Get in Touch
 Duration 14 hours

Course Outline

Navigating the Ransomware Landscape

  • The evolution and current trends in ransomware threats
  • Standard attack vectors and the tactics, techniques, and procedures (TTPs) employed
  • Recognizing ransomware groups and their associated networks

The Ransomware Incident Lifecycle

  • Initial intrusion and network lateral movement
  • Phases involving data exfiltration and encryption
  • Communication dynamics with threat actors post-attack

Foundations of Negotiation

  • Core principles of cyber crisis negotiation
  • Assessing the motives and leverage points of adversaries
  • Strategies for effective communication aimed at containment and resolution

Hands-On Negotiation Simulations

  • Engaging in simulated negotiations to rehearse real-world scenarios
  • Handling escalation and time constraints during discussions
  • Recording negotiation results for future analysis and reference

Leveraging Threat Intelligence for Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs)
  • Utilizing intelligence platforms to enhance investigations and strengthen defenses
  • Monitoring active ransomware groups and their ongoing activities

Strategic Decision-Making Under Stress

  • Addressing business continuity and legal implications during an incident
  • Collaborating with leadership, internal staff, and external entities to manage the crisis
  • Weighing the merits of payment versus alternative data recovery paths

Post-Incident Enhancement

  • Facilitating lessons learned sessions and comprehensive incident reporting
  • Advancing detection and monitoring systems to mitigate future risks
  • Strengthening systems against both known and emerging ransomware vectors

Advanced Intelligence and Strategic Preparedness

  • Developing sustained threat profiles for ransomware actors
  • Incorporating external intelligence sources into defensive strategies
  • Adopting proactive measures and predictive analytics to maintain a security advantage

Review and Future Directions

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Practical experience in incident response or Security Operations Center (SOC) functions
  • A working knowledge of threat intelligence principles and associated tools

Target Audience:

  • Security professionals engaged in incident response
  • Threat intelligence analysts
  • Security teams focused on ransomware preparedness

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories