Get in Touch
 Duration 14 hours

Course Outline

Exploring the Ransomware Ecosystem

  • The evolution and current trends in ransomware.
  • Prevalent attack vectors, tactics, techniques, and procedures (TTPs).
  • Recognizing ransomware groups and their affiliated networks.

The Ransomware Incident Lifecycle

  • Initial system compromise and internal lateral movement.
  • The stages of data exfiltration and encryption within an attack.
  • Communication patterns observed after an attack with threat actors.

Negotiation Principles and Frameworks

  • The core tenets of cyber crisis negotiation strategies.
  • Analyzing adversary motives and identifying leverage points.
  • Effective communication strategies for containment and resolution.

Practical Ransomware Negotiation Exercises

  • Simulated engagements with threat actors to rehearse realistic scenarios.
  • Strategies for managing escalation and high-pressure time constraints.
  • Documenting negotiation results for future review and analysis.

Threat Intelligence for Ransomware Defense

  • Gathering and correlating ransomware indicators of compromise (IOCs).
  • Leveraging threat intelligence platforms to deepen investigations and strengthen defenses.
  • Monitoring ransomware groups and their active campaigns.

Decision-Making Under Pressure

  • Navigating business continuity planning and legal implications during an attack.
  • Coordinating with leadership, internal teams, and external partners to manage the incident.
  • Weighing the options between payment and recovery pathways for data restoration.

Post-Incident Improvement

  • Facilitating lessons-learned sessions and comprehensive incident reporting.
  • Enhancing detection and monitoring capabilities to mitigate future risks.
  • Hardening systems against both known and emerging ransomware threats.

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for specific ransomware groups.
  • Integrating external intelligence feeds into your overall defense strategy.
  • Adopting proactive measures and predictive analysis to maintain a strategic advantage.

Conclusion and Next Steps

Requirements

  • A solid grasp of core cybersecurity fundamentals.
  • Practical experience in incident response or Security Operations Center (SOC) workflows.
  • Working familiarity with threat intelligence concepts and associated tools.

Target Audience:

  • Cybersecurity specialists engaged in incident response efforts.
  • Threat intelligence analysts.
  • Security teams focused on preparation for potential ransomware events.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories