Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
The Ransomware Landscape
- Evolution and current trends in ransomware
- Standard attack vectors, tactics, techniques, and procedures (TTPs)
- Identifying ransomware groups and their associated networks
Ransomware Incident Lifecycle
- Initial breach and lateral movement across the network
- Data exfiltration and encryption stages during an attack
- Communication patterns with threat actors following an incident
Negotiation Principles and Frameworks
- Core strategies for cyber crisis negotiation
- Understanding adversary motivations and leverage points
- Communication techniques for containment and resolution
Practical Ransomware Negotiation Exercises
- Simulated negotiations with threat actors to rehearse real-world scenarios
- Handling escalation and time pressure during negotiations
- Documenting negotiation results for future review and analysis
Threat Intelligence for Ransomware Defense
- Gathering and correlating ransomware indicators of compromise (IOCs)
- Leveraging threat intelligence platforms to enhance investigations and fortify defenses
- Monitoring ransomware groups and their active campaigns
Decision-Making Under Pressure
- Business continuity planning and legal implications during an attack
- Coordinating with leadership, internal teams, and external partners to manage the incident
- Weighing payment options against recovery paths for data restoration
Post-Incident Improvement
- Conducting lessons learned sessions and incident reporting
- Enhancing detection and monitoring capabilities to prevent repeat attacks
- Strengthening systems against known and emerging ransomware threats
Advanced Intelligence & Strategic Readiness
- Developing long-term threat profiles for ransomware groups
- Incorporating external intelligence feeds into your defense strategy
- Implementing proactive measures and predictive analytics to stay ahead of threats
Summary and Next Steps
Requirements
- A solid grasp of cybersecurity fundamentals
- Hands-on experience with incident response or Security Operations Center (SOC) operations
- Knowledge of threat intelligence concepts and associated tools
Target Audience:
- Cybersecurity experts focused on incident response
- Threat intelligence analysts
- Security teams preparing for potential ransomware events
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
The instructor's mastery of all the topics
Miguel Angel Jimenez Sanchez - ASP Integra Opciones
Course - MITRE ATT&CK
Machine Translated