Give your team the skills to produce a security risk assessment that stands up to scrutiny from executives, auditors and regulators. This security risk management course is taught by consultants who carry out these assessments for government and industry every week, and it uses one of your own sites as the working example, so your people leave with a method they can apply the next day.
What your organisation gains
- A consistent, defensible risk method aligned to AS ISO 31000:2018 and SA HB 167:2025, applied the same way across every site.
- Assessments that convert into funded, prioritised treatments rather than reports that sit on a shelf.
- Less reliance on external consultants for routine assessments, with Agilient available for the complex ones.
- A clear line of sight to PSPF Release 2026 security plans and SOCI Act CIRMP obligations.
Why train with Agilient
Taught by practitioners
Every Agilient consultant has at least 20 years of experience, typically as security managers within large organisations, and has dealt first hand with the issues the course covers.
Built for your organisation
Content, examples and scenarios are shaped around your sites, policies and incident history, not an off-the-shelf syllabus that dates quickly.
Active learning
Participants work through case studies and carry out the activities themselves, so the skills stick after the day.
Designed for you to own
Train-the-trainer options and a strategy for moving the course into your own online learning mean the capability stays in-house.
Why security risk assessment skills matter now
Security risk assessments now carry more weight than they used to. Under the Protective Security Policy Framework (PSPF) Release 2026, Commonwealth entities must maintain a security plan that is considered annually and reviewed at least every two years, record their security risk tolerance in that plan and name a risk steward for each security risk. Critical infrastructure owners have similar obligations under their Critical Infrastructure Risk Management Program (CIRMP), which covers cyber and information security, personnel, supply chain, and physical security and natural hazards.
The guidance behind the method has also moved on. Standards Australia published SA HB 167:2025, Managing security related risks, in September 2025, replacing the 2006 handbook that many organisations still quote. AS ISO 31000:2018 remains the current risk management standard, and ISO has begun work on its next revision. This course brings your team up to date with both.
What the course covers
- Context and scope Setting terms of reference, the internal and external context, and the criteria you will use to judge risk.
- Assets and criticality Identifying people, information, assets and services, and rating how critical each one is to the organisation.
- Threat assessment Assessing the intent and capability of credible threat sources, drawing on the national threat level and your own incident data.
- Vulnerability and existing controls Testing how well current physical, personnel and information controls would stand up to each threat.
- Likelihood and consequence Analysing and rating risk consistently, and avoiding the common traps that make risk ratings hard to defend.
- Evaluation against risk tolerance Comparing results with the organisation’s documented risk tolerance and deciding what needs treatment.
- Treatment options and cost Choosing proportionate treatments, using the hierarchy of controls and simple cost and benefit reasoning.
- Writing it up Structuring the security risk assessment and the security plan so decision makers can act on them, and setting a review cycle.
- Practical workshop Applying the method to one of your own sites or functions, with an Agilient consultant guiding the group.
What participants will be able to do
- Scope a security risk assessment and define the context and criteria.
- Identify and rate critical assets, credible threats and existing vulnerabilities.
- Rate likelihood and consequence consistently and evaluate risk against tolerance.
- Recommend proportionate, costed treatments and assign risk owners.
- Produce a security risk assessment and review schedule that meet PSPF or CIRMP expectations.
Who should attend
- Security managers and advisers
- Risk and compliance managers
- Facility and property managers
- PSPF and CIRMP owners and risk stewards
- Security officers moving into advisory roles
Choose the level and format that suits you
The course can be run at more than one level, so governance and day-to-day practice are covered together.
- Executive briefing. A short session for executives and boards on accountability, obligations, risk appetite and what good looks like.
- Manager and practitioner workshop. The full course, with case studies and practical exercises for the people who manage the risk day to day.
- Train-the-trainer. Preparing your own trainers to deliver the course inside your organisation, with the materials and guidance to do it well.
- In person or online. Delivered at your premises, at a venue you choose, or live online through Microsoft Teams and other platforms.
Bringing the capability in-house, with Agilient as your partner
More organisations want to build and keep this capability within their own teams. Agilient supports that. After delivering the course, Agilient can train your trainers, help your learning and development team plan the conversion of the course into an online module, and stay involved as an adviser, so your people deliver it with the benefit of Agilient’s hands-on experience.
How it works
- Get in touch. Tell us which course you are interested in, roughly how many people, where and when.
- Scoping conversation. An Agilient consultant discusses your people, sites, policies and recent incidents, and agrees the level, format and duration with you.
- Tailored content. Case studies, scenarios and exercises are built around your own environment and procedures.
- Delivery and handover. The course is delivered in person or online. Agilient can then train your trainers, support an online version, or review related procedures, controls or risk assessments.
Related Agilient services and resources
- Security risk assessment consultants when you need an independent assessment completed for you
- CPTED Training
- Security risk management framework guide
- The security risk assessment process, step by step
- Free security risk maturity check
Frequently asked questions
What does a security risk management course cover?
It covers the full security risk assessment cycle: context and scope, asset criticality, threat and vulnerability assessment, likelihood and consequence analysis, evaluation against risk tolerance, treatment options, and writing up the assessment and security plan. Agilient’s course ends with a workshop on one of your own sites.
Which standards does the course follow?
The method follows AS ISO 31000:2018 Risk management guidelines and SA HB 167:2025 Managing security related risks, and shows how the results feed PSPF Release 2026 security plans and CIRMP obligations under the SOCI Act.
Do participants need to complete the threat assessment course first?
No. Threat assessment is covered within this course. Organisations that want deeper threat analysis skills often run the Security Threat Assessment Training course first or combine the two.
How long is the course?
Duration is agreed with you. Courses range from a two-hour briefing to a one, one and a half or two-day program, depending on your audience, risks and how much practical work you want included.
Can the course be delivered online?
Yes. Agilient delivers courses in person at your premises and live online through Microsoft Teams and other platforms, and can combine the two for teams spread across several locations.
Can our own team deliver this training in future?
Yes. Agilient runs train-the-trainer sessions so your people can deliver the course themselves, and can work with your learning and development team on a strategy for converting the course into an online module for induction and refreshers.
Can individuals book a place on this course?
No. Agilient runs its training in-house for organisations rather than as public courses, so individual places are not available. Group size, timing and content are agreed with each organisation.
Is this an accredited course?
No, and that is deliberate. It is not a nationally recognised qualification that follows a fixed syllabus, which can date quickly. It is designed and delivered by practitioners who have dealt with these issues first hand, tailored to your organisation, and built on case studies, active learning and practical exercises.
Ready to build this capability in your organisation?
Tell us what you need. Agilient will recommend the right level, format and duration, and tailor the course to your organisation.
Other in-house security training courses
- Security Threat Assessment Training
- Insider Threat Training
- Security Awareness Training Course
- Customer Aggression Training for Managers
- De-escalation Training for Customer-Facing Staff
- Managing Physical Aggression in the Workplace
- Patient De-escalation Training for Healthcare Workers
- Occupational Violence and Aggression (OVA) Training for Healthcare
- Crisis Management Team Training and Tabletop Exercises
- Situational Awareness and Active Armed Offender Training
- Physical Restraint and Personal Protection Training
- CPTED Training: Crime Prevention Through Environmental Design
Sources
- AS ISO 31000:2018 Risk management guidelines, Standards Australia
- SA HB 167:2025 Managing security related risks, Standards Australia
- PSPF Release 2026 List of Requirements, Department of Home Affairs
Last updated 29/09/2026.