Present the case for investment in cybersecurity operations centres in terms that a finance function will accept.
Managing Cybersecurity Operations Centres
Turn cybersecurity operations centres from a stated policy into a practice your organisation can evidence.
Course Overview
Most security failures involving cybersecurity operations centres exploit a process gap rather than a technical one. Security arrangements around this part of corporate security practice are tested by adversaries, not by auditors. The content is relevant to those who own the wider corporate security practice agenda and to those who are held accountable for its results. Participants test their assumptions about cybersecurity operations centres against scenarios designed to break weak ones. Teams frequently over-invest in documenting the corporate security practice capability and under-invest in testing it. The course gives participants a defensible structure for this part of corporate security practice and the judgement to adapt it. The result is the confidence to make and defend decisions about cybersecurity operations centres under scrutiny. The most reliable predictor of sound this area of corporate security practice is whether anyone reviews it when nothing has gone wrong. Participants finish with a short, specific brief on the corporate security practice discipline ready to put in front of a decision maker.
Expected Learning Outcomes
Build the investigation capability and evidence handling for cybersecurity operations centres.
Review cybersecurity operations centres after each incident, exercise and change of threat.
Assess and control third-party and contractor exposure in cybersecurity operations centres.
Identify vulnerabilities in cybersecurity operations centres and rank them by consequence.
Align cybersecurity operations centres with the wider objectives of the protected site rather than optimising it in isolation.
Distinguish the parts of cybersecurity operations centres that must be standardised from those that require judgement.
Who Should Attend
Facility and site managers accountable for protection of cybersecurity operations centres.
Business continuity and crisis managers covering cybersecurity operations centres.
Procurement and contracting staff whose agreements set obligations around cybersecurity operations centres.
Technical staff being prepared for supervisory responsibility over cybersecurity operations centres.
Contract managers overseeing outsourced security in cybersecurity operations centres.
Investigation and loss prevention specialists working on cybersecurity operations centres.
Course Modules
Cybersecurity operations centres: threat assessment and intelligence
2 sessions · 8 pointsSession 1Making the investment case for cybersecurity operations centres
- Compare the cost of cybersecurity operations centres with the cost of its absence.
- Establish evidence handling and chain of custody for cybersecurity operations centres.
- Build the internal briefing that explains cybersecurity operations centres to those affected.
- Build the threat picture for cybersecurity operations centres from sources relevant to this site and sector.
Session 2Who answers for cybersecurity operations centres, and to whom
- Confirm access control on cybersecurity operations centres cannot be routinely bypassed.
- Test the procedure for cybersecurity operations centres against a realistic scenario.
- Define the first response actions for an incident involving cybersecurity operations centres.
- Confirm recorded material from cybersecurity operations centres is retained long enough to be useful.
Cybersecurity operations centres: continuity, exercises and external coordination
2 sessions · 8 pointsSession 1Moving cybersecurity operations centres from approval to execution
- Coordinate arrangements for cybersecurity operations centres with civil defence and police in advance.
- Review cybersecurity operations centres after every incident, exercise or change in threat.
- Assess contractor and third-party exposure within cybersecurity operations centres.
- Identify single points of dependency in cybersecurity operations centres and reduce them.
Session 2Surveillance on cybersecurity operations centres that supports an investigation later
- Establish who is informed, consulted and accountable in cybersecurity operations centres.
- Confirm that reporting on cybersecurity operations centres reaches the people who can act.
- Identify where judgement in cybersecurity operations centres is legitimate and where it is not.
- Supervise and spot-check performance on cybersecurity operations centres rather than relying on reports.
Cybersecurity operations centres: procedures, access control and identity
2 sessions · 8 pointsSession 1Layering controls on cybersecurity operations centres so one failure is not fatal
- Check that controls on cybersecurity operations centres cover deterrence, detection, delay and response.
- Define the trigger that would require cybersecurity operations centres to be redesigned.
- Decide what will be stopped to create capacity for cybersecurity operations centres.
- Confirm vetting standards applied to staff and contractors in cybersecurity operations centres.
Session 2Where cybersecurity operations centres typically breaks, and why
- Verify identity checks applied at entry points relevant to cybersecurity operations centres.
- Prepare the response for the most likely failure in cybersecurity operations centres.
- Review surveillance coverage for cybersecurity operations centres against likely approach routes.
- Identify the data already collected that bears on cybersecurity operations centres.
Cybersecurity operations centres: governance, assurance and investment case
2 sessions · 8 pointsSession 1Finding the vulnerability in cybersecurity operations centres an adversary would use
- Assess insider risk in roles with privileged access to cybersecurity operations centres.
- Exercise the plan for cybersecurity operations centres under realistic conditions and record failures.
- Rank the weaknesses in cybersecurity operations centres by consequence rather than by ease of fixing.
- Remove steps in cybersecurity operations centres that add effort without adding assurance.
Session 2Supervising the guard force on cybersecurity operations centres
- Prepare the summary of cybersecurity operations centres that senior management will read.
- Report on cybersecurity operations centres in terms that support an investment decision.
- Reduce the variation in how cybersecurity operations centres is carried out between teams.
- Agree the smallest change to cybersecurity operations centres that would be visibly useful.
Choose the package that suits you
Silver Package
At least 3 people
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Gold Package
At least 3 people
- 5-night stay in a 5-star hotel
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Complete your registration
We will contact you within one business day to confirm.