Security Management for Oil and Gas Facilities Training Course
| Course code | SD-SM-006 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Oil and gas facilities face security exposures that can interrupt production, endanger personnel, damage critical assets and create regulatory, environmental and reputational consequences. Security managers must protect sites ranging from remote well pads, pipelines and terminals to refineries, LNG plants and offshore support bases, while maintaining access for employees, contractors, drivers and emergency responders. This requires more than guards and gates: it requires a risk-based security management system that connects threat intelligence, physical protection, control-room response, contractor controls and business continuity.
This course teaches participants how to assess and manage security risk across the oil and gas asset lifecycle. Participants learn to define credible threat scenarios; conduct facility security risk assessments using API RP 780 principles; identify critical assets and vulnerabilities; select proportionate protective measures; and develop facility security plans aligned with API RP 781 and ISO 28000. The programme covers perimeter protection, access control, visitor and vehicle management, surveillance, patrols, incident command, security investigation, crisis communication and the interface between physical security, process safety and cyber security.
Training is delivered through instructor-led technical sessions, facilitated risk workshops and realistic oil and gas cases involving pipeline intrusion, terminal protest activity, theft, insider threat and suspicious-device incidents. Participants work with risk registers, security survey checklists, bow-tie diagrams, incident reporting forms and response escalation matrices. Each participant leaves with a practical Facility Security Management Improvement Plan, including a prioritised risk register, proposed controls, ownership actions and implementation measures that can be adapted for their own site.
The course is suited to professionals with responsibility for facility security, HSE, operations, emergency response, asset integrity or contractor management. It provides a foundation for newer security practitioners while giving experienced operational personnel a structured method for improving site-level security decisions.
Course objectives
By the end of this course, participants will be able to:
- Conduct a facility security risk assessment using asset, threat, vulnerability and consequence criteria based on API RP 780 principles
- Develop a security risk register with scored scenarios, existing controls, residual-risk ratings and accountable action owners
- Apply criticality analysis to identify high-consequence assets, security-sensitive areas and essential operational dependencies
- Design layered physical-security controls for perimeter, access, surveillance, lighting, patrol and alarm-response arrangements
- Produce a facility security plan structure aligned with API RP 781, including roles, procedures, contact lists and review controls
- Create access-control and contractor-screening procedures for personnel, vehicles, visitors, deliveries and temporary workforces
- Use bow-tie analysis to map preventive barriers, mitigative barriers and escalation factors for a selected security scenario
- Prepare an incident escalation and post-incident review process with reporting thresholds, evidence controls and corrective actions
Benefits of attending
For you
- Build a defensible method for explaining why a security control is necessary, proportionate and prioritised
- Gain practical experience producing facility security risk registers and improvement actions for operating assets
- Strengthen credibility when working with operations, HSE, guard-force providers, contractors and public security agencies
- Improve readiness to lead or support security assessments, drills, incident reviews and management briefings
- Develop evidence-based capability relevant to security, HSE assurance, facility management and emergency-management roles
For your organisation
- Creates a consistent risk-based approach for assessing threats across facilities, pipelines, terminals and support locations
- Improves the quality of security plans, access procedures, escalation arrangements and corrective-action tracking
- Reduces exposure to theft, intrusion, sabotage, insider activity and disruptive unauthorised access through layered controls
- Strengthens coordination between security, operations, HSE, emergency response and contracted security providers
- Provides site-specific improvement plans that management can use to prioritise security investment and assurance activity
Target competencies
Who should attend
- Security Managers and Supervisors — who must establish, operate or improve security arrangements at oil and gas assets
- HSE Managers and Advisors — who need to integrate security threats with site risk management, emergency preparedness and assurance
- Operations Managers and Shift Supervisors — who make operational decisions during access disruptions, threats and security incidents
- Facility, Terminal and Pipeline Managers — who are accountable for protecting critical infrastructure, personnel and production continuity
- Emergency Response and Crisis Management Personnel — who coordinate site actions and external-agency liaison during security events
- Contractor and Logistics Managers — who control workforce, vehicle, delivery and supplier access to operational locations
Requirements and prerequisites
This is a foundation-to-intermediate course. Participants should understand basic oil and gas facility operations, including the purpose of production, processing, storage, pipeline or terminal assets, and should be familiar with their organisation’s incident-reporting and emergency-response arrangements. Experience in security, HSE, operations, maintenance, logistics or contractor management is useful but not essential. Participants should be comfortable reading site plans, procedures and risk registers. No prior qualification in corporate security, law enforcement, cybersecurity, API standards or BowTieXP is required. Complete beginners should expect an applied introduction to security risk terminology before progressing to site-planning exercises.
Training methodology
The programme combines focused instructor-led sessions with facilitated application to oil and gas operating scenarios. Participants use site-layout extracts, security survey checklists, risk matrices and bow-tie worksheets to assess realistic threats such as pipeline interference, terminal intrusion, cargo theft and insider activity. Small groups test control options against operational constraints, contractor movements and emergency-response requirements. Daily debriefs connect decisions to API RP 780, API RP 781 and ISO 28000 principles. On the final day, participants convert their work into a site-specific security improvement plan for workplace use.
Course outline
Day 1: Oil and gas security risk foundations
- Security threats across upstream, midstream, downstream and offshore-support operations
- Critical asset identification and operational dependency mapping
- Distinguishing security hazards from process-safety and occupational-safety hazards
- Security management system elements and governance accountabilities
- Threat, vulnerability, consequence and likelihood terminology
- API RP 780 security risk assessment methodology
- Security risk appetite, tolerability criteria and risk-ranking matrices
Workshop: Participants map critical assets and draft three credible threat scenarios for a selected oil and gas facility.
Day 2: Facility security risk assessment and treatment
- Security survey planning and site-walkdown evidence collection
- Threat-source profiling including criminal, activist, insider and hostile-actor scenarios
- Vulnerability assessment of boundaries, buildings, control rooms and utility systems
- Consequence analysis for personnel, production, environmental and reputational impacts
- Risk-register construction and residual-risk evaluation
- Bow-tie analysis for security barrier management
- Control selection using prevention, detection, delay, response and recovery layers
Workshop: Teams complete a scored security risk register and bow-tie diagram for an attempted intrusion at a pipeline valve station.
Day 3: Physical protection and access management
- Defence-in-depth design for oil and gas facilities
- Perimeter fencing, gates, lighting and intrusion-detection considerations
- Electronic access-control system roles, permissions and audit trails
- Visitor, contractor, driver and delivery screening workflows
- CCTV coverage design, monitoring priorities and evidential recording
- Guard-force post orders, patrol patterns and supervisory checks
- Key control, pass management and security-sensitive area zoning
Workshop: Participants conduct a desktop security survey of a terminal layout and produce a layered-control improvement sketch.
Day 4: Incident response, investigation and resilience
- Security incident classification and notification thresholds
- Control-room, operations and security-team response coordination
- Incident command roles and liaison with police, regulators and port authorities
- Suspicious package, armed intrusion, protest and theft response procedures
- Evidence preservation, witness management and security incident reporting
- Root-cause review and corrective-action management after security events
- Business continuity interfaces for access disruption and critical asset compromise
Workshop: Groups run a timed incident-command tabletop for a security breach at a product-loading terminal and produce an escalation log.
Day 5: Security plans, assurance and implementation
- API RP 781 facility security plan structure and content
- ISO 28000 security management system alignment
- Security roles, competence requirements and contracted-service oversight
- Security performance indicators, inspections and management reporting
- Audit trails, document control and periodic plan review
- Security drills, exercises and lessons-learned processes
- Prioritising capital, procedural and training actions in a security improvement roadmap
Workshop: Each participant presents a Facility Security Management Improvement Plan containing priority risks, control actions, owners, measures and review dates.
Tools & standards covered
API RP 780, API RP 781, ISO 28000, BowTieXP
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Mombasa · USD 3,200 -
12 – 16 Oct 2026Book
Nairobi · USD 3,000 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Cape Town · USD 4,200 -
02 – 06 Nov 2026Book
Dubai · USD 4,500 -
16 – 20 Nov 2026Book
Live Online · USD 1,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Security Management
Security Management Fundamentals for Organizational Resilience Training Course
Security failures rarely remain isolated. A perimeter breach, protest, theft, insider threat, cyber-enabled disruption, severe weather event…
ISO 18788 Security Operations Management System Training Course
Private security operations face heightened scrutiny where services involve guarding, protective security, patrols, access control, secure t…
Advanced Security Management for Threat Intelligence Integration Training Course
Security managers in high-risk, regulated and operationally complex environments need more than incident reports and periodic risk registers…
Milestone XProtect for Security Control Room Operations Training Course
Security control room operators must turn high volumes of camera alarms, live video, access events and operator requests into timely, defens…