Get in Touch
 Duration 14 hours

Course Outline

Grasping the Ransomware Ecosystem

  • The evolution and current trends of ransomware
  • Typical attack vectors, along with tactics, techniques, and procedures (TTPs)
  • Identifying ransomware groups and their associated affiliates

Ransomware Incident Lifecycle

  • Initial breach and lateral movement across the network
  • Phases involving data exfiltration and encryption
  • Patterns of communication with threat actors post-attack

Negotiation Principles and Frameworks

  • Core strategies for cyber crisis negotiation
  • Analyzing adversary motives and their leverage points
  • Communication strategies aimed at containment and resolution

Practical Ransomware Negotiation Exercises

  • Simulating negotiations with threat actors to reflect real-world conditions
  • Managing escalation and time constraints during discussions
  • Recording negotiation outcomes for future analysis and reference

Threat Intelligence for Ransomware Defense

  • Aggregating and correlating ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to enrich investigations and bolster defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making Under Pressure

  • Business continuity planning and legal considerations during an incident
  • Coordinating with leadership, internal teams, and external partners to manage the event
  • Assessing the choice between payment and alternative data recovery pathways

Post-Incident Improvement

  • Holding lessons-learned sessions and documenting incident reports
  • Enhancing detection and monitoring capabilities to mitigate future risks
  • Hardening systems against both known and emerging ransomware threats

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for ransomware groups
  • Integrating external intelligence feeds into the defensive strategy
  • Implementing proactive measures and predictive analysis to maintain a strategic advantage

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Hands-on experience with incident response or Security Operations Center (SOC) operations
  • Working knowledge of threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity specialists engaged in incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories