built around a multi-site operating scenario. Participants assess raw reports, score sources, construct link charts, test threat hypotheses and translate findings into risk-register entries and protective-control decisions. Small groups produce operational alerts and executive briefs for different audiences, then challenge each other’s assumptions in facilitated review sessions. The final day is an application lab in which each participant assembles a Threat Intelligence Integration Plan and receives instructor feedback on governance, feasibility and measures.
Course outline
Day 1: Threat intelligence governance for security management
- Threat intelligence lifecycle in corporate and HSE-sensitive operations
- Strategic, operational and tactical intelligence product definitions
- Priority intelligence requirements and key intelligence questions
- Asset criticality, exposure and vulnerability profiling
- Security governance roles using RACI decision matrices
- ISO 31000 and ISO 45001 integration points
- Intelligence ethics, privacy boundaries and need-to-know handling
Workshop: Participants map a selected site or business unit, identify critical assets and stakeholders, and produce a prioritised set of intelligence requirements.
Day 2: Collection, validation and structured analysis
- Collection planning across internal, external and partner sources
- Human reporting, incident data and open-source intelligence collection
- Source reliability and information credibility scoring
- STIX 2.1 objects and TAXII information-exchange concepts
- MISP event, attribute and tag structures
- Analysis of Competing Hypotheses methodology
- Link analysis for actors, events, locations and relationships
Workshop: Using a simulated stream of site, contractor and external reports, participants create a source-evaluated intelligence log and test competing threat hypotheses.
Day 3: Intelligence-led security risk assessment
- Threat actor capability, intent and opportunity assessment
- Vulnerability analysis of facilities, people and critical processes
- Threat-to-control mapping and control-effectiveness testing
- Likelihood and consequence calibration using intelligence evidence
- Risk-register integration and residual-risk statements
- Indicator and warning framework design
- Scenario analysis for civil unrest, insider threat and targeted crime
Workshop: Teams convert an intelligence assessment into a security risk-register entry, control-gap analysis and set of measurable warning indicators.
Day 4: Reporting, escalation and protective action
- Operational alert formats and time-critical dissemination rules
- Executive intelligence brief structure and confidence statements
- Escalation thresholds and decision-authority matrices
- Protective-security response options and proportionality tests
- Integration with crisis management and business continuity activation
- Information-sharing agreements and data-retention controls
- Lessons-learned loops and intelligence performance measures
Workshop: Participants prepare an executive brief and an operational security alert for an escalating regional disruption, then defend their recommended actions in a decision meeting.
Day 5: Implementation planning and assurance
- Threat intelligence maturity assessment criteria
- Target operating model design for central and site teams
- Workflow design from collection through closure
- Metrics for timeliness, relevance, accuracy and action uptake
- MISP and i2 Analyst’s Notebook use-case selection
- Assurance reviews, audit trails and governance reporting
- Ninety-day implementation roadmap and stakeholder engagement
Workshop: Each participant completes and presents a Threat Intelligence Integration Plan containing requirements, workflows, reporting templates, governance controls and a 90-day roadmap.
Tools & standards covered
MISP, i2 Analyst's Notebook, STIX 2.1, ISO 31000
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Security Management
Crime Prevention Through Environmental Design for Facility Security Training Course
Facilities can be secure on paper yet remain vulnerable because entrances are poorly observed, boundaries are ambiguous, public and staff ro…
Security Management Fundamentals for Organizational Resilience Training Course
Security failures rarely remain isolated. A perimeter breach, protest, theft, insider threat, cyber-enabled disruption, severe weather event…
Security Management Fundamentals for Workplace Protection Training Course
Workplace security managers must protect people, premises, assets and operations while balancing access, service continuity, privacy, budget…
Avigilon Control Center Video Security Management Training Course
Security teams need more than live camera views to manage incidents, protect people, and meet evidential, privacy, and operational requireme…