Security Management Fundamentals for Organizational Resilience Training Course
| Course code | SD-SM-011 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security failures rarely remain isolated. A perimeter breach, protest, theft, insider threat, cyber-enabled disruption, severe weather event or failure of a critical supplier can quickly affect employee safety, site operations, regulatory obligations, customer service and reputation. Security managers and HSE professionals need a structured way to identify credible threats, determine where controls are weak, coordinate response decisions and maintain business operations under pressure. This course addresses the practical gap between security policies on paper and an integrated security management system that supports organizational resilience.
Participants learn to build and operate a risk-based security management approach aligned with ISO 31000, ISO 22301 and relevant ISO 27001 control principles. The course covers threat and vulnerability assessment, asset criticality, security risk registers, Bowtie analysis, physical and personnel security controls, incident command arrangements, crisis communications, business continuity planning and assurance activities. Participants practise translating risk findings into proportionate treatment plans, control owners, performance indicators and review schedules that management teams can use to make defensible investment and response decisions.
Delivery combines instructor-led explanation with realistic site-security and operational-disruption scenarios. Working individually and in small groups, participants assess a simulated organization, map its critical assets and dependencies, develop a security risk register, analyse a priority threat using BowtieXP principles, and test response and recovery arrangements through a tabletop exercise. Each participant leaves with a practical Security Management and Resilience Action Plan containing prioritized risks, control improvements, escalation triggers, assurance measures and a 90-day implementation roadmap for their own workplace.
The course is designed for professionals who already contribute to safety, security, facilities, operations, continuity or risk activities and now need a common framework for managing security as part of organizational resilience. It is equally valuable to managers approving security improvements because it connects recommended controls to business impact, accountable ownership and measurable performance.
Course objectives
By the end of this course, participants will be able to:
- Conduct a structured threat, vulnerability and asset-criticality assessment for an operational site or business function
- Build a security risk register using likelihood, consequence, control effectiveness and residual-risk ratings
- Apply Bowtie analysis to map threat pathways, preventive barriers, recovery barriers and escalation factors
- Select proportionate physical, personnel, information and operational security controls against defined risk scenarios
- Define incident-command roles, decision thresholds and escalation routes for security-related disruptions
- Develop a business continuity response strategy for a security event affecting critical people, assets or suppliers
- Create security performance indicators, control-assurance checks and management review reporting
- Produce a 90-day Security Management and Resilience Action Plan with owners, milestones and resource priorities
Benefits of attending
For you
- Gain a defensible method for converting broad security concerns into prioritized, documented risk treatment actions
- Build confidence facilitating threat and vulnerability discussions with operations, HSE, IT, facilities and senior leaders
- Develop practical evidence for leading security risk-register, continuity or emergency-preparedness improvement work
- Learn to justify security-control investment through asset criticality, residual risk and business-impact reasoning
- Leave with an employer-relevant action plan that can support progression into security, resilience or risk-management responsibilities
For your organisation
- Establish a common language for security, safety, continuity and operational teams assessing disruptive threats
- Improve prioritization of security spending by linking controls to critical assets, credible scenarios and residual risk
- Strengthen incident readiness through clearer command roles, escalation thresholds and communication arrangements
- Reduce avoidable control gaps by testing barriers, ownership and assurance evidence before an incident occurs
- Create an actionable improvement roadmap that management can track through milestones, indicators and review cycles
Target competencies
Who should attend
- Security Managers and Supervisors — who need a repeatable method for prioritizing threats, controls and response readiness
- HSE Managers and Advisors — who must connect security risks with workforce safety, emergency preparedness and operational risk
- Business Continuity and Resilience Managers — who coordinate recovery arrangements for disruptive security incidents
- Facilities and Site Managers — who oversee access control, contractor management, critical assets and site protection
- Operations Managers — who need to maintain service delivery when security events affect people, premises or supply chains
- Risk, Compliance and Internal Audit Professionals — who assess whether security controls are designed, owned and evidenced
Requirements and prerequisites
Participants should have practical familiarity with their organization’s operations, sites, key assets or service processes, and should be able to describe existing incident reporting and emergency arrangements. Experience in security, HSE, facilities, operations, risk or business continuity is helpful; this is a fundamentals course for professionals rather than a technical guard-force or cyber-security qualification. Participants should understand basic risk terms such as hazard, threat, likelihood, consequence and control. No prior certification in ISO 31000, ISO 22301, ISO 27001 or BowtieXP is required, and no specialist security software expertise is assumed.
Training methodology
The instructor uses short, focused teaching blocks to introduce each framework, followed by guided application to a realistic multi-site organization. Participants work with asset inventories, threat scenarios, risk-register templates, Bowtie diagrams, incident logs and continuity-planning worksheets. Facilitated group exercises require teams to challenge assumptions, assign control ownership and defend priorities to a mock management panel. A final tabletop exercise tests decisions during an escalating security disruption. Participants close by adapting course outputs into a 90-day implementation plan for their own function or site.
Course outline
Day 1: Security management and resilience foundations
- Security management system purpose, scope and governance
- Links between security, HSE, business continuity and enterprise risk
- ISO 31000 risk-management principles and process
- ISO 22301 continuity concepts for disruptive incidents
- Security context analysis using internal and external factors
- Asset identification and criticality classification
- Stakeholder, legal and regulatory obligation mapping
Workshop: Participants map the critical assets, stakeholders, dependencies and security-management boundaries for a simulated organization.
Day 2: Threat, vulnerability and risk assessment
- Threat-source identification across people, premises, information and supply chains
- Vulnerability assessment methods for sites and operational processes
- Likelihood, consequence and risk-appetite criteria
- Inherent-risk and residual-risk scoring methods
- Security risk-register structure and data fields
- Control-effectiveness evaluation and evidence sources
- Risk prioritization and treatment decision rules
Workshop: Participants conduct a threat and vulnerability assessment and produce a ranked security risk register for the case organization.
Day 3: Security controls and barrier management
- Bowtie method for security-event pathways
- Preventive barriers, mitigative barriers and escalation factors
- Physical security controls including access, perimeter and surveillance measures
- Personnel security controls for visitors, contractors and insiders
- Information-security control interfaces and ISO 27001 principles
- Security control ownership, maintenance and testing
- Proportionate treatment plans and control-selection rationale
Workshop: Participants develop a Bowtie analysis for a priority threat and specify control improvements, owners and verification evidence.
Day 4: Incident response and continuity of operations
- Security incident classification and reporting thresholds
- Incident-command structures and role allocation
- Escalation protocols and executive decision points
- Crisis communication stakeholder matrices and message approval
- Business impact analysis for security disruptions
- Continuity strategies for people, premises, systems and suppliers
- Tabletop exercise design, injects and post-exercise actions
Workshop: Teams respond to an escalating site-security disruption in a tabletop exercise and produce an incident decision log and recovery priorities.
Day 5: Assurance, performance and implementation
- Security performance indicators and leading versus lagging measures
- Control-assurance plans, inspections and audit trails
- Incident investigation and corrective-action management
- Management review inputs and security reporting dashboards
- Security culture, workforce awareness and contractor engagement
- Risk-treatment budgeting and business-case development
- Ninety-day implementation planning and review cadence
Workshop: Participants complete and present a Security Management and Resilience Action Plan with prioritized actions, accountable owners, measures and 90-day milestones.
Tools & standards covered
ISO 31000:2018, ISO 22301:2019, ISO/IEC 27001:2022, BowTieXP
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Security Management
Crime Prevention Through Environmental Design for Facility Security Training Course
Facilities can be secure on paper yet remain vulnerable because entrances are poorly observed, boundaries are ambiguous, public and staff ro…
ASIS Physical Asset Protection Standard Implementation Training Course
Physical asset protection programmes often develop as disconnected projects: a guard contract is renewed, access control is upgraded, CCTV c…
Security Management for Oil and Gas Facilities Training Course
Oil and gas facilities face security exposures that can interrupt production, endanger personnel, damage critical assets and create regulato…
Security Management for Corporate Security Managers Training Course
Corporate security managers are expected to protect people, sites, information and operations while justifying expenditure to senior leaders…