Design business continuity arrangements covering post-incident organisational recovery.
Organisational Recovery After Major Security Incidents
Build a working method for post-incident organisational recovery that stands up to scrutiny and survives daily pressure.
Course Overview
The value of preparation for post-incident organisational recovery is only visible on the day it is needed. Guard force performance on this part of corporate security practice reflects supervision, not instruction. Participants gain a clear basis for measuring what the wider corporate security practice agenda has actually achieved. It is written for people who have to make post-incident organisational recovery work with the resources they already have. Discussion is anchored to worked examples of the corporate security practice discipline rather than to abstract argument. The course gives participants a defensible structure for this aspect of corporate security practice and the judgement to adapt it. Practitioner evidence points the same way: post-incident organisational recovery improves fastest where responsibility for it is named and owned. Improvement in this part of corporate security practice stalls when it depends on one capable individual rather than a defined method. The final module sets out how progress on this aspect of corporate security practice will be evidenced six months later.
Expected Learning Outcomes
Establish escalation routes for post-incident organisational recovery that work outside normal hours.
Identify vulnerabilities in post-incident organisational recovery and rank them by consequence.
Balance security requirements in post-incident organisational recovery against operational practicality.
Set the minimum documentation for post-incident organisational recovery that is genuinely necessary, and stop there.
Review post-incident organisational recovery after each incident, exercise and change of threat.
Select indicators that show whether post-incident organisational recovery is improving, and reject those that only look useful.
Who Should Attend
Staff seconded into improvement work on post-incident organisational recovery.
Business continuity and crisis managers covering post-incident organisational recovery.
Analysts producing the data on which decisions about post-incident organisational recovery rest.
Investigation and loss prevention specialists working on post-incident organisational recovery.
Information security staff whose remit overlaps post-incident organisational recovery.
Human resources staff handling vetting and insider risk in post-incident organisational recovery.
Course Modules
Post-incident organisational recovery: procedures, access control and identity
2 sessions · 8 pointsSession 1Handling evidence from post-incident organisational recovery so it survives scrutiny
- Identify the data already collected that bears on post-incident organisational recovery.
- Confirm vetting standards applied to staff and contractors in post-incident organisational recovery.
- Define the first response actions for an incident involving post-incident organisational recovery.
- Coordinate arrangements for post-incident organisational recovery with civil defence and police in advance.
Session 2Getting other functions to support post-incident organisational recovery
- Exercise the plan for post-incident organisational recovery under realistic conditions and record failures.
- Establish the boundary of post-incident organisational recovery and record what sits outside it.
- Establish who is informed, consulted and accountable in post-incident organisational recovery.
- Assess insider risk in roles with privileged access to post-incident organisational recovery.
Post-incident organisational recovery: insider risk, vetting and personnel security
2 sessions · 8 pointsSession 1Supervising the guard force on post-incident organisational recovery
- Prepare the summary of post-incident organisational recovery that senior management will read.
- Set escalation criteria and out-of-hours contacts for post-incident organisational recovery.
- Define acceptance criteria for post-incident organisational recovery in advance.
- Map the handovers in post-incident organisational recovery between functions and secure them.
Session 2Moving post-incident organisational recovery from approval to execution
- Report on post-incident organisational recovery in terms that support an investment decision.
- Identify vulnerabilities in post-incident organisational recovery and rank them by consequence, not ease of fix.
- Record the rationale for each significant choice made about post-incident organisational recovery.
- Assign responsibility for keeping documentation of post-incident organisational recovery current.
Post-incident organisational recovery: layered controls — deter, detect, delay, respond
2 sessions · 8 pointsSession 1The paperwork for post-incident organisational recovery that is actually needed
- Verify identity checks applied at entry points relevant to post-incident organisational recovery.
- Record what was learned when post-incident organisational recovery did not go as planned.
- Draft the minimum viable security procedure for post-incident organisational recovery.
- Set out how exceptions to post-incident organisational recovery are requested and approved.
Session 2The first fifteen minutes of an incident involving post-incident organisational recovery
- Decide what will be stopped to create capacity for post-incident organisational recovery.
- Compare the cost of post-incident organisational recovery with the cost of its absence.
- Establish evidence handling and chain of custody for post-incident organisational recovery.
- Confirm recorded material from post-incident organisational recovery is retained long enough to be useful.
Post-incident organisational recovery: surveillance, monitoring and control rooms
2 sessions · 8 pointsSession 1Exercising the plan for post-incident organisational recovery realistically
- Rank the weaknesses in post-incident organisational recovery by consequence rather than by ease of fixing.
- Supervise and spot-check performance on post-incident organisational recovery rather than relying on reports.
- Build the threat picture for post-incident organisational recovery from sources relevant to this site and sector.
- Confirm access control on post-incident organisational recovery cannot be routinely bypassed.
Session 2Finding the vulnerability in post-incident organisational recovery an adversary would use
- Protect sensitive information relating to post-incident organisational recovery from casual disclosure.
- Identify single points of dependency in post-incident organisational recovery and reduce them.
- Review post-incident organisational recovery after every incident, exercise or change in threat.
- Rehearse the briefing on post-incident organisational recovery that would follow an incident.
Choose the package that suits you
Silver Package
At least 3 people
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Gold Package
At least 3 people
- 5-night stay in a 5-star hotel
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Complete your registration
We will contact you within one business day to confirm.