Get in Touch
 Duration 14 hours

Course Outline

Decoding the Ransomware Ecosystem

  • The evolution and current trends of ransomware.
  • Key attack vectors, along with tactics, techniques, and procedures (TTPs).
  • Identifying specific ransomware groups and their associated affiliates.

The Ransomware Incident Lifecycle

  • Initial system compromise and subsequent lateral movement across the network.
  • The stages of data exfiltration and encryption within an attack.
  • Post-attack communication dynamics with threat actors.

Negotiation Principles and Frameworks

  • The core foundations of cyber crisis negotiation strategies.
  • Analyzing the motivations and leverage points of adversaries.
  • Developing communication strategies to manage containment and resolution.

Practical Ransomware Negotiation Exercises

  • Simulated interactions with threat actors to rehearse real-world scenarios.
  • Handling escalation and managing time pressure during negotiations.
  • Recording negotiation outcomes for future reference and analytical review.

Threat Intelligence for Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs).
  • Leveraging threat intelligence platforms to deepen investigations and strengthen defenses.
  • Monitoring ransomware groups and their continuous campaign activities.

Decision-Making Under Pressure

  • Business continuity planning and navigating legal considerations during an attack.
  • Coordinating with leadership, internal teams, and external partners to control the incident.
  • Weighing the options between payment and recovery pathways for data restoration.

Post-Incident Improvement

  • Facilitating lessons learned sessions and producing incident reports.
  • Enhancing detection and monitoring capabilities to avert future attacks.
  • Reinforcing systems against both known and emerging ransomware threats.

Advanced Intelligence & Strategic Readiness

  • Developing comprehensive long-term threat profiles for ransomware groups.
  • Incorporating external intelligence feeds into your broader defense strategy.
  • Deploying proactive measures and predictive analysis to maintain a strategic advantage over threats.

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity fundamentals.
  • Professional experience in incident response or Security Operations Center (SOC) workflows.
  • Knowledge of core threat intelligence concepts and associated tools.

Target Audience:

  • Cybersecurity experts engaged in incident response roles.
  • Threat intelligence analysts.
  • Security teams preparing for potential ransomware events.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories