Get in Touch
 Duration 14 hours

Course Outline

The Ransomware Ecosystem

  • The evolution and current trends in ransomware
  • Standard attack vectors, tactics, techniques, and procedures (TTPs)
  • Recognizing ransomware groups and their associated networks

Lifecycle of a Ransomware Incident

  • Initial breach and subsequent lateral movement across the network
  • The phases of data exfiltration and encryption
  • Communication patterns observed after an attack with threat actors

Core Negotiation Principles and Frameworks

  • The foundation of cyber crisis negotiation strategies
  • Understanding adversary motivations and their leverage points
  • Tactical communication approaches for containment and resolution

Hands-On Ransomware Negotiation Simulations

  • Practicing realistic negotiation scenarios with simulated threat actors
  • Handling escalation and managing time-sensitive pressure during negotiations
  • Documenting negotiation results for future review and analysis

Threat Intelligence for Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to enhance investigations and fortify defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making Under Pressure

  • Navigating business continuity planning and legal implications during an attack
  • Coordinating with leadership, internal teams, and external partners to manage the incident
  • Weighing the options of payment versus alternative data recovery paths

Post-Incident Enhancement

  • Facilitating lessons learned sessions and compiling incident reports
  • Strengthening detection and monitoring capabilities to mitigate future threats
  • Hardening systems against both known and emerging ransomware variants

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for specific ransomware groups
  • Incorporating external intelligence feeds into your overall defense strategy
  • Deploying proactive measures and predictive analytics to outpace emerging threats

Summary and Future Actions

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Practical experience in incident response or Security Operations Center (SOC) activities
  • Proficiency with threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity experts engaged in incident response
  • Threat intelligence analysts
  • Security teams responsible for ransomware preparedness

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories