Identify and rate critical business assets using a structured criticality matrix.
Threat and Vulnerability Assessment for Critical Business Assets
Identify which business assets truly matter, profile the threats against them, and test physical and procedural vulnerabilities using adversary path analysis and criticality ratings.
Course Overview
Not every asset in a business deserves the same level of protection, yet many security programmes spread effort evenly across a site because no one has formally decided which assets, if lost or disrupted, would actually hurt the organisation most. This course starts from asset criticality: identifying and rating the people, information, equipment and processes whose loss would matter, using a structured business-impact lens rather than instinct. It then turns to the threat side, profiling the capability, intent and history of realistic adversaries rather than defending against a generic list, before testing vulnerability through adversary path and sequence analysis that traces how a determined actor would actually reach a critical asset. Participants apply techniques including asset criticality matrices and adversary sequence diagrams to a realistic facility, producing a ranked set of critical assets and the specific vulnerabilities that expose each one. The course closes by linking assessment findings to protection upgrades that are proportionate to what is actually at stake.
Expected Learning Outcomes
Profile realistic threat actors by capability, intent and historical behaviour.
Trace an adversary's most likely path to a critical asset using sequence analysis.
Test physical and procedural controls against a defined adversary capability.
Estimate the probability of interruption along an adversary's path to a target asset.
Link business impact analysis to security investment priorities for critical assets.
Present a ranked set of critical asset vulnerabilities to inform protection upgrades.
Who Should Attend
Corporate security managers protecting facilities with clearly critical assets or functions.
Risk analysts responsible for asset criticality and business impact assessments.
Critical infrastructure and utility security professionals assessing site vulnerability.
Security consultants conducting vulnerability assessments for high-value clients.
Business continuity managers linking asset criticality to resilience planning.
Government and defence-sector security staff assessing protection of sensitive sites.
Course Modules
Select any module to see its sessions and points.
01Identifying and Rating Critical Business Assets
2 sessions · 8 points
Session 1Defining What Counts as a Critical Asset
- Distinguish critical assets from assets that are merely valuable or visible on a site.
- Inventory people, information, equipment and processes that support core business functions.
- Link asset criticality to the consequences of loss, not to replacement cost alone.
- Involve business function owners in identifying assets that security teams might overlook.
Session 2Building and Applying a Criticality Matrix
- Build a criticality matrix that scores assets against impact, recovery time and substitutability.
- Apply consistent scoring definitions so ratings can be compared across a diverse asset base.
- Rank assets to focus limited protective resources on the highest-consequence items first.
- Update asset criticality ratings when business operations or dependencies change.
02Profiling Threats to Critical Assets
2 sessions · 8 points
Session 1Characterising Realistic Threat Actors
- Profile threat actors by capability, resources, intent and historical targeting behaviour.
- Distinguish opportunistic threats from those specifically targeting a named critical asset.
- Use incident data and open-source information to keep threat profiles current.
- Avoid designing controls against a worst-case threat that is not credible for the site.
Session 2Matching Threats to Specific Assets
- Map which threat actors have credible interest in each identified critical asset.
- Assess how a critical asset's visibility or reputation affects its attractiveness as a target.
- Consider insider access as a distinct threat pathway alongside external adversaries.
- Document assumptions behind each threat-to-asset link for later review and challenge.
03Vulnerability Testing Through Adversary Path Analysis
2 sessions · 8 points
Session 1Mapping Adversary Sequences
- Construct an adversary sequence diagram showing the steps needed to reach a critical asset.
- Identify detection, delay and response opportunities at each step of the sequence.
- Apply a methodology such as CARVER to compare the attractiveness of multiple targets.
- Identify the single weakest step that would most reduce an adversary's effort if closed.
Session 2Testing Controls Against a Defined Capability
- Define an adversary capability level appropriate to the site rather than an unlimited worst case.
- Test whether existing detection and delay measures function as designed under that capability.
- Estimate probability of interruption by comparing adversary task time to response time.
- Record vulnerability test results with evidence that supports later investment decisions.
04From Assessment to Protection Decisions
2 sessions · 8 points
Session 1Linking Business Impact to Investment Priorities
- Translate business impact analysis outputs into security investment priorities for assets.
- Compare protection upgrade options against the criticality and vulnerability of each asset.
- Present a cost-proportionate case for investment in the highest-consequence assets first.
- Address stakeholders who resist investment in a critical asset with a low incident history.
Session 2Reporting and Reassessing Over Time
- Present ranked critical asset vulnerabilities in a format suited to a governance audience.
- Recommend interim measures for critical assets awaiting longer-term protection upgrades.
- Set a reassessment trigger tied to changes in business operations or the threat environment.
- Track implementation of protection upgrades against the vulnerabilities they were meant to close.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
