Get in Touch
 Duration 14 hours

Course Outline

The Ransomware Ecosystem

  • Evolution and current trends in ransomware.
  • Key attack vectors, tactics, techniques, and procedures (TTPs).
  • Identifying ransomware groups and their associated affiliates.

Ransomware Incident Lifecycle

  • Initial breach and lateral movement across the network.
  • Data exfiltration and encryption stages of an attack.
  • Communication patterns following an attack with threat actors.

Negotiation Principles and Frameworks

  • Core strategies for cyber crisis negotiation.
  • Assessing adversary motives and leverage.
  • Communication tactics for containment and resolution.

Practical Ransomware Negotiation Exercises

  • Simulated negotiations with threat actors to rehearse real-world scenarios.
  • Managing escalation and time constraints during negotiations.
  • Recording negotiation outcomes for future analysis and reference.

Threat Intelligence for Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs).
  • Leveraging threat intelligence platforms to enhance investigations and defenses.
  • Monitoring ransomware groups and their active campaigns.

Decision-Making Under Pressure

  • Business continuity planning and legal implications during an attack.
  • Coordinating with leadership, internal teams, and external partners to manage the incident.
  • Weighing the decision between payment and recovery pathways for data restoration.

Post-Incident Improvement

  • Conducting lessons learned reviews and incident reporting.
  • Enhancing detection and monitoring capabilities to mitigate future risks.
  • Strengthening systems against known and emerging ransomware threats.

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for ransomware groups.
  • Incorporating external intelligence feeds into your defense strategy.
  • Adopting proactive measures and predictive analytics to stay ahead of threats.

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity fundamentals.
  • Practical experience in incident response or Security Operations Center (SOC) environments.
  • Knowledge of threat intelligence principles and associated tooling.

Target Audience:

  • Cybersecurity specialists engaged in incident response.
  • Threat intelligence analysts.
  • Security teams responsible for ransomware preparedness.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories