Get in Touch
 Duration 14 hours

Course Outline

Understanding the Ransomware Ecosystem

  • The evolution and current trends of ransomware
  • Common attack vectors, tactics, techniques, and procedures (TTPs)
  • Identification of ransomware groups and their affiliated entities

Ransomware Incident Lifecycle

  • Initial breach and lateral movement across the network
  • Data exfiltration and encryption stages of an attack
  • Communication patterns with threat actors following an attack

Negotiation Principles and Frameworks

  • Core principles of cyber crisis negotiation strategies
  • Comprehending the motives and leverage points of adversaries
  • Communication techniques for effective containment and resolution

Practical Ransomware Negotiation Exercises

  • Simulated negotiations with threat actors to rehearse real-world scenarios
  • Managing escalation and time constraints during negotiations
  • Documenting negotiation outcomes for future reference and analysis

Threat Intelligence for Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to enhance investigations and fortify defenses
  • Monitoring ransomware groups and their ongoing campaigns

Decision-Making Under Pressure

  • Business continuity planning and legal considerations during an attack
  • Coordinating with leadership, internal teams, and external partners to manage the incident
  • Assessing the viability of payment versus alternative data recovery pathways

Post-Incident Improvement

  • Facilitating lessons learned sessions and reporting on the incident
  • Enhancing detection and monitoring capabilities to prevent future attacks
  • Strengthening systems against known and emerging ransomware threats

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for ransomware groups
  • Integrating external intelligence feeds into your overall defense strategy
  • Implementing proactive measures and predictive analysis to stay ahead of threats

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity fundamentals
  • Practical experience in incident response or Security Operations Center (SOC) operations
  • Familiarity with threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity professionals engaged in incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events

Testimonials (2)

Related Categories