A focused course, tailored for you
The AVP Threat Management Operating Playbook
How an AVP of Threat Management runs detect, hunt, respond, and report so the audit committee, the CISO, and the SOC see the same picture.
The audit committee opens the threat-management page first. It reads detections closed, mean time to contain, top unresolved exposure, and the trendline. Everything you do upstream has to roll into that one page, every quarter, without smoothing.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
An Associate Vice President of Threat Management sits between the SOC floor and the executive room. The SOC has alerts, hunts, tickets, and shift handovers. The executive room has a single page with four numbers and a trend arrow. Between those two layers sit detection coverage decisions, hunt programme priorities, IR runbook quality, threat-intel-to-control pipelines, vendor red-team scopes, and the headcount-versus-coverage tradeoffs you defend in budget season. Most operating models collapse one of those layers into the other. They either drown the executive in SOC noise, or they sanitise the SOC reality until the executive page no longer reflects what the analysts are actually seeing. The playbook keeps both layers honest. Detection engineering driven by adversary tradecraft your sector actually faces, mapped to ATT&CK, with the gap log that becomes next quarter's roadmap. Hunt programme with hypothesis-driven sprints, a findings register that names the threats, and a feedback loop into detection. IR runbooks that survive the worst-case call, including legal hold, regulator notification, customer comms, and post-incident learning. Threat intel ingestion with named owners and SLAs from indicator to control change. And one scorecard that compresses all of it into the page the audit committee reads first.
What you walk away with
- Run detection engineering against ATT&CK with a published coverage map, a quarterly gap log, and an owned roadmap that survives a budget review.
- Stand up a hunt programme with hypothesis-driven sprints, a findings register, and a closed feedback loop from hunt findings into detection content.
- Maintain IR runbooks that hold up at 11pm on a Sunday, including legal, comms, regulator notification, and the post-incident learning loop.
- Convert threat intel from PDFs into ticketed control changes with named owners and an indicator-to-action SLA you can defend.
- Produce the one-page threat-management scorecard the audit committee opens first, with numbers that match what the analysts on the floor see.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules in the Art of Service learning environment, sequenced from operating model through to the audit-committee scorecard.
- Downloadable templates and worked examples for every module, including the detection coverage map, the hunt findings register, the IR runbook pack, the tabletop pre-read and after-action, the budget defence pack, and the audit-committee scorecard.
- Hand-built implementation playbook tailored to your team's stack, reporting line, sector regulator, and committee cadence, delivered alongside course access.
- Thirty-day refund window.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours: learning-environment account provisioned, all twelve written modules available, downloadable templates and worked examples ready, hand-built implementation playbook delivered alongside course access.
Weeks one to two: work through modules one through five to rebuild the operating model and the detection-hunt-intel core.
Weeks three to four: work through modules six through ten to rebuild IR, tabletop, vendor scopes, budget defence, and partner boundaries.
Weeks five to six: work through modules eleven and twelve to land the regulator walk-through and the audit-committee scorecard, in time for the next committee cycle.
Before and after
Threat management runs as a SOC plus a hunt cell plus an IR retainer plus a stack of PDFs from intel feeds. Quarterly reporting is rebuilt from scratch each cycle. The audit committee leaves with questions you answer by email later. The CFO keeps proposing tools instead of analysts. Coverage against the adversary techniques that actually hit your sector is unknown.
Threat management runs as a single operating system with detection coverage, hunt cadence, intel-to-action, and IR readiness all rolled into one scorecard. The audit committee opens the page first and leaves with confidence. The budget conversation runs off a coverage-versus-cost picture rather than vendor pitches. The MSSP and the IR retainer run inside named boundaries. Adversary tradecraft maps to live detections you can name.
What happens if you do not address this
Skip the operating model work and the next post-incident review surfaces a runbook gap in front of the General Counsel and the regulator. Skip the coverage map and the next budget cycle hands headcount to a tool the CFO chose without you. Skip the scorecard and the audit committee starts asking why the threat page is different every quarter. None of those are tail risks. They are the predictable consequence of running a threat programme without an operating model the AVP layer owns.
Who it is for
Associate Vice Presidents and senior directors who own threat management for a regulated enterprise. You report to the CISO or the CSO. You have a SOC manager and a threat intel lead beneath you. You sit on the IR bridge. You present quarterly to the audit committee, the risk committee, or both. Your headcount is somewhere between 15 and 80 analysts and engineers. You are the one who has to translate adversary reality into a board-readable number, and a board-readable number into where the next analyst goes.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Roughly thirty to forty hours total over four to six weeks, split between the modules and the templates. Most takers work it as two evening sessions a week plus one weekend pass.
Why $199 is the right number
Open-source frameworks like ATT&CK, D3FEND, and NIST 800-61 give you the vocabulary but not the operating model. Vendor playbooks give you their product workflow, not your programme. SANS courses train the SOC analyst. Big consulting engagements rebuild the function from outside, slowly, at a price that competes with two analyst salaries. This playbook sits in the gap. It is the AVP-level operating model with the templates already drafted, priced so it does not need a budget approval cycle.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.