Get in Touch
 Duration 14 hours

Course Outline

Exploring the Ransomware Ecosystem

  • The evolution and current trends in ransomware
  • Typical attack vectors, tactics, techniques, and procedures (TTPs)
  • Recognizing ransomware groups and their associated networks

Ransomware Incident Lifecycle

  • Initial breach and lateral movement across the network
  • The stages of data exfiltration and encryption
  • Communication patterns with threat actors following an attack

Negotiation Principles and Frameworks

  • Core concepts of cyber crisis negotiation
  • Analyzing adversary motives and leverage points
  • Strategies for communication to achieve containment and resolution

Practical Ransomware Negotiation Exercises

  • Simulated negotiations with threat actors to rehearse realistic scenarios
  • Handling escalation and time constraints during discussions
  • Recording negotiation outcomes for future review and analysis

Threat Intelligence for Ransomware Defense

  • Gathering and linking ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to enhance investigations and defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making Under Pressure

  • Business continuity planning and legal implications during an attack
  • Coordinating with leadership, internal teams, and external partners for incident management
  • Weighing the option of payment against recovery pathways for data restoration

Post-Incident Improvement

  • Facilitating lessons learned sessions and generating incident reports
  • Enhancing detection and monitoring systems to prevent future attacks
  • Strengthening systems against known and emerging ransomware threats

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for ransomware groups
  • Integrating external intelligence feeds into your defensive strategy
  • Adopting proactive measures and predictive analysis to anticipate threats

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity basics
  • Practical experience in incident response or Security Operations Center (SOC) activities
  • Knowledge of threat intelligence principles and associated tools

Target Audience:

  • Cybersecurity professionals engaged in incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories