
Discover NGSP
Next Generation Security Practitioner
Six Tiers. One Mission. Security Excellence.
The NGSP Guide
Six Tiers.
One Mission.
Security Excellence.
Start here.


The Next Generation Security Practitioner Guide gives you a detailed look at how GRC-X redefines security capability, equipping practitioners to align, engage, and lead through the lens of business risk. The guide is a resource for professionals and a genuine look inside how the programme will help you build your capability.
-
A full overview of the six learning tiers and what each unlocks
-
How NGSP bridges the gap between certification and real-world influence
-
Insight into our simulation-driven methodology and practitioner tools
-
Practical details on programme format, duration, and certification
Download the Guide
Next Generation Security Practitioner (NGSP) is a powerful, six-tier learning journey that mirrors the real challenges security teams face today.
Built to equip security teams for the future of the industry and empowering security teams to:
Align - Protecting the business in pursuit of its goals
Engage - Translating security requirements in a language the business understands
Integrate - Achieving the strongest security posture while enabling the business
What is NGSP?
Align.
Engage.
Integrate.
Roles
BISOs
Who bridge information security and the business requirement.
Security Managers & Leads
Who align security programmes and controls with business priorities.
Risk Managers & Analysts
Who connect exposure and impact directly to business outcomes.
Programme & Project Managers
Who embed security by design into project delivery and transformation.
Security Consultants
Who solve security problems and align security with business goals.
Emerging Leaders in Security
Practitioners preparing to step into roles of senior influence.
NGSP is designed for practitioners who sit at the intersection of security and the business. People who are expected to translate technical knowledge into influence, decisions, and resilience.
If you're already industry certified but looking for an advanced learning programme to elevate your career. NGSP is for you.
Practitioners who lead not just respond
Who is NGSP For?
Lead the security conversation and drive ownership
Build powerful allies and security advocacy
Transform from enforcer to strategic partner
Learn security through the lens of business risk
Outcomes
Build on the foundations of your CISSP, CISM, CRISC (or equivalent certification), moving beyond theory into real-world practice.
NGSP takes the problems every practitioner knows - misalignment, mistrust, poor adoption - and turns them into opportunities for influence and impact. Through immersive simulation, practical tools, and consulting behaviours.
A bridge between certification and how you impact the business - designed for practitioners who already know the frameworks, but want to lead the conversation.
Turn your certified professional knowledge into influence.
Why Attend?
Strengthening security interventions - from blueprint to resilience
Delivery & Execution
Tier 6
Making risk mitigation a business enabler not just a defensive tactic
Mitigating
Risk
Tier 5
Strengthening security posture through insight, problem-solving & collaboration
Security Consulting
Tier 4
Increasing security resilience through powerful business partnerships
Building Alliances
Tier 3
Calculating loss in real-terms and getting the business to act
Business Impact
Tier 2
Mastering
the art of
identifying and communicating
emerging risk
Profiling
Risk
Tier 1
The NGSP programme unfolds across six connected tiers.
A complete information security journey that builds insight and influence to drive security the business can trust.
6 Tiers.
One Mission.
Security Excellence.
The NGSP Learning Journey
The world security teams operate in has changed faster than most can adapt.
AI is amplifying threats and speeding up decision cycles. Geopolitical instability, supply-chain exposure, and hybrid work have erased the old boundaries of control. Attackers move faster, leadership expects clarity sooner, and the cost of hesitation has never been higher.
Security practitioners are under pressure to translate complexity into confidence - fast.
The challenge isn’t knowing the frameworks; it’s applying them in live environments, influencing decisions, and keeping pace with risk that refuses to stand still.
Here's what our programme solves...
NGSP tackles the real issues facing security teams today
What NGSP Solves
Profiling Risk
The Security Issue
The threat landscape is rapidly evolving. When traditional assessments are too slow, checklist-heavy, and technical, this breeds mistrust in the output. Escalation comes too late and security become slow to react.
NGSP increases the speed at which risk, gets identified, assessed and escalated.
The Solution
Rapid, business-aligned risk-profiling using NGSP’s proprietary THOR lens to surface vulnerabilities, exposures, and threats.
What You'll Apply:
Converting profiles into clear loss scenarios by asking targeted questions that reveal real root causes of exposure.
Business Impact
The Security Issue
When threats can't be linked clearly, to financial, operational, or reputational consequences, leaders simply don't see the risk.
NGSP teaches practitioners to calculate real business impact, clearly and credibly, keeping security central to decisions.
The Solution
Converting risk profiles into clear loss scenarios by asking targeted questions that reveal real root causes of exposure.
What You'll Apply:
A concise impact map that links threats to business outcomes and prioritises attention.
The Security Issue
When security are seen as too IT-centric, and are seen as a blocker (not an enabler), stakeholders resist or ignore initiatives, leaving adoption weak and programmes stalled. NGSP shows practitioners how to build trust and influence by engaging outside IT and communicating security in a language that matters to the business.
The Solution
Understanding where security sits in business decisions. This, and translating security requirements in a language they understand.
What You'll Apply:
A practical alliance plan - who to engage, how to frame, and how to conduct, the critical conversations that can't be avoided.
Building Alliances
The Security Issue
If the need for security is vague, and solutions lack buy-in, high-stakes meetings drift and the risk increases. Without a clear consulting method, security controls and measures don't get owned.
NGSP provides a framework to diagnose issues, reach root causes, and co-create solutions leaders support and ownership.
The Solution
The PULSE consulting methodology (Position, Unpack, Lockdown, Solve, Execute). Framing security discussions, defining security problems and co-building solutions.
What You'll Apply:
A repeatable security consulting playbook in solving security problems, that secure agreement and direction.
Security Consulting
The Security Issue
If security is overloaded, rigid, or misaligned with what leaders can support, then plans collapse under their own weight. Messages fail to win resources, fixes are partial, and frustration grows.
NGSP trains practitioners to design SMART, defensible strategies that win backing and are taken seriously.
The Solution
Building practical, defensible strategies that secure buy-in and reduce exposure. Designing targeted mitigation plans and smart controls.
What You'll Apply:
A prioritised, mitigation planning process with rationale leaders will understand and back.
Mitigating Risk
The Security Issue
The threat landscape (and enterprise landscape) is moving so fast that security controls can become obsolete overnight. Teams must increase their speed and agility in identifying and correcting vulnerabilities.
NGSP teaches how to reframe, review, rework, and remove systemic weaknesses in security, making it better by design.
The Solution
Integrated security by way of a continous improvement methodology; evaluating weaknesses and building in greater resilience.
What You'll Apply:
A systematic method to evaluate, review and action security decisions along with a clear design-thinking-based approach.
Delivery & Execution
Seamless & Automated
Fully hosted on a world-class learning management system:
-
Automated invites, progress tracking, and post-workshop tasks
-
Focus on learning, not logistics
-
Smooth, end-to-end experience from registration to certification
Simulation at the Core
Every session mirrors the pressures of real-world security and risk situations:
-
Hands-on simulation and role play, not slides and lectures
-
Practice decision-making under pressure
-
80% practical, 20% theory - grounded in reality
A Structured Journey
Immersive workshops form the core of the NGSP experience:
-
Video pre-learning introduces the models and tactics ahead of time
-
Follows the 70/20/10 model: 70% interactive, 20% theory, 10% applied
-
Builds confidence and authority tier by tier
Training built for tomorrow, not yesterday
Traditional certification training focuses on theory, exams, and can be guilty of ticking boxes. NGSP is different. It’s a carefully designed eight-week journey where the learning unfolds step by step, blending interactive workshops, video pre-learning, and applied assignments. Every element is structured to turn knowledge into influence and theory into practice - so the skills you build can be used immediately in the real world.