Get in Touch

Course Outline

Comprehending the Ransomware Threat Environment

  • Historical development and emerging patterns of ransomware activity
  • Standard attack vectors, tactics, techniques, and procedures (TTPs)
  • Identification of ransomware collectives and associated affiliated entities

Ransomware Incident Lifecycle Analysis

  • Initial intrusion methods and internal network propagation
  • Data exfiltration and encryption stages within the attack sequence
  • Post-incident communication protocols established by threat actors

Negotiation Frameworks and Strategic Principles

  • Core strategies for cyber crisis negotiation and management
  • Analysis of adversary motivations and their leverage capabilities
  • Communication methodologies aimed at containment and incident resolution

Applied Ransomware Negotiation Training

  • Simulated interactions with threat actors to replicate operational scenarios
  • Techniques for managing escalation and mitigating time-sensitive pressures
  • Documentation of negotiation outcomes for archival and analytical purposes

Threat Intelligence Applications for Ransomware Mitigation

  • Collection and correlation of ransomware indicators of compromise (IOCs)
  • Leveraging threat intelligence platforms to enhance investigation depth and defensive posture
  • Monitoring ransomware group activities and persistent campaign efforts

Strategic Decision-Making in High-Stress Environments

  • Business continuity planning and regulatory compliance considerations during active attacks
  • Coordination with executive leadership, internal units, and external stakeholders for incident management
  • Assessment of ransom payment versus data recovery options for system restoration

Post-Incident Analysis and Improvement

  • Execution of lessons learned reviews and formal incident reporting
  • Enhancement of detection and monitoring capabilities to deter future incursions
  • System hardening measures to counter known and evolving ransomware threats

Advanced Intelligence and Strategic Posture

  • Development of longitudinal threat profiles for ransomware collectives
  • Integration of external intelligence sources into defensive strategies
  • Implementation of proactive measures and predictive analytics to preempt threats

Concluding Summary and Action Items

Requirements

  • Familiarity with cybersecurity foundational principles
  • Operational experience in incident response or Security Operations Center (SOC) functions
  • Proficiency with threat intelligence concepts and associated tools

Target Audience:

  • Cybersecurity professionals engaged in incident response activities
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events
 14 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories