Get in Touch
 Duration 14 hours

Course Outline

Understanding the Ransomware Ecosystem

  • The evolution and current trends of ransomware.
  • Common attack vectors, tactics, techniques, and procedures (TTPs).
  • Identifying ransomware groups and their associated affiliates.

Ransomware Incident Lifecycle

  • Initial compromise and lateral movement across the network.
  • The data exfiltration and encryption phases of an attack.
  • Post-attack communication patterns with threat actors.

Negotiation Principles and Frameworks

  • The foundations of cyber crisis negotiation strategies.
  • Understanding the motives and leverage points of adversaries.
  • Communication strategies aimed at containment and resolution.

Practical Ransomware Negotiation Exercises

  • Simulated negotiations with threat actors to rehearse real-world scenarios.
  • Managing escalation and time pressure during negotiations.
  • Documenting negotiation outcomes for future reference and analysis.

Threat Intelligence for Ransomware Defense

  • Collecting and correlating ransomware indicators of compromise (IOCs).
  • Leveraging threat intelligence platforms to enrich investigations and improve defenses.
  • Tracking ransomware groups and their ongoing campaigns.

Decision-Making Under Pressure

  • Business continuity planning and legal considerations during an attack.
  • Coordinating with leadership, internal teams, and external partners to manage the incident.
  • Evaluating payment options versus recovery pathways for data restoration.

Post-Incident Improvement

  • Conducting lessons learned sessions and reporting on the incident.
  • Enhancing detection and monitoring capabilities to prevent future attacks.
  • Hardening systems against known and emerging ransomware threats.

Advanced Intelligence & Strategic Readiness

  • Building long-term threat profiles for ransomware groups.
  • Integrating external intelligence feeds into your defense strategy.
  • Implementing proactive measures and predictive analysis to stay ahead of threats.

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity fundamentals.
  • Practical experience in incident response or Security Operations Center (SOC) operations.
  • Knowledge of threat intelligence concepts and associated tools.

Audience:

  • Cybersecurity professionals engaged in incident response.
  • Threat intelligence analysts.
  • Security teams preparing for potential ransomware events.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories