Get in Touch
 Duration 14 hours

Course Outline

Grasping the Ransomware Ecosystem

  • The progression and current trends in ransomware evolution
  • Standard attack vectors, along with common tactics, techniques, and procedures (TTPs)
  • Recognizing specific ransomware syndicates and their associated affiliates

The Ransomware Incident Lifecycle

  • Initial breach detection and lateral movement across the network
  • The phases of data exfiltration and subsequent encryption
  • Analyzing post-attack communication patterns from threat actors

Foundations of Negotiation Principles and Frameworks

  • Core strategies for managing cyber crisis negotiations
  • Decoding the motives and leverage points of adversaries
  • Effective communication tactics aimed at containment and resolution

Practical Ransomware Negotiation Drills

  • Simulated interactions with threat actors to rehearse realistic scenarios
  • Techniques for managing escalation and mitigating time pressure
  • Recording negotiation outcomes for future review and analytical insights

Threat Intelligence for Ransomware Defense

  • Aggregating and correlating ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to enhance investigations and strengthen defenses
  • Monitoring the activities and ongoing campaigns of specific ransomware groups

Decision-Making Under Pressure

  • Navigating business continuity planning and legal obligations during an attack
  • Collaborating with leadership, internal teams, and external partners to manage the incident
  • Weighing the option of payment against alternative data recovery pathways

Post-Incident Improvement

  • Facilitating lessons-learned sessions and compiling comprehensive incident reports
  • Enhancing detection and monitoring capabilities to forestall future attacks
  • Strengthening systems against both known and emerging ransomware vectors

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for specific ransomware entities
  • Integrating external intelligence feeds into the broader defense strategy
  • Deploying proactive measures and predictive analytics to stay ahead of threats

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Hands-on experience in incident response or Security Operations Center (SOC) activities
  • Acquaintance with threat intelligence methodologies and associated tooling

Target Audience:

  • Cybersecurity professionals engaged in incident response operations
  • Specialists focused on threat intelligence analysis
  • Security teams actively preparing for potential ransomware events

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories