Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
The Ransomware Ecosystem Explained
- The evolution and current trends in ransomware
- Common attack vectors, tactics, techniques, and procedures (TTPs)
- Identifying ransomware groups and their associated affiliates
Ransomware Incident Lifecycle
- Initial breach and lateral movement across the network
- The data exfiltration and encryption stages of an attack
- Post-attack communication patterns with threat actors
Negotiation Principles and Frameworks
- Core strategies for cyber crisis negotiation
- Analyzing adversary motives and sources of leverage
- Communication tactics aimed at containment and resolution
Practical Ransomware Negotiation Exercises
- Simulated interactions with threat actors to rehearse real-world scenarios
- Handling escalation and time pressure during negotiation processes
- Documenting negotiation outcomes for future reference and analysis
Threat Intelligence for Ransomware Defense
- Aggregation and correlation of ransomware indicators of compromise (IOCs)
- Leveraging threat intelligence platforms to enhance investigations and bolster defenses
- Monitoring ransomware groups and their active campaigns
Decision-Making Under Pressure
- Business continuity planning and legal implications during an attack
- Coordinating with leadership, internal teams, and external partners to manage the incident
- Assessing the viability of payment versus recovery pathways for data restoration
Post-Incident Improvement
- Facilitating lessons learned sessions and reporting on the incident
- Enhancing detection and monitoring capabilities to prevent recurrence
- Hardening systems against both known and emerging ransomware threats
Advanced Intelligence & Strategic Readiness
- Developing long-term threat profiles for ransomware groups
- Integrating external intelligence feeds into your overall defense strategy
- Implementing proactive measures and predictive analysis to stay ahead of threats
Summary and Next Steps
Requirements
- A solid grasp of cybersecurity fundamentals
- Practical experience in incident response or Security Operations Center (SOC) operations
- Familiarity with threat intelligence concepts and associated tooling
Target Audience:
- Cybersecurity professionals engaged in incident response
- Threat intelligence analysts
- Security teams preparing for potential ransomware events
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.