Get in Touch

Course Outline

Navigating the Ransomware Ecosystem

  • The evolution and current trends in ransomware
  • Typical attack vectors, tactics, techniques, and procedures (TTPs)
  • Recognizing ransomware groups and their associated affiliates

The Ransomware Incident Lifecycle

  • Initial compromise and lateral movement across the network
  • The data exfiltration and encryption stages of an attack
  • Communication patterns observed with threat actors post-attack

Core Negotiation Principles & Frameworks

  • The fundamentals of cyber crisis negotiation
  • Analyzing the motives and leverage held by adversaries
  • Communication techniques aimed at containment and resolution

Hands-On Ransomware Negotiation Simulations

  • Engaging in simulated negotiations with threat actors to replicate real-world scenarios
  • Handling escalation and time pressure during negotiation processes
  • Recording negotiation outcomes for future review and analysis

Leveraging Threat Intelligence for Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs)
  • Utilizing threat intelligence platforms to enrich investigations and bolster defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making in High-Pressure Situations

  • Addressing business continuity planning and legal implications during an attack
  • Coordinating with leadership, internal teams, and external partners to manage the incident
  • Weighing the options between paying a ransom and pursuing data recovery pathways

Post-Incident Optimization

  • Facilitating lessons learned sessions and documenting incident reports
  • Enhancing detection and monitoring capabilities to mitigate future attacks
  • Strengthening systems against both known and emerging ransomware threats

Advanced Intelligence & Strategic Preparedness

  • Developing long-term threat profiles for specific ransomware groups
  • Incorporating external intelligence feeds into your defense strategy
  • Deploying proactive measures and predictive analysis to outpace threats

Conclusion & Future Actions

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Practical experience in incident response or Security Operations Center (SOC) workflows
  • Knowledge of threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity specialists engaged in incident response
  • Threat intelligence analysts
  • Security teams building readiness for ransomware events
 14 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories