Skip to main content
ISO 31000

ISO/TS 31050 Emerging Risks Manager

PECB-accredited ISO/TS 31050 Emerging Risks Manager certification. Two days on the risks that are not in your register yet.

PECBRisk Manager2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

How this course is run

  • Cohort capped at 6 people
  • Practitioner-led, taught by a working CISO
  • PECB Gold Certified Trainer
  • 99.3% exam pass rateAll candidates since 2023, PECB exams.

What is included

  • 2 days of training
  • PECB certification exam
  • Course licence and materials
  • Certificate
  • Support throughout the course

What you'll be able to do

  • 1Explain what makes a risk emerging, and why the methods that work on known risks leave it out of the register
  • 2Run a horizon scan that produces decisions rather than a watch list nobody reads
  • 3Assess a risk whose likelihood cannot honestly be scored, and still give management something to act on
  • 4Attach emerging risk work to the ISO 31000 framework and process already running in your organisation

Day by day

Day 1Emerging risk, and why a conventional register misses it
  • What the specification calls an emerging risk

    Definitions, characteristics and the line between an emerging risk and a risk you have simply not assessed yet.

  • Where it attaches to ISO 31000

    Framework, process and the points in both where emerging risk work belongs instead of running beside them.

  • Risk intelligence and its sources

    What counts as a signal, where it comes from, and how to stop collecting noise.

Day 2Scanning, assessing and treating what has no history
  • Horizon scanning in practice

    Running a scan on your own context, and turning weak signals into something a committee can act on.

  • Assessment under deep uncertainty

    Analysing a risk you cannot score, and reporting it honestly rather than forcing it onto a five by five grid.

  • Treatment, monitoring and review

    Building response capacity rather than scenario-specific controls, then keeping the subject alive between reviews.

Right fit if you are.

  • ✓Risk managers running an ISO 31000 process who keep being surprised by what it misses
  • ✓CISOs and resilience leads asked what is coming, not what already happened
  • ✓Internal auditors who have to challenge a register that only contains yesterday’s risks
  • ✓Candidates preparing the PECB ISO/TS 31050 Emerging Risks Manager certification

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • ✗Beginners with no exposure to risk management: start with ISO 31000 Foundation
  • ✗Teams looking for a tool or a software shortlist, this is method rather than product
  • ✗Anyone who needs a full implementation programme: that is Lead Risk Manager territory

Prerequisites

  • A working understanding of risk management principles, for example ISO 31000 Foundation or equivalent practice
  • Practical exposure to a risk management process inside an organisation

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

No date yet for this course. Tell us where to reach you and you will hear from us as soon as one is confirmed.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

Every risk register is a record of what has already happened to somebody. That is what makes it defensible, and that is also its blind spot. An emerging risk has no loss history, no frequency to count and no comparable incident to anchor on, so the methods that make a register credible are exactly the methods that leave it out.

ISO/TS 31050 is the technical specification that addresses that gap. It sits inside the ISO 31000 family, uses the same framework and the same process, and adds what is needed to handle a risk that is new, fast-moving or not yet understood.

What the two days cover

The course works through the specification clause by clause, then applies it to risks you bring with you. Expect to leave with a scanning routine you can run next quarter, not a reading list.

  • What makes a risk emerging, and how the specification defines it
  • Where emerging risk work attaches to the ISO 31000 framework and process you already run
  • Horizon scanning, weak signals and the sources that feed them
  • Assessing a risk you cannot honestly score, and reporting it without pretending to a number
  • Treatment that builds capacity to respond, rather than controls against a specific scenario
  • Monitoring, review and the communication that keeps the subject alive between reviews

Who teaches it

Christophe Mazzola, a practising CISO and PECB Gold Certified Trainer. The examples come from audits and implementations he is running now, not from the slide deck.

Certification

The course prepares the PECB Certified ISO/TS 31050 Emerging Risks Manager examination. The exam and the certification fee are included in the price, in every delivery format. PECB sets the exam content, the duration and the credential terms; its official programme page is the source for those.

Buyers always ask

What is ISO/TS 31050 and how does it relate to ISO 31000?+

ISO/TS 31050 is a technical specification in the ISO 31000 family. It does not replace ISO 31000: it uses the same framework and the same process, and adds guidance for risks that are new, rapidly evolving or not yet understood, which conventional assessment tends to leave out.

Do I need ISO 31000 Foundation before this course?+

Not formally, but it helps. The two days assume you know what a risk framework and a risk process are. If you have never run either, ISO 31000 Foundation first will make this course far more useful.

Is the exam included?+

Yes. The PECB examination and the certification fee are included in the price, in every delivery format. PECB publishes the exam format, duration and credential terms on its own programme page.

Who is this for, in practice?+

People who already own a risk register and have been told it is backward-looking. Risk managers, CISOs, resilience leads and internal auditors who need a defensible method for the part of the risk landscape that has no incident history.

Can you run it for my team in house?+

Yes. In-house delivery is built around your own risk register and your own context, so the horizon scan on day two runs on your organisation rather than a case study. Ask for a quote and we will scope it.

ISO/TS 31050 Emerging Risks Manager · PECB · Cyber Academy