← All 186 courses
SEC-509 Security

Operational Resilience Programme Leadership

Run operational resilience at programme level, the way a regulator expects to see it. Learners map critical business services end to end, set impact tolerances the business will actually sign, design severe-but-plausible scenario testing, and oversee threat-led penetration testing without becoming the test's weak point. The programme is then defended in a board-style session and a simulated regulator information request.

B5Advanced
6modules
42skill atoms
1role journey
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Critical Business Service Mapping7 skill atoms
services defined by customer outcome not by systemend-to-end mapping across people, process, technology and third partiessingle point of failure discoverymapping depth vs maintainabilityexecutive-level service ownershipkeeping maps current through changeusing maps to direct investment
2Impact Tolerances7 skill atoms
maximum tolerable disruption per serviceunits that mean something such as transactions or affected customersset with the business, not by ITtolerance vs RTO and RPOevidencing you can stay within tolerancebreach analysis and lessonsboard sign-off and annual review
3Scenario & Severe-but-Plausible Testing7 skill atoms
scenario library designthird-party and cloud region failure scenariosdata integrity and destructive cyber scenarioslive testing vs simulation trade-offhandling a vulnerability discovered mid-testremediation and re-test disciplineself-assessment document quality
4Threat-Led Penetration Testing Oversight7 skill atoms
TIBER-EU and DORA TLPT structureintelligence-led scopingwhite, blue and control team rolesprovider independence requirementsrisk management during live production testingfindings handling and confidentialityauthority engagement through the engagement
5Third-Party & Concentration Risk7 skill atoms
critical provider identificationsector-level concentration exposurean exit strategy that is actually executablestressed exit vs planned exitsubstitutability testingcontractual leverage and audit rightsoversight of the provider's own resilience
6Board Reporting & Regulator Engagement7 skill atoms
one-page resilience posture reportinghonest red-status conversationslinking spend to tolerance headroompre-briefing before bad news landsresponding to a regulator information requestremediation commitments you can keepsustaining the narrative across years
Where it fits

SEC-509 in a role journey.

This course appears in 1 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

GRC / Compliance Analyst

Capstone stage
SEC-506SEC-509journey complete

Roles this course serves

The capability ladder

This course is authored to band B5.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-509 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free