Managing Corporate Insider Threat Detection Programmes

A practical programme in insider threat detection for professionals who are accountable for results, not just awareness.

📍 Tunis🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

Insider risk in insider threat detection is uncomfortable to discuss and expensive to ignore. Guard force performance on the practice within corporate security practice reflects supervision, not instruction. It is appropriate for those preparing to take on wider responsibility for this part of corporate security practice. Participants leave with a method for insider threat detection, not a set of opinions about it. Sessions alternate between guided analysis of the corporate security practice discipline and supervised application. The outcome is a practitioner who can hold a position on the corporate security practice capability and revise it on evidence. Mature organisations treat insider threat detection as a standing capability rather than a project that finishes. The version of this part of corporate security practice described in the manual and the version practised on the floor tend to diverge over time. The programme closes with an action plan for this area of corporate security practice that each participant writes for their own organisation.

Expected Learning Outcomes

01

Exercise and test arrangements for insider threat detection under realistic conditions.

02

Establish what evidence would demonstrate that insider threat detection is under control.

03

Protect information and intellectual property within insider threat detection.

04

Balance security requirements in insider threat detection against operational practicality.

05

Review contracts and agreements for the obligations they create around insider threat detection.

06

Build the security operating procedures governing insider threat detection.

07

Diagnose whether a problem in insider threat detection is one of design, resourcing or discipline.

Who Should Attend

01

Analysts producing the data on which decisions about insider threat detection rest.

02

Business continuity and crisis managers covering insider threat detection.

03

Managers of multi-site operations seeking consistency in insider threat detection.

04

Facility and site managers accountable for protection of insider threat detection.

05

Information security staff whose remit overlaps insider threat detection.

06

Contract managers overseeing outsourced security in insider threat detection.

Course Modules

01

Insider threat detection: procedures, access control and identity

2 sessions · 8 points

Session 1Handling evidence from insider threat detection so it survives scrutiny

  • Close out actions on insider threat detection rather than leaving them open indefinitely.
  • Map the handovers in insider threat detection between functions and secure them.
  • Review insider threat detection after every incident, exercise or change in threat.
  • Coordinate arrangements for insider threat detection with civil defence and police in advance.

Session 2Testing insider threat detection before relying on it

  • Set out the decisions in insider threat detection that require sign-off and by whom.
  • Build the threat picture for insider threat detection from sources relevant to this site and sector.
  • Establish who is informed, consulted and accountable in insider threat detection.
  • Compare the cost of insider threat detection with the cost of its absence.
02

Insider threat detection: incident response and escalation

2 sessions · 8 points

Session 1Coordinating with external authorities on insider threat detection

  • Establish the boundary of insider threat detection and record what sits outside it.
  • Review surveillance coverage for insider threat detection against likely approach routes.
  • Reduce the variation in how insider threat detection is carried out between teams.
  • Remove steps in insider threat detection that add effort without adding assurance.

Session 2Assessing the threat to insider threat detection specifically, not generically

  • Prepare the summary of insider threat detection that senior management will read.
  • Define the first response actions for an incident involving insider threat detection.
  • Establish evidence handling and chain of custody for insider threat detection.
  • Assess contractor and third-party exposure within insider threat detection.
03

Insider threat detection: vulnerability assessment and prioritisation

2 sessions · 8 points

Session 1Insider risk inside insider threat detection

  • Draft the minimum viable security procedure for insider threat detection.
  • Report on insider threat detection in terms that support an investment decision.
  • Confirm recorded material from insider threat detection is retained long enough to be useful.
  • Check that controls on insider threat detection cover deterrence, detection, delay and response.

Session 2Moving insider threat detection from approval to execution

  • Set escalation criteria and out-of-hours contacts for insider threat detection.
  • Test the procedure for insider threat detection against a realistic scenario.
  • Check guard force instructions for insider threat detection are current and understood.
  • Confirm access control on insider threat detection cannot be routinely bypassed.
04

Insider threat detection: governance, assurance and investment case

2 sessions · 8 points

Session 1Surveillance on insider threat detection that supports an investigation later

  • Check that insider threat detection still works when volumes rise unexpectedly.
  • Assign responsibility for keeping documentation of insider threat detection current.
  • Identify where judgement in insider threat detection is legitimate and where it is not.
  • Verify identity checks applied at entry points relevant to insider threat detection.

Session 2Escalation and decision rights in insider threat detection

  • Exercise the plan for insider threat detection under realistic conditions and record failures.
  • Check that records of insider threat detection answer the questions likely to be asked.
  • Identify vulnerabilities in insider threat detection and rank them by consequence, not ease of fix.
  • Set out how exceptions to insider threat detection are requested and approved.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.