Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Exploring the Ransomware Ecosystem
- The evolution and current trends in ransomware
- Typical attack vectors, tactics, techniques, and procedures (TTPs)
- Recognizing ransomware groups and their associated networks
Ransomware Incident Lifecycle
- Initial breach and lateral movement across the network
- The stages of data exfiltration and encryption
- Communication patterns with threat actors following an attack
Negotiation Principles and Frameworks
- Core concepts of cyber crisis negotiation
- Analyzing adversary motives and leverage points
- Strategies for communication to achieve containment and resolution
Practical Ransomware Negotiation Exercises
- Simulated negotiations with threat actors to rehearse realistic scenarios
- Handling escalation and time constraints during discussions
- Recording negotiation outcomes for future review and analysis
Threat Intelligence for Ransomware Defense
- Gathering and linking ransomware indicators of compromise (IOCs)
- Leveraging threat intelligence platforms to enhance investigations and defenses
- Monitoring ransomware groups and their active campaigns
Decision-Making Under Pressure
- Business continuity planning and legal implications during an attack
- Coordinating with leadership, internal teams, and external partners for incident management
- Weighing the option of payment against recovery pathways for data restoration
Post-Incident Improvement
- Facilitating lessons learned sessions and generating incident reports
- Enhancing detection and monitoring systems to prevent future attacks
- Strengthening systems against known and emerging ransomware threats
Advanced Intelligence & Strategic Readiness
- Developing long-term threat profiles for ransomware groups
- Integrating external intelligence feeds into your defensive strategy
- Adopting proactive measures and predictive analysis to anticipate threats
Summary and Next Steps
Requirements
- A solid grasp of cybersecurity basics
- Practical experience in incident response or Security Operations Center (SOC) activities
- Knowledge of threat intelligence principles and associated tools
Target Audience:
- Cybersecurity professionals engaged in incident response
- Threat intelligence analysts
- Security teams preparing for potential ransomware events
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.