Highlights
- One unified method for both software-engineering and information-security risk — no need to learn two separate frameworks
- Grounded entirely in recognised standards: ISO 31000, ISO/IEC 27005, ISO/IEC/IEEE 16085, NIST CSF 2.0, and the HM Treasury Orange Book
- Highly practical: delegates work on their own real, current risks throughout the session
- Leave with tangible outputs — a started risk register, an escalation path, and reusable templates
- Delivered in a single 3.5-hour session, minimising time out of the business
- Small cohorts (up to 20) for genuine discussion and facilitator attention
- Taught by a CISSP-ISSAP-ISSEP-ISSMP holder — one of the UK's most credentialed risk and security practitioners
- Live online delivery via Microsoft Teams, on your organisation's own tenant
Course Details
Module 1 — Foundations: Framing Risk and Establishing Context
Highlights:
- Build a shared risk vocabulary: likelihood, consequence, risk owner, appetite, tolerance
- Learn the ISO 31000 process end-to-end and why a repeatable process closes consistency gaps
- Establish internal/external context and articulate a working risk appetite statement
- Understand how the standards landscape fits together (ISO 31000, ISO/IEC 27005, NIST CSF 2.0, NCSC guidance)
Module 2 — Identifying and Documenting Risk
Highlights:
- Apply structured identification techniques: brainstorming, checklists, scenario analysis, SWIFT
- Use lightweight threat modelling to surface software-engineering risks systematically
- Cover priority domains: supply-chain, software lifecycle, and information-security risk
- Write sound risk statements (cause → event → consequence) in a consistent, comparable register format
Module 3 — Assessing and Prioritising Risk
Highlights:
- Distinguish risk analysis from risk evaluation within the ISO 31000 process
- Apply qualitative scoring and risk matrices — and understand their well-documented limitations
- Know when to move to semi-quantitative or quantitative methods to avoid false precision
- Recognise and guard against the cognitive biases that distort risk judgement
Module 4 — Treating, Escalating and Monitoring Risk
Highlights:
- Select proportionate treatments: avoid, reduce, transfer, or retain, mapped to the Orange Book's four responses
- Apply formal risk acceptance, sign-off, and residual risk discipline
- Escalate effectively: set thresholds, choose governance routes, and report concisely to senior leaders
- Keep the risk register a living document through ongoing monitoring and review
Who should attend
Who Should Attend
This course is designed for engineering leaders and managers — anyone with responsibility for engineering delivery who needs a consistent, repeatable way to handle risk across their team.
Primary audience:
- Engineering leaders and managers (the course's core target group)
- Team leads and heads of engineering
- Technical leads with people-management or delivery-ownership responsibility
- Anyone who currently owns, or should own, risk decisions within an engineering team
Also well suited to:
- Software engineering managers who handle both delivery risk and information-security risk, but have never had a single consistent method for either
- Leaders in regulated or high-scrutiny organisations (like public-service broadcasters, government, financial services) who need their risk practice to be standards-based and defensible
- Managers overseeing technology vendor or supply-chain relationships, given the course's specific coverage of supply-chain risk
- Leaders who currently manage risk informally or inconsistently across teams, and want a shared vocabulary and process the whole organisation can use
No prerequisites required:
- No security or risk-specialist background needed — the course builds the vocabulary and process from the ground up, so it works equally well for a first-time risk owner and someone with prior exposure to security or governance frameworks
- Not aimed at dedicated risk/security specialists seeking certification-level depth (it's explicitly not a certification course, e.g. not CISSP-track content)
Feedback
4.8 out of 5 average
"Our tailored course provided a well rounded introduction and also covered some intermediate level topics that we needed to know. Clive gave us some best practice ideas and tips to take away. Fast paced but the instructor never lost any of the delegates"
Brian Leek, Data Analyst, May 2022
“JBI did a great job of customizing their syllabus to suit our business needs and also bringing our team up to speed on the current best practices. Our teams varied widely in terms of experience and the Instructor handled this particularly well - very impressive”
Brian F, Team Lead, RBS, Data Analysis Course, 20 April 2022