Get in Touch
 Duration 14 hours

Course Outline

Exploring the Ransomware Ecosystem

  • The evolution and current trends in ransomware
  • Typical attack vectors, tactics, techniques, and procedures (TTPs)
  • Identification of ransomware groups and their associated affiliates

The Ransomware Incident Lifecycle

  • Initial breach and lateral movement across the network
  • The phases of data exfiltration and encryption
  • Communication patterns with threat actors following the attack

Negotiation Principles and Frameworks

  • The fundamentals of cyber crisis negotiation
  • Analyzing the motives and leverage points of adversaries
  • Effective communication strategies for containment and resolution

Hands-On Ransomware Negotiation Scenarios

  • Simulated negotiations with threat actors to rehearse real-world situations
  • Handling escalation and time-sensitive pressures during negotiations
  • Recording negotiation outcomes for future reference and analysis

Threat Intelligence in Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to enhance investigations and strengthen defenses
  • Monitoring ransomware groups and their continuous campaigns

Decision-Making Under Pressure

  • Addressing business continuity planning and legal implications during an attack
  • Coordinating with leadership, internal teams, and external partners to manage the incident
  • Assessing the choice between payment and recovery pathways for data restoration

Post-Incident Enhancement

  • Conducting lessons learned sessions and reporting on the incident
  • Strengthening detection and monitoring capabilities to prevent recurrence
  • Fortifying systems against known and emerging ransomware threats

Advanced Intelligence & Strategic Preparedness

  • Developing long-term threat profiles for ransomware groups
  • Incorporating external intelligence feeds into your defense strategy
  • Deploying proactive measures and predictive analysis to stay ahead of threats

Conclusion and Future Actions

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Practical experience in incident response or Security Operations Center (SOC) workflows
  • Acquaintance with threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity specialists engaged in incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories