Build the investigation capability and evidence handling for corporate data protection and privacy.
Data Protection and Privacy in Organisations
Turn corporate data protection and privacy from a stated policy into a practice your organisation can evidence.
Course Overview
Insider risk in corporate data protection and privacy is uncomfortable to discuss and expensive to ignore. Most security failures involving protection and privacy exploit a process gap rather than a technical one. Content is organised around the decisions practitioners actually face in the corporate security practice capability, not around theory headings. What blocks progress on corporate data protection and privacy is usually unclear ownership rather than unclear intent. They gain the ability to sequence improvements to the wider corporate security practice agenda in an order their organisation can absorb. It suits anyone whose decisions touch protection and privacy, in large organisations and small ones alike. Comparative studies of corporate data protection and privacy across sectors find the same handful of failure points recurring. The teaching approach is deliberately practical: participants build a security procedure for protection and privacy as they go. The closing exercise tests whether the participant's plan for this area of corporate security practice survives a hostile question.
Expected Learning Outcomes
Identify the failure points in protection and privacy most likely to cause loss, and control them first.
Review contracts and agreements for the obligations they create around corporate data protection and privacy.
Plan the response and escalation for incidents involving protection and privacy.
Design business continuity arrangements covering corporate data protection and privacy.
Assess the threat picture relevant to protection and privacy rather than a generic one.
Adapt recognised practice on corporate data protection and privacy to local constraints without hollowing it out.
Who Should Attend
Control room and monitoring staff operating corporate data protection and privacy.
Contract managers overseeing outsourced security in protection and privacy.
Security managers and officers responsible for corporate data protection and privacy.
Guard force supervisors delivering protection and privacy.
Consultants and advisers supporting clients on corporate data protection and privacy.
Analysts producing the data on which decisions about protection and privacy rest.
Course Modules
Corporate data protection and privacy: vulnerability assessment and prioritisation
2 sessions · 8 pointsSession 1Comparing corporate data protection and privacy with recognised practice
- Arrange the handover of corporate data protection and privacy so capability survives staff changes.
- Confirm that contractual obligations around protection and privacy are understood.
- Review whether corporate data protection and privacy is aligned with the objectives of the protected site.
- Define the trigger that would require protection and privacy to be redesigned.
Session 2Insider risk inside protection and privacy
- Identify the data already collected that bears on corporate data protection and privacy.
- Agree the indicators that will show whether protection and privacy is improving.
- Review corporate data protection and privacy after every incident, exercise or change in threat.
- Write down the assumptions underpinning the approach to protection and privacy.
Protection and privacy: investigation, evidence and reporting
2 sessions · 8 pointsSession 1The first fifteen minutes of an incident involving protection and privacy
- Plan the sequence in which improvements to corporate data protection and privacy will be introduced.
- Check guard force instructions for protection and privacy are current and understood.
- Confirm access control on corporate data protection and privacy cannot be routinely bypassed.
- Set escalation criteria and out-of-hours contacts for protection and privacy.
Session 2Layering controls on protection and privacy so one failure is not fatal
- Prepare the response for the most likely failure in corporate data protection and privacy.
- Confirm recorded material from protection and privacy is retained long enough to be useful.
- Benchmark the organisation's corporate data protection and privacy against comparable operations.
- Protect sensitive information relating to protection and privacy from casual disclosure.
Protection and privacy: governance, assurance and investment case
2 sessions · 8 pointsSession 1Getting other functions to support protection and privacy
- Exercise the plan for corporate data protection and privacy under realistic conditions and record failures.
- Prepare the summary of protection and privacy that senior management will read.
- Record the rationale for each significant choice made about corporate data protection and privacy.
- Agree what will be standardised in protection and privacy and what will not.
Session 2Who answers for corporate data protection and privacy, and to whom
- Report on corporate data protection and privacy in terms that support an investment decision.
- Build the threat picture for protection and privacy from sources relevant to this site and sector.
- Verify identity checks applied at entry points relevant to corporate data protection and privacy.
- Check that protection and privacy still works when volumes rise unexpectedly.
Protection and privacy: layered controls — deter, detect, delay, respond
2 sessions · 8 pointsSession 1Handling evidence from protection and privacy so it survives scrutiny
- Collect evidence on the present handling of corporate data protection and privacy before proposing changes.
- Supervise and spot-check performance on protection and privacy rather than relying on reports.
- Assess insider risk in roles with privileged access to corporate data protection and privacy.
- Name a single owner for each element of protection and privacy.
Session 2Supervising the guard force on protection and privacy
- Assess contractor and third-party exposure within corporate data protection and privacy.
- Establish evidence handling and chain of custody for protection and privacy.
- Define the first response actions for an incident involving corporate data protection and privacy.
- Coordinate arrangements for protection and privacy with civil defence and police in advance.
Choose the package that suits you
Silver Package
At least 3 people
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Gold Package
At least 3 people
- 5-night stay in a 5-star hotel
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Complete your registration
We will contact you within one business day to confirm.