Get in Touch

Course Outline

Understanding the Ransomware Ecosystem

  • Evolution and current trends in ransomware
  • Common attack vectors, tactics, techniques, and procedures (TTPs)
  • Identifying ransomware groups and their affiliated actors

Ransomware Incident Lifecycle

  • Initial compromise and lateral movement within the network
  • Data exfiltration and encryption stages of an attack
  • Post-attack communication patterns with threat actors

Negotiation Principles and Frameworks

  • Foundations of cyber crisis negotiation strategies
  • Understanding the motives and leverage employed by adversaries
  • Communication strategies aimed at containment and resolution

Practical Ransomware Negotiation Exercises

  • Simulated negotiations with threat actors to practice real-world scenarios
  • Managing escalation and time pressure during negotiations
  • Documenting negotiation outcomes for future reference and analysis

Threat Intelligence for Ransomware Defense

  • Collecting and correlating ransomware indicators of compromise (IOCs)
  • Utilising threat intelligence platforms to enrich investigations and improve defences
  • Tracking ransomware groups and their ongoing campaigns

Decision-Making Under Pressure

  • Business continuity planning and legal considerations during an attack
  • Collaborating with leadership, internal teams, and external partners to manage the incident
  • Evaluating payment versus recovery pathways for data restoration

Post-Incident Improvement

  • Conducting lessons-learned sessions and reporting on the incident
  • Enhancing detection and monitoring capabilities to prevent future attacks
  • Hardening systems against known and emerging ransomware threats

Advanced Intelligence & Strategic Readiness

  • Building long-term threat profiles for ransomware groups
  • Integrating external intelligence feeds into your defence strategy
  • Implementing proactive measures and predictive analysis to stay ahead of threats

Summary and Next Steps

Requirements

  • A foundational understanding of cybersecurity principles
  • Experience in incident response or Security Operations Centre (SOC) operations
  • Familiarity with threat intelligence concepts and associated tools

Audience:

  • Cybersecurity professionals engaged in incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events
 14 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories