Security Threat Assessment Training

Security manager reviewing threat information for a security threat assessment

Know who could target your organisation, how capable they are, and what that means for your security spending. This security threat assessment training teaches managers to read the national threat picture and turn it into a clear, local threat statement, using the same approach Agilient’s consultants use on live threat and risk assessments.

What your organisation gains

  • Security decisions based on credible, current threats rather than assumptions or last year’s report.
  • A repeatable way to translate national threat advice into what it means for your sites and people.
  • Threat statements that feed directly into your security risk assessment and security plan.
  • Managers who can brief executives confidently when the threat environment changes.
DeliveryIn-house for your organisation, at your premises or live online via Microsoft Teams
DurationAgreed with you, from a two-hour briefing to a two-day program
LevelsExecutive briefing, manager or practitioner workshop, and train-the-trainer
ApproachPractitioner-led, with case studies, active learning and practical exercises
Suited toExecutives, security and risk managers
Course codeAGGOVSEC002

Why train with Agilient

Taught by practitioners

Every Agilient consultant has at least 20 years of experience, typically as security managers within large organisations, and has dealt first hand with the issues the course covers.

Built for your organisation

Content, examples and scenarios are shaped around your sites, policies and incident history, not an off-the-shelf syllabus that dates quickly.

Active learning

Participants work through case studies and carry out the activities themselves, so the skills stick after the day.

Designed for you to own

Train-the-trainer options and a strategy for moving the course into your own online learning mean the capability stays in-house.

Why threat assessment matters now

Australia’s National Terrorism Threat Level has been PROBABLE since August 2024. The Australian Government advises that a crowded place in a major city is the most likely location for an attack, and that an attack is most likely to come from a lone actor or small group with little or no warning.

In the Director-General’s Annual Threat Assessment of 24/06/2026, ASIO described espionage and foreign interference as being at extreme levels, warned of growing preparation for sabotage against infrastructure, and cautioned that the PROBABLE level should not be read as a sign that risk is easing, because the security environment is degrading. Organisations need people who can read this national picture and work out what it means for their own sites, staff and services.

What the course covers

  1. Threat and risk The difference between threat, vulnerability and risk, and why a threat assessment comes first.
  2. Threat sources Criminal, issue motivated, terrorist, insider and state actor threats, and how each relates to your operations.
  3. Intent and capability Rating threat sources on intent and capability, and expressing the result as a threat level.
  4. Information sources Using the National Terrorism Threat Level, ASIO public assessments, police and open source information, and your own incident records.
  5. Trends and history Reading historical incidents and trends to anticipate what is likely next.
  6. Obligations Where threat assessment requirements come from, including the PSPF, the SOCI Act CIRMP Rules and the crowded places strategy.
  7. Writing the threat statement Producing a concise threat assessment that can feed a security risk assessment or security plan.
  8. Practical workshop Workshopping a threat assessment for your organisation with an experienced Agilient consultant.

What participants will be able to do

  • Explain the difference between threat, vulnerability and risk.
  • Identify and categorise the threat sources relevant to the organisation.
  • Rate intent and capability and express a defensible threat level.
  • Use national, open source and internal information to support the assessment.
  • Write a threat statement that feeds directly into security risk assessment and planning.

Who should attend

  • Executives and senior managers
  • Security managers and advisers
  • Risk and business continuity managers
  • Venue, precinct and facility managers

Choose the level and format that suits you

The course can be run at more than one level, so governance and day-to-day practice are covered together.

  • Executive briefing. A short session for executives and boards on accountability, obligations, risk appetite and what good looks like.
  • Manager and practitioner workshop. The full course, with case studies and practical exercises for the people who manage the risk day to day.
  • Train-the-trainer. Preparing your own trainers to deliver the course inside your organisation, with the materials and guidance to do it well.
  • In person or online. Delivered at your premises, at a venue you choose, or live online through Microsoft Teams and other platforms.

Bringing the capability in-house, with Agilient as your partner

More organisations want to build and keep this capability within their own teams. Agilient supports that. After delivering the course, Agilient can train your trainers, help your learning and development team plan the conversion of the course into an online module, and stay involved as an adviser, so your people deliver it with the benefit of Agilient’s hands-on experience.

How it works

  1. Get in touch. Tell us which course you are interested in, roughly how many people, where and when.
  2. Scoping conversation. An Agilient consultant discusses your people, sites, policies and recent incidents, and agrees the level, format and duration with you.
  3. Tailored content. Case studies, scenarios and exercises are built around your own environment and procedures.
  4. Delivery and handover. The course is delivered in person or online. Agilient can then train your trainers, support an online version, or review related procedures, controls or risk assessments.

Related Agilient services and resources

Frequently asked questions

What is a security threat assessment?

A security threat assessment identifies the people or groups who could harm an organisation and rates each one on intent and capability. The result is a threat level for each threat source, which then feeds the security risk assessment and security plan.

How is a threat assessment different from a risk assessment?

A threat assessment looks only at who might cause harm and how likely they are to try. A risk assessment combines that threat picture with vulnerabilities and consequences to decide what action is needed. Agilient’s Security Risk Assessment and Management Course covers the full risk process.

Is there an Australian standard for threat assessment?

There is no Australian standard dedicated to threat assessment. The course draws on AS ISO 31000:2018, SA HB 167:2025, SA HB 188:2021 and Australia’s Strategy for Protecting Crowded Places from Terrorism.

How long is the course?

Duration is agreed with you. Courses range from a two-hour briefing to a one, one and a half or two-day program, depending on your audience, risks and how much practical work you want included.

Can the course be delivered online?

Yes. Agilient delivers courses in person at your premises and live online through Microsoft Teams and other platforms, and can combine the two for teams spread across several locations.

Can our own team deliver this training in future?

Yes. Agilient runs train-the-trainer sessions so your people can deliver the course themselves, and can work with your learning and development team on a strategy for converting the course into an online module for induction and refreshers.

Can individuals book a place on this course?

No. Agilient runs its training in-house for organisations rather than as public courses, so individual places are not available. Group size, timing and content are agreed with each organisation.

Is this an accredited course?

No, and that is deliberate. It is not a nationally recognised qualification that follows a fixed syllabus, which can date quickly. It is designed and delivered by practitioners who have dealt with these issues first hand, tailored to your organisation, and built on case studies, active learning and practical exercises.

Ready to build this capability in your organisation?

Tell us what you need. Agilient will recommend the right level, format and duration, and tailor the course to your organisation.

Other in-house security training courses

Sources

Last updated 29/09/2026.