Tracks

Eight routes, one discipline

A track chains courses in the order the discipline is actually built: understand, analyse, design, deploy, validate. Each leads to a certification whose exam tests professional judgement as much as knowledge of the texts.

BCBusiness continuityPractitionerFree

Business Continuity

From your first BIA to a certifiable management system

The reference path for building a continuity capability that holds under real disruption. You learn to prioritise honestly, to quantify defensible timeframes, to choose strategies you can actually fund, and to write plans that people under stress can genuinely follow. Everything is anchored in ISO 22301 and BCI good practice.

5 courses 7 h Associated certificationRead

What you will be able to do

  • Run a three-level BIA and get it validated by management
  • Set MTPD, RTO, RPO and MBCO that stand up in an audit
  • Compare continuity strategies on an economic basis
  • Write operational plans and a three-tier response structure
OROperational resilienceExpert

Operational Resilience

Think in critical services and tolerances, not processes

Operational resilience shifted the discipline's centre of gravity: you no longer start from the internal process but from the service delivered to the client, and you set a ceiling on harm before talking about recovery. This path teaches the full method — identifying important services, impact tolerances, end-to-end mapping, severe scenario testing — as practised by UK regulators, the Basel Committee and DORA.

4 courses 3 h Associated certificationRead

What you will be able to do

  • Identify important business services from the client's viewpoint
  • Set and defend quantified impact tolerances
  • Map end-to-end dependencies down to tier-2 third parties
  • Build and run a severe scenario testing programme
OPOperational riskPractitioner

Operational Risk

Identify, measure and arbitrate the risk you cannot hedge

Operational risk is the only risk you can neither hedge nor diversify: you can only understand and reduce it. This path covers the full toolkit — taxonomy, loss data collection, risk and control self-assessment, key risk indicators, scenario analysis — and shows how to connect these to decisions rather than to spreadsheets.

4 courses 3 h Associated certificationRead

What you will be able to do

  • Build a usable risk taxonomy
  • Run an RCSA campaign that produces decisions
  • Set up loss data collection with root cause analysis
  • Design key risk indicators that are genuinely predictive
ITIT continuityPractitioner

IT Continuity & Disaster Recovery

Design, cost and prove a recovery capability

Many organisations have an IT recovery plan; few know how long they would actually take to restart. This path treats recovery as an engineering discipline: derive objectives from the business, design an architecture that meets them, protect backups against an attacker who owns the directory, and measure real restoration time rather than assume it.

4 courses 3 h Associated certificationRead

What you will be able to do

  • Derive technical RTOs and RPOs from the business BIA
  • Compare recovery architectures and their cost
  • Design a ransomware-resistant backup strategy
  • Run a measured, usable restoration test
CMCrisis managementPractitioner

Crisis Management

Decide fast, under uncertainty, without losing trust

A crisis differs from an incident not in severity but in ambiguity: nobody yet knows what is happening, and decisions must still be made. This path trains decision capability more than procedure — three-tier structure, battle rhythm, incident log, simultaneous communication — and closes by designing an exercise programme that genuinely progresses year on year.

4 courses 3 h Associated certificationRead

What you will be able to do

  • Distinguish incident, emergency and crisis and activate the right level
  • Staff a crisis team with roles, deputies and a battle rhythm
  • Keep an incident log usable in audit and litigation
  • Produce credible holding statements within the first thirty minutes
DORAOperational resilienceExpert

DORA Compliance

The five pillars, article by article, deliverable by deliverable

DORA is not a documentation exercise: the regulation makes the management body personally accountable, imposes a register of information of unprecedented granularity, and sets notification deadlines that are not negotiable. This path walks the five pillars starting from the deliverables a supervisor expects, not from the structure of the text.

5 courses 4 h Associated certificationRead

What you will be able to do

  • Determine the scope of application and argue proportionality
  • Build an ICT risk framework the board can approve
  • Classify and report a major incident within the deadlines
  • Produce a register of information matching the authorities' template
CYCyber resiliencePractitioner

Cyber Resilience

Hold when the defences have already failed

Cyber resilience starts where cybersecurity ends: when the attacker is already inside. This path connects incident response and business continuity, works the ransomware scenario end to end — from the disconnection decision to rebuilding a trusted directory — and shows how to design arrangements that survive compromise of their own administration tooling.

3 courses 2 h Associated certificationRead

What you will be able to do

  • Connect CSIRT, crisis team and business continuity
  • Run the first six hours of a ransomware incident
  • Decide on a mass disconnection and own its consequences
  • Rebuild a trusted foundation after compromise
TPThird-party riskPractitioner

Third-Party & Supply Chain Risk

Your resilience stops where your suppliers' begins

Most costly disruptions today originate in a link owned by a third party. This path covers the full cycle: identifying critical dependencies, proportionate due diligence, contract clauses that actually hold in a dispute, monitoring nth-tier concentration, and exit strategies tested before they are needed.

3 courses 2 h Associated certificationRead

What you will be able to do

  • Distinguish an important supplier from a critical one
  • Run due diligence proportionate to the stake
  • Negotiate usable audit, testing and exit clauses
  • Map tier-2 sub-outsourcing and measure concentration