Security Management for Oil and Gas Facilities Training Course

5 days Security Management Certificate on completion
Course codeSD-SM-006
Duration5 days
LevelFoundation to Intermediate
CategorySecurity Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Oil and gas facilities face security exposures that can interrupt production, endanger personnel, damage critical assets and create regulatory, environmental and reputational consequences. Security managers must protect sites ranging from remote well pads, pipelines and terminals to refineries, LNG plants and offshore support bases, while maintaining access for employees, contractors, drivers and emergency responders. This requires more than guards and gates: it requires a risk-based security management system that connects threat intelligence, physical protection, control-room response, contractor controls and business continuity.

This course teaches participants how to assess and manage security risk across the oil and gas asset lifecycle. Participants learn to define credible threat scenarios; conduct facility security risk assessments using API RP 780 principles; identify critical assets and vulnerabilities; select proportionate protective measures; and develop facility security plans aligned with API RP 781 and ISO 28000. The programme covers perimeter protection, access control, visitor and vehicle management, surveillance, patrols, incident command, security investigation, crisis communication and the interface between physical security, process safety and cyber security.

Training is delivered through instructor-led technical sessions, facilitated risk workshops and realistic oil and gas cases involving pipeline intrusion, terminal protest activity, theft, insider threat and suspicious-device incidents. Participants work with risk registers, security survey checklists, bow-tie diagrams, incident reporting forms and response escalation matrices. Each participant leaves with a practical Facility Security Management Improvement Plan, including a prioritised risk register, proposed controls, ownership actions and implementation measures that can be adapted for their own site.

The course is suited to professionals with responsibility for facility security, HSE, operations, emergency response, asset integrity or contractor management. It provides a foundation for newer security practitioners while giving experienced operational personnel a structured method for improving site-level security decisions.

Course objectives

By the end of this course, participants will be able to:

  • Conduct a facility security risk assessment using asset, threat, vulnerability and consequence criteria based on API RP 780 principles
  • Develop a security risk register with scored scenarios, existing controls, residual-risk ratings and accountable action owners
  • Apply criticality analysis to identify high-consequence assets, security-sensitive areas and essential operational dependencies
  • Design layered physical-security controls for perimeter, access, surveillance, lighting, patrol and alarm-response arrangements
  • Produce a facility security plan structure aligned with API RP 781, including roles, procedures, contact lists and review controls
  • Create access-control and contractor-screening procedures for personnel, vehicles, visitors, deliveries and temporary workforces
  • Use bow-tie analysis to map preventive barriers, mitigative barriers and escalation factors for a selected security scenario
  • Prepare an incident escalation and post-incident review process with reporting thresholds, evidence controls and corrective actions

Benefits of attending

For you

  • Build a defensible method for explaining why a security control is necessary, proportionate and prioritised
  • Gain practical experience producing facility security risk registers and improvement actions for operating assets
  • Strengthen credibility when working with operations, HSE, guard-force providers, contractors and public security agencies
  • Improve readiness to lead or support security assessments, drills, incident reviews and management briefings
  • Develop evidence-based capability relevant to security, HSE assurance, facility management and emergency-management roles

For your organisation

  • Creates a consistent risk-based approach for assessing threats across facilities, pipelines, terminals and support locations
  • Improves the quality of security plans, access procedures, escalation arrangements and corrective-action tracking
  • Reduces exposure to theft, intrusion, sabotage, insider activity and disruptive unauthorised access through layered controls
  • Strengthens coordination between security, operations, HSE, emergency response and contracted security providers
  • Provides site-specific improvement plans that management can use to prioritise security investment and assurance activity

Target competencies

Security risk assessmentFacility security planningThreat scenario analysisLayered protection designAccess control managementIncident escalation planning

Who should attend

  • Security Managers and Supervisors — who must establish, operate or improve security arrangements at oil and gas assets
  • HSE Managers and Advisors — who need to integrate security threats with site risk management, emergency preparedness and assurance
  • Operations Managers and Shift Supervisors — who make operational decisions during access disruptions, threats and security incidents
  • Facility, Terminal and Pipeline Managers — who are accountable for protecting critical infrastructure, personnel and production continuity
  • Emergency Response and Crisis Management Personnel — who coordinate site actions and external-agency liaison during security events
  • Contractor and Logistics Managers — who control workforce, vehicle, delivery and supplier access to operational locations

Requirements and prerequisites

This is a foundation-to-intermediate course. Participants should understand basic oil and gas facility operations, including the purpose of production, processing, storage, pipeline or terminal assets, and should be familiar with their organisation’s incident-reporting and emergency-response arrangements. Experience in security, HSE, operations, maintenance, logistics or contractor management is useful but not essential. Participants should be comfortable reading site plans, procedures and risk registers. No prior qualification in corporate security, law enforcement, cybersecurity, API standards or BowTieXP is required. Complete beginners should expect an applied introduction to security risk terminology before progressing to site-planning exercises.

Training methodology

The programme combines focused instructor-led sessions with facilitated application to oil and gas operating scenarios. Participants use site-layout extracts, security survey checklists, risk matrices and bow-tie worksheets to assess realistic threats such as pipeline interference, terminal intrusion, cargo theft and insider activity. Small groups test control options against operational constraints, contractor movements and emergency-response requirements. Daily debriefs connect decisions to API RP 780, API RP 781 and ISO 28000 principles. On the final day, participants convert their work into a site-specific security improvement plan for workplace use.

Course outline

Day 1: Oil and gas security risk foundations

  • Security threats across upstream, midstream, downstream and offshore-support operations
  • Critical asset identification and operational dependency mapping
  • Distinguishing security hazards from process-safety and occupational-safety hazards
  • Security management system elements and governance accountabilities
  • Threat, vulnerability, consequence and likelihood terminology
  • API RP 780 security risk assessment methodology
  • Security risk appetite, tolerability criteria and risk-ranking matrices

Workshop: Participants map critical assets and draft three credible threat scenarios for a selected oil and gas facility.

Day 2: Facility security risk assessment and treatment

  • Security survey planning and site-walkdown evidence collection
  • Threat-source profiling including criminal, activist, insider and hostile-actor scenarios
  • Vulnerability assessment of boundaries, buildings, control rooms and utility systems
  • Consequence analysis for personnel, production, environmental and reputational impacts
  • Risk-register construction and residual-risk evaluation
  • Bow-tie analysis for security barrier management
  • Control selection using prevention, detection, delay, response and recovery layers

Workshop: Teams complete a scored security risk register and bow-tie diagram for an attempted intrusion at a pipeline valve station.

Day 3: Physical protection and access management

  • Defence-in-depth design for oil and gas facilities
  • Perimeter fencing, gates, lighting and intrusion-detection considerations
  • Electronic access-control system roles, permissions and audit trails
  • Visitor, contractor, driver and delivery screening workflows
  • CCTV coverage design, monitoring priorities and evidential recording
  • Guard-force post orders, patrol patterns and supervisory checks
  • Key control, pass management and security-sensitive area zoning

Workshop: Participants conduct a desktop security survey of a terminal layout and produce a layered-control improvement sketch.

Day 4: Incident response, investigation and resilience

  • Security incident classification and notification thresholds
  • Control-room, operations and security-team response coordination
  • Incident command roles and liaison with police, regulators and port authorities
  • Suspicious package, armed intrusion, protest and theft response procedures
  • Evidence preservation, witness management and security incident reporting
  • Root-cause review and corrective-action management after security events
  • Business continuity interfaces for access disruption and critical asset compromise

Workshop: Groups run a timed incident-command tabletop for a security breach at a product-loading terminal and produce an escalation log.

Day 5: Security plans, assurance and implementation

  • API RP 781 facility security plan structure and content
  • ISO 28000 security management system alignment
  • Security roles, competence requirements and contracted-service oversight
  • Security performance indicators, inspections and management reporting
  • Audit trails, document control and periodic plan review
  • Security drills, exercises and lessons-learned processes
  • Prioritising capital, procedural and training actions in a security improvement roadmap

Workshop: Each participant presents a Facility Security Management Improvement Plan containing priority risks, control actions, owners, measures and review dates.

Tools & standards covered

API RP 780, API RP 781, ISO 28000, BowTieXP

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course starts with security risk concepts and oil and gas threat scenarios before moving into assessment and planning methods. Participants with operational, HSE, facilities or contractor-management experience will be able to relate the exercises directly to their work.

A laptop is recommended for completing risk-register and improvement-plan templates, particularly for live online delivery. No licensed security software is required; workshop materials can be completed using provided templates, while BowTieXP is demonstrated as an optional analysis tool.

Yes. The methods apply across upstream installations, gas-processing plants, pipelines, tank farms, terminals, refineries and support facilities. Cases are selected to show how threat exposure and controls differ by asset type.

This course is centred on oil and gas operational assets, production continuity, process-safety interfaces and critical-infrastructure consequences. It teaches facility risk assessment, security planning and assurance rather than guard tactics, close protection or generic crime prevention.

You can use the security survey checklist, risk-register structure, bow-tie worksheet and escalation matrix to review a specific site or operating area. The final improvement plan is designed to support a management discussion on priorities, ownership and investment decisions.

Participants leave with completed or partially completed templates for a facility security risk register, bow-tie analysis, security survey and incident escalation process. They also receive a tailored Facility Security Management Improvement Plan for adapting to their own asset.

Upcoming sessions

  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 28 Sep – 02 Oct 2026
    Nairobi · USD 3,000
    Book
  • 28 Sep – 02 Oct 2026
    Mombasa · USD 3,200
    Book
  • 12 – 16 Oct 2026
    Nairobi · USD 3,000
    Book
  • 12 – 16 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Cape Town · USD 4,200
    Book
  • 02 – 06 Nov 2026
    Dubai · USD 4,500
    Book
  • 16 – 20 Nov 2026
    Live Online · USD 1,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Security Management

5 Days Certificate

Security Management Fundamentals for Organizational Resilience Training Course

Security failures rarely remain isolated. A perimeter breach, protest, theft, insider threat, cyber-enabled disruption, severe weather event…

5 Days Certificate

ISO 18788 Security Operations Management System Training Course

Private security operations face heightened scrutiny where services involve guarding, protective security, patrols, access control, secure t…

5 Days Certificate

Advanced Security Management for Threat Intelligence Integration Training Course

Security managers in high-risk, regulated and operationally complex environments need more than incident reports and periodic risk registers…

5 Days Certificate

Milestone XProtect for Security Control Room Operations Training Course

Security control room operators must turn high volumes of camera alarms, live video, access events and operator requests into timely, defens…