Get in Touch
 Duration 14 hours

Course Outline

Navigating the Ransomware Ecosystem

  • The evolution and current trends in ransomware
  • Typical attack vectors, tactics, techniques, and procedures (TTPs)
  • Recognizing ransomware groups and their affiliated entities

The Ransomware Incident Lifecycle

  • Initial intrusion and lateral movement across the network
  • Stages of data exfiltration and encryption within an attack
  • Communication dynamics with threat actors following an attack

Negotiation Frameworks and Principles

  • Core strategies for cyber crisis negotiation
  • Comprehending adversary motives and their sources of leverage
  • Talking points and strategies for containment and resolution

Hands-On Ransomware Negotiation Practice

  • Simulated interactions with threat actors to rehearse real-world scenarios
  • Managing escalation and time-sensitive pressures during negotiations
  • Recording negotiation outcomes for future analysis and reference

Threat Intelligence for Ransomware Defense

  • Aggregating and correlating ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to deepen investigations and strengthen defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making Under Pressure

  • Business continuity planning and legal implications during an attack
  • Coordinating with leadership, internal teams, and external partners for incident management
  • Assessing the viability of payment versus data recovery pathways

Post-Incident Enhancement

  • Holding lessons-learned sessions and documenting incident reports
  • Upgrading detection and monitoring capabilities to mitigate future risks
  • Strengthening systems against both known and emerging ransomware threats

Advanced Intelligence & Strategic Preparedness

  • Developing long-term threat profiles for ransomware groups
  • Incorporating external intelligence feeds into your defensive strategy
  • Deploying proactive measures and predictive analytics to anticipate threats

Conclusion and Future Actions

Requirements

  • A solid grasp of cybersecurity core principles
  • Practical experience in incident response or Security Operations Center (SOC) workflows
  • Knowledge of threat intelligence methodologies and associated tools

Target Audience:

  • Cybersecurity experts specializing in incident response
  • Threat intelligence analysts
  • Security teams engaged in ransomware preparedness

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories