Get in Touch
 Duration 14 hours

Course Outline

Navigating the Ransomware Landscape

  • Evolution and emerging trends in ransomware
  • Standard attack vectors, tactics, techniques, and procedures (TTPs)
  • Recognizing ransomware syndicates and their associated affiliates

The Ransomware Incident Cycle

  • Initial intrusion and lateral movement across networks
  • Phases involving data exfiltration and encryption
  • Communication dynamics with threat actors post-attack

Core Negotiation Concepts and Models

  • Basis of cyber crisis negotiation methodologies
  • Decoding adversary motives and leverage points
  • Strategies for communication aimed at containment and resolution

Hands-On Ransomware Negotiation Drills

  • Simulated negotiations with threat actors to rehearse real-world situations
  • Tackling escalation and time constraints during dialogue
  • Recording negotiation results for future analysis and reference

Applying Threat Intelligence to Ransomware Defense

  • Aggregation and correlation of ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to deepen investigations and enhance defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making in High-Pressure Environments

  • Business continuity strategies and legal frameworks during attacks
  • Coordinating with leadership, internal teams, and external partners for incident management
  • Weighing the merits of payment versus alternative data recovery paths

Post-Incident Optimization

  • Facilitating lessons-learned sessions and comprehensive incident reporting
  • Enhancing detection and monitoring systems to deter future breaches
  • Strengthening systems against known and evolving ransomware threats

Sophisticated Intelligence & Strategic Preparedness

  • Developing long-term threat profiles for ransomware actors
  • Incorporating external intelligence streams into defensive strategies
  • Adopting proactive measures and predictive analytics to anticipate threats

Wrap-Up and Future Actions

Requirements

  • A solid grasp of cybersecurity basics
  • Hands-on experience in incident response or Security Operations Center (SOC) workflows
  • Working knowledge of threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity specialists focused on incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware incidents

Number of participants


Price per participant

Testimonials (2)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories