Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Exploring the Ransomware Ecosystem
- The evolution and current trends in ransomware
- Typical attack vectors, tactics, techniques, and procedures (TTPs)
- Identification of ransomware groups and their associated affiliates
The Ransomware Incident Lifecycle
- Initial breach and lateral movement across the network
- The phases of data exfiltration and encryption
- Communication patterns with threat actors following the attack
Negotiation Principles and Frameworks
- The fundamentals of cyber crisis negotiation
- Analyzing the motives and leverage points of adversaries
- Effective communication strategies for containment and resolution
Hands-On Ransomware Negotiation Scenarios
- Simulated negotiations with threat actors to rehearse real-world situations
- Handling escalation and time-sensitive pressures during negotiations
- Recording negotiation outcomes for future reference and analysis
Threat Intelligence in Ransomware Defense
- Gathering and correlating ransomware indicators of compromise (IOCs)
- Leveraging threat intelligence platforms to enhance investigations and strengthen defenses
- Monitoring ransomware groups and their continuous campaigns
Decision-Making Under Pressure
- Addressing business continuity planning and legal implications during an attack
- Coordinating with leadership, internal teams, and external partners to manage the incident
- Assessing the choice between payment and recovery pathways for data restoration
Post-Incident Enhancement
- Conducting lessons learned sessions and reporting on the incident
- Strengthening detection and monitoring capabilities to prevent recurrence
- Fortifying systems against known and emerging ransomware threats
Advanced Intelligence & Strategic Preparedness
- Developing long-term threat profiles for ransomware groups
- Incorporating external intelligence feeds into your defense strategy
- Deploying proactive measures and predictive analysis to stay ahead of threats
Conclusion and Future Actions
Requirements
- A solid grasp of cybersecurity fundamentals
- Practical experience in incident response or Security Operations Center (SOC) workflows
- Acquaintance with threat intelligence concepts and associated tools
Target Audience:
- Cybersecurity specialists engaged in incident response
- Threat intelligence analysts
- Security teams preparing for potential ransomware events
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.