Get in Touch
 Duration 14 hours

Course Outline

The Ransomware Ecosystem Explained

  • The evolution and emerging trends in ransomware
  • Typical attack vectors, tactics, techniques, and procedures (TTPs)
  • Identifying ransomware groups and their associated affiliates

The Lifecycle of a Ransomware Incident

  • Initial breach and lateral movement across the network
  • The data exfiltration and encryption stages of an attack
  • Post-attack communication dynamics with threat actors

Core Negotiation Principles and Frameworks

  • The foundations of crisis negotiation strategies in cyber contexts
  • Analyzing adversary motives and sources of leverage
  • Communication techniques aimed at containment and resolution

Applied Ransomware Negotiation Exercises

  • Simulated negotiations with threat actors to rehearse realistic scenarios
  • Handling escalation and time pressure during negotiation processes
  • Recording negotiation outcomes for future reference and analysis

Leveraging Threat Intelligence for Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs)
  • Utilizing threat intelligence platforms to enrich investigations and bolster defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making Under Pressure

  • Business continuity planning and legal implications during an attack
  • Coordinating with leadership, internal teams, and external partners to manage the incident
  • Weighing payment against recovery pathways for data restoration

Post-Incident Improvement and Hardening

  • Facilitating lessons learned sessions and generating incident reports
  • Enhancing detection and monitoring capabilities to mitigate future attacks
  • Strengthening systems against both known and emerging ransomware threats

Advanced Intelligence & Strategic Preparedness

  • Developing long-term threat profiles for ransomware groups
  • Incorporating external intelligence feeds into your defensive strategy
  • Adopting proactive measures and predictive analysis to anticipate threats

Summary and Future Steps

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Hands-on experience with incident response or Security Operations Center (SOC) operations
  • Working knowledge of threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity specialists engaged in incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories