Tracks
Eight routes, one discipline
A track chains courses in the order the discipline is actually built: understand, analyse, design, deploy, validate. Each leads to a certification whose exam tests professional judgement as much as knowledge of the texts.
Business Continuity
From your first BIA to a certifiable management system
The reference path for building a continuity capability that holds under real disruption. You learn to prioritise honestly, to quantify defensible timeframes, to choose strategies you can actually fund, and to write plans that people under stress can genuinely follow. Everything is anchored in ISO 22301 and BCI good practice.
What you will be able to do
- Run a three-level BIA and get it validated by management
- Set MTPD, RTO, RPO and MBCO that stand up in an audit
- Compare continuity strategies on an economic basis
- Write operational plans and a three-tier response structure
Operational Resilience
Think in critical services and tolerances, not processes
Operational resilience shifted the discipline's centre of gravity: you no longer start from the internal process but from the service delivered to the client, and you set a ceiling on harm before talking about recovery. This path teaches the full method — identifying important services, impact tolerances, end-to-end mapping, severe scenario testing — as practised by UK regulators, the Basel Committee and DORA.
What you will be able to do
- Identify important business services from the client's viewpoint
- Set and defend quantified impact tolerances
- Map end-to-end dependencies down to tier-2 third parties
- Build and run a severe scenario testing programme
Operational Risk
Identify, measure and arbitrate the risk you cannot hedge
Operational risk is the only risk you can neither hedge nor diversify: you can only understand and reduce it. This path covers the full toolkit — taxonomy, loss data collection, risk and control self-assessment, key risk indicators, scenario analysis — and shows how to connect these to decisions rather than to spreadsheets.
What you will be able to do
- Build a usable risk taxonomy
- Run an RCSA campaign that produces decisions
- Set up loss data collection with root cause analysis
- Design key risk indicators that are genuinely predictive
IT Continuity & Disaster Recovery
Design, cost and prove a recovery capability
Many organisations have an IT recovery plan; few know how long they would actually take to restart. This path treats recovery as an engineering discipline: derive objectives from the business, design an architecture that meets them, protect backups against an attacker who owns the directory, and measure real restoration time rather than assume it.
What you will be able to do
- Derive technical RTOs and RPOs from the business BIA
- Compare recovery architectures and their cost
- Design a ransomware-resistant backup strategy
- Run a measured, usable restoration test
Crisis Management
Decide fast, under uncertainty, without losing trust
A crisis differs from an incident not in severity but in ambiguity: nobody yet knows what is happening, and decisions must still be made. This path trains decision capability more than procedure — three-tier structure, battle rhythm, incident log, simultaneous communication — and closes by designing an exercise programme that genuinely progresses year on year.
What you will be able to do
- Distinguish incident, emergency and crisis and activate the right level
- Staff a crisis team with roles, deputies and a battle rhythm
- Keep an incident log usable in audit and litigation
- Produce credible holding statements within the first thirty minutes
DORA Compliance
The five pillars, article by article, deliverable by deliverable
DORA is not a documentation exercise: the regulation makes the management body personally accountable, imposes a register of information of unprecedented granularity, and sets notification deadlines that are not negotiable. This path walks the five pillars starting from the deliverables a supervisor expects, not from the structure of the text.
What you will be able to do
- Determine the scope of application and argue proportionality
- Build an ICT risk framework the board can approve
- Classify and report a major incident within the deadlines
- Produce a register of information matching the authorities' template
Cyber Resilience
Hold when the defences have already failed
Cyber resilience starts where cybersecurity ends: when the attacker is already inside. This path connects incident response and business continuity, works the ransomware scenario end to end — from the disconnection decision to rebuilding a trusted directory — and shows how to design arrangements that survive compromise of their own administration tooling.
What you will be able to do
- Connect CSIRT, crisis team and business continuity
- Run the first six hours of a ransomware incident
- Decide on a mass disconnection and own its consequences
- Rebuild a trusted foundation after compromise
Third-Party & Supply Chain Risk
Your resilience stops where your suppliers' begins
Most costly disruptions today originate in a link owned by a third party. This path covers the full cycle: identifying critical dependencies, proportionate due diligence, contract clauses that actually hold in a dispute, monitoring nth-tier concentration, and exit strategies tested before they are needed.
What you will be able to do
- Distinguish an important supplier from a critical one
- Run due diligence proportionate to the stake
- Negotiate usable audit, testing and exit clauses
- Map tier-2 sub-outsourcing and measure concentration