Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Decoding the Ransomware Ecosystem
- The evolution and current trends in ransomware
- Standard attack vectors, tactics, techniques, and procedures (TTPs)
- Identifying ransomware groups and their associated affiliates
Ransomware Incident Lifecycle
- Initial breach and lateral movement across the network
- The data exfiltration and encryption stages of an attack
- Patterns of post-attack communication with threat actors
Negotiation Principles and Frameworks
- Core strategies for cyber crisis negotiation
- Analyzing the motives and leverage of adversaries
- Communication techniques aimed at containment and resolution
Practical Ransomware Negotiation Exercises
- Simulated negotiations with threat actors to mirror real-world scenarios
- Handling escalation and time pressure during the negotiation process
- Documenting negotiation outcomes for future analysis and reference
Threat Intelligence for Ransomware Defense
- Aggregating and correlating ransomware indicators of compromise (IOCs)
- Leveraging threat intelligence platforms to enrich investigations and bolster defenses
- Monitoring ransomware groups and their active campaigns
Decision-Making Under Pressure
- Business continuity planning and legal implications during an attack
- Coordinating with leadership, internal teams, and external partners to manage the incident
- Weighing the option of payment against alternative data recovery pathways
Post-Incident Improvement
- Facilitating lessons learned sessions and reporting on the incident
- Enhancing detection and monitoring capabilities to deter future attacks
- Fortifying systems against both known and emerging ransomware threats
Advanced Intelligence & Strategic Readiness
- Constructing long-term threat profiles for ransomware groups
- Incorporating external intelligence feeds into your defense strategy
- Deploying proactive measures and predictive analysis to stay ahead of threats
Summary and Next Steps
Requirements
- A solid grasp of cybersecurity fundamentals
- Hands-on experience in incident response or Security Operations Center (SOC) environments
- Working knowledge of threat intelligence concepts and associated tools
Target Audience:
- Cybersecurity specialists focused on incident response
- Threat intelligence analysts
- Security teams proactively preparing for ransomware events
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.