Courses
The full catalogue
Every course starts from a practitioner’s question and ends with a deliverable. The six foundation courses are free, and the first lesson of every course always stays open.
32 courses
Business Continuity Fundamentals
The vocabulary, the lifecycle and the reflexes that structure the whole discipline
Running a BIA that holds
Three levels, one impact scale, and durations management owns
Continuity strategies and solutions
The step everybody skips, and that decides everything
Writing plans people can use
Write for someone who is frightened, at night, without their laptop
Implementing an ISO 22301 BCMS
From the certification decision to the first surveillance audit
Operational Resilience Fundamentals
Why regulators changed their vocabulary — and what it changes
Identifying important services and tolerances
The list that commits the board, and the numbers it will have to defend
End-to-end mapping
Six layers, down to tier-2 third parties, to find the breaking points
Testing severe but plausible scenarios
Building scenarios that hurt without becoming implausible
Operational Risk Fundamentals
The only risk you can neither hedge nor diversify
Running an RCSA campaign
Surface decisions, not fill a matrix
Loss data collection and key risk indicators
A database that drives decisions, indicators that give warning
Scenario analysis and quantification
Quantifying the extreme when history says nothing
IT Continuity Fundamentals
Availability, continuity, recovery: three questions, three architectures
Designing a recovery architecture
From business need to infrastructure design, with its cost
Backups, immutability and restoration
Designing backups that survive a compromised administrator
Testing and measuring a DR plan
Time it, don't confirm it
Crisis Management Fundamentals
Deciding before you know what is happening
Staffing and running a crisis team
Roles, battle rhythm, and the discipline that prevents burnout
Crisis communication
Say little, say true, say fast — in that order
Designing and facilitating exercises
A successful exercise is one that reveals a gap
DORA at a glance
Five pillars, twenty entity categories, one personal accountability
ICT risk management framework
Articles 5 to 16: what the board must be able to approve
Incident classification and reporting
The clock starts at classification, not at detection
ICT third-party risk and register of information
The most underestimated deliverable in the regulation
Resilience testing and TLPT
From the mandatory annual test to authority-supervised red teaming
Cyber Resilience Fundamentals
Designing for after the compromise
Responding to ransomware
The first six hours, decision by decision
Connecting cyber and continuity
Two management systems, one capability
Third-Party Risk Fundamentals
Important is not critical, and large is not important
Due diligence and contract clauses
A clause with no audit right and no joint test proves nothing
Concentration and exit strategies
Knowing how to leave before you are forced to