Get in Touch
 Duration 14 hours

Course Outline

Comprehending the Ransomware Landscape

  • The progression and current trends in ransomware activity
  • Typical attack vectors, tactics, techniques, and procedures (TTPs)
  • Recognizing ransomware syndicates and their associated affiliates

The Ransomware Incident Lifecycle

  • Initial intrusion and lateral movement across the network
  • Phases of data theft and encryption during an attack
  • Communication patterns with threat actors following the breach

Core Principles and Frameworks for Negotiation

  • The basics of cyber crisis negotiation approaches
  • Analyzing the motivations and leverage held by adversaries
  • Strategies for communicating to contain and resolve incidents

Practical Ransomware Negotiation Workshops

  • Simulated dialogues with threat actors to rehearse real-world situations
  • Handling escalation and time constraints during negotiations
  • Recording negotiation outcomes for future review and analysis

Leveraging Threat Intelligence for Ransomware Protection

  • Gathering and connecting ransomware indicators of compromise (IOCs)
  • Utilizing threat intelligence platforms to enhance investigations and defenses
  • Monitoring ransomware groups and their active campaigns

Decision-Making in High-Pressure Situations

  • Business continuity planning and legal aspects during an attack
  • Coordinating with leadership, internal teams, and external partners to manage the incident
  • Assessing the option to pay versus pursuing data recovery methods

Post-Incident Enhancement

  • Holding lessons learned sessions and reporting on the incident
  • Upgrading detection and monitoring capabilities to prevent repeat attacks
  • Strengthening systems against both known and emerging ransomware threats

Advanced Intelligence & Strategic Preparedness

  • Developing long-term threat profiles for ransomware groups
  • Incorporating external intelligence feeds into your defense strategy
  • Adopting proactive measures and predictive analysis to remain ahead of threats

Wrap-Up and Future Steps

Requirements

  • A solid grasp of cybersecurity basics
  • Practical experience in incident response or Security Operations Center (SOC) workflows
  • Knowledge of threat intelligence principles and associated tooling

Target Audience:

  • Security professionals focused on incident response
  • Threat intelligence analysts
  • Security teams preparing for potential ransomware events

Testimonials (2)

Upcoming Courses

Related Categories