Skip to main content
Image coming soon

SEC2990 Mastering Basel III for Security Intelligence Analysts in Regulated Financial Institutions

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering Basel III for Security Intelligence Analysts in Regulated Financial Institutions

Turn regulatory depth into decision-making authority within your current scope

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Security teams provide data, but finance decides capital impact, leaving analysts out of the loop on how their work affects firm-wide risk weightings

The situation this course is for

Despite producing high-fidelity intelligence, many security analysts see their outputs reinterpreted or diluted by risk and finance teams when it comes to Basel III reporting. The technical depth is there, but the articulation to capital adequacy is missing, so their influence stops short of actual risk-based capital decisions.

Who this is for

Senior security analyst in a regulated financial institution who contributes to operational risk and capital planning inputs but lacks formal ownership in Basel III reporting

Who this is not for

Entry-level SOC analysts, auditors without security operations exposure, or executives seeking board-level summaries

What you walk away with

  • Connect security control effectiveness directly to Operational Risk Advanced Measurement Approaches (AMA) inputs
  • Shape internal capital adequacy assessments using threat intelligence as a primary source
  • Produce evidence packages that align with supervisory expectations under Basel III Pillar 2
  • Lead the security input track for Internal Capital Adequacy Assessment Process (ICAAP) without requiring promotion
  • Anticipate and influence how security incidents affect firm-wide capital buffers

The 12 modules (with all 144 chapters)

Module 1. Basel III Fundamentals for Security Practitioners
Break down Basel III structure with a focus on operational risk, capital adequacy, and the role of non-financial data in Pillar 2 assessments. Translate key terms like RWA, CVA, and TLAC into actionable intelligence touchpoints.
12 chapters in this module
  1. Understanding Basel III and its three-pillar framework
  2. Why operational risk matters in capital planning
  3. How security events feed into loss event databases
  4. Pillar 1 vs Pillar 2: Where security has leverage
  5. Key differences between Basel II and Basel III for risk reporting
  6. How capital adequacy decisions are made at large banks
  7. The role of the ORSA in internal risk governance
  8. Linking cyber risk to credit and market risk spillovers
  9. Supervisory expectations for risk data quality
  10. How G-SIBs structure their capital buffers
  11. The impact of stress testing on operational risk assumptions
  12. Common regulatory scrutiny points on cyber risk inputs
Module 2. Mapping Security Controls to Operational Risk Categories
Identify which security controls align with Basel III-defined operational risk event types, including internal fraud, system failures, and damage to physical assets.
12 chapters in this module
  1. Classifying security incidents by Basel operational loss type
  2. Mapping firewall misconfigurations to system failure events
  3. Attributing insider threats to internal fraud categories
  4. Tying data breaches to external fraud and customer claims
  5. Documenting cyber events for loss event database entry
  6. Using NIST CSF to map controls to risk loss types
  7. Aligning MITRE ATT&CK stages with operational risk stages
  8. Calibrating incident severity for capital modeling
  9. Creating auditable logs for supervisory review
  10. Linking patch management gaps to risk exposure scores
  11. Tracking third-party breaches under outsourcing risk
  12. Establishing consistent classification across teams
Module 3. Building Evidence for Internal Capital Adequacy Assessments
Structure documentation that meets Internal Capital Adequacy Assessment Process (ICAAP) standards, focusing on traceability from control to capital impact.
12 chapters in this module
  1. What ICAAP reviewers look for in security submissions
  2. Building a chain of evidence from control to capital
  3. Documenting control effectiveness for auditors
  4. Quantifying risk reduction from security improvements
  5. Using maturity models to justify risk weighting
  6. Aligning security KPIs with capital planning timelines
  7. Creating defensible narratives for capital models
  8. Avoiding common gaps in evidence packages
  9. Incorporating peer benchmarking into submissions
  10. Linking tabletop exercise outcomes to capital assumptions
  11. Validating incident response effectiveness
  12. Structuring version-controlled evidence packages
Module 4. Quantifying Cyber Risk for Capital Modeling
Apply loss distribution approaches and scenario analysis to estimate potential capital impact from cyber threats, using realistic assumptions and credible sources.
12 chapters in this module
  1. Introduction to Loss Distribution Approach (LDA)
  2. Estimating frequency and severity of cyber events
  3. Using external breach data to inform assumptions
  4. Adjusting for firm-specific risk factors
  5. Scenario analysis for extreme but plausible events
  6. Integrating cyber risk into AMA models
  7. Calibrating model outputs with historical data
  8. Validating assumptions with peer institutions
  9. Presenting cyber risk estimates to capital teams
  10. Handling model uncertainty in capital planning
  11. Updating assumptions after real incidents
  12. Linking threat intelligence to scenario inputs
Module 5. Integrating Threat Intelligence into Risk Weighted Assets
Show how up-to-date threat data can adjust the risk weighting of digital assets and influence capital reserve levels.
12 chapters in this module
  1. Defining digital assets in RWA calculations
  2. Linking threat actor capability to asset risk rating
  3. Updating risk ratings based on emerging threats
  4. Using TTPs to adjust control effectiveness scores
  5. Mapping threat intelligence to asset exposure
  6. Adjusting RWA for cloud migration risks
  7. Factoring in zero-day exploit availability
  8. Incorporating geopolitical risk into asset valuation
  9. Updating risk weights after major incidents
  10. Documenting rationale for risk weighting changes
  11. Aligning with internal model validation teams
  12. Presenting adjustments to capital planning units
Module 6. Security’s Role in Supervisory Review and Evaluation Process
Prepare for SRP interactions by structuring responses that demonstrate control effectiveness and risk awareness aligned with Basel expectations.
12 chapters in this module
  1. Understanding the SRP lifecycle and key stages
  2. Identifying which security data supervisors request
  3. Preparing concise responses to supervisory queries
  4. Demonstrating control testing frequency and results
  5. Showing alignment with regulatory timelines
  6. Documenting risk exception management
  7. Responding to findings on cyber risk oversight
  8. Incorporating supervisory feedback into planning
  9. Using CSAP results to strengthen submissions
  10. Coordinating with compliance and risk teams
  11. Anticipating follow-up questions from examiners
  12. Maintaining documentation for future cycles
Module 7. Advanced Metrics for Cyber Risk Reporting
Develop and present KPIs and KRIs that resonate with capital planning teams and meet regulatory standards.
12 chapters in this module
  1. Selecting metrics that reflect true risk reduction
  2. Calculating mean time to detect and respond
  3. Tracking control coverage across critical assets
  4. Measuring patching velocity and effectiveness
  5. Benchmarking against industry peers
  6. Presenting trends over time for capital models
  7. Linking metrics to operational risk thresholds
  8. Avoiding vanity metrics in regulatory submissions
  9. Using dashboards for executive reporting
  10. Ensuring metric consistency across departments
  11. Validating data sources for auditability
  12. Updating metrics after control changes
Module 8. Third-Party and Supply Chain Risk in Basel Framework
Extend Basel III thinking to vendor relationships and outsourced functions, showing how third-party breaches affect capital expectations.
12 chapters in this module
  1. Classifying third-party relationships by risk tier
  2. Mapping vendor access to operational risk categories
  3. Assessing vendor control effectiveness
  4. Integrating SIG questionnaires into risk models
  5. Tracking vendor incidents in loss databases
  6. Using ISMS certifications as risk mitigants
  7. Quantifying residual risk after controls
  8. Reporting third-party risk in ICAAP
  9. Managing concentration risk in the supply chain
  10. Preparing for vendor-related supervisory queries
  11. Aligning vendor risk with business continuity
  12. Updating risk profiles after vendor changes
Module 9. Cyber Risk in Stress Testing Scenarios
Incorporate credible cyber attack scenarios into CCAR and DFAST submissions, ensuring security inputs are factored into capital stress tests.
12 chapters in this module
  1. Overview of CCAR and DFAST requirements
  2. Designing plausible cyber attack scenarios
  3. Estimating financial impact of data breaches
  4. Modeling operational disruption from ransomware
  5. Assessing reputational damage and customer loss
  6. Linking scenario outcomes to capital drawdown
  7. Validating scenario assumptions with threat intel
  8. Coordinating with finance and risk teams
  9. Responding to stress test findings
  10. Updating scenarios after real-world attacks
  11. Documenting scenario design for auditors
  12. Presenting cyber risk in stress test narratives
Module 10. Cross-Functional Alignment on Operational Risk
Lead coordination between security, compliance, finance, and internal audit to ensure consistent risk reporting and capital treatment.
12 chapters in this module
  1. Identifying key stakeholders in operational risk
  2. Establishing regular cross-functional syncs
  3. Aligning definitions of risk and control failure
  4. Resolving discrepancies in risk scoring
  5. Creating shared documentation standards
  6. Managing version control across teams
  7. Facilitating joint risk assessments
  8. Escalating unresolved issues to governance
  9. Using risk registers to track ownership
  10. Integrating feedback from multiple teams
  11. Maintaining audit trails for decisions
  12. Building trust through consistent delivery
Module 11. Documentation Standards for Regulatory Submissions
Produce clear, concise, and compliant documentation that survives supervisory scrutiny and internal review.
12 chapters in this module
  1. Structuring evidence for clarity and traceability
  2. Writing narratives that link control to capital
  3. Using standardized templates for consistency
  4. Versioning and approval workflows
  5. Ensuring data integrity and authenticity
  6. Preparing for document requests from auditors
  7. Organizing documentation by risk type
  8. Including metadata for searchability
  9. Archiving submissions for future reference
  10. Redacting sensitive information securely
  11. Validating completeness before submission
  12. Responding to document deficiency notices
Module 12. Sustaining Impact Beyond the Reporting Cycle
Build institutional knowledge and playbooks that endure leadership changes and regulatory shifts.
12 chapters in this module
  1. Creating reusable templates for future cycles
  2. Documenting lessons learned from reviews
  3. Training new team members on Basel linkages
  4. Updating playbooks after regulatory changes
  5. Sharing best practices across departments
  6. Measuring long-term impact on capital treatment
  7. Building credibility through consistent output
  8. Expanding influence to adjacent risk domains
  9. Mentoring peers on regulatory integration
  10. Tracking career progression from these contributions
  11. Positioning for future leadership roles
  12. Maintaining relevance in evolving regulatory landscape

How this maps to your situation

  • When capital planning season begins
  • After a supervisory inquiry lands on your desk
  • Before ICAAP documentation is finalized
  • When a new threat intelligence report changes risk assumptions

Before vs. after

Before
Security insights are logged but treated as secondary inputs in capital planning; influence ends at technical reporting.
After
Security-driven analysis directly shapes capital adequacy assessments; your documentation is cited in ICAAP and SRP filings.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 90 minutes per week for 12 weeks, with flexible access and downloadable resources for on-demand review.

If nothing changes
Continuing to treat Basel III as 'someone else’s responsibility' means remaining outside of capital-related decisions , even when your data is foundational to them. Over time, this erodes influence and positions security as a cost center rather than a risk-shaping function.

How this compares to the alternatives

Generic Basel III training covers bankers and risk officers but skips how security data feeds into models. This course fills that gap , it’s built specifically for analysts who need to translate controls into capital impact, not just compliance checkboxes.

Frequently asked

Do I need a finance background to benefit?
No. The course is designed for security professionals and translates financial risk concepts into operational terms using real examples from top-tier banks.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me get promoted?
It’s designed to expand your influence within your current role , letting you own the security-to-capital narrative without needing a title change.
$199 one-time. 90 minutes per week for 12 weeks, with flexible access and downloadable resources for on-demand review..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours