Get in Touch
 Duration 14 hours

Course Outline

Understanding the Ransomware Ecosystem

  • The evolution and current trends in ransomware.
  • Common attack vectors, along with their associated tactics, techniques, and procedures (TTPs).
  • Identifying specific ransomware groups and their affiliated networks.

The Ransomware Incident Lifecycle

  • Initial system compromise and lateral movement across the network.
  • The phases of data exfiltration and encryption during an attack.
  • Communication patterns typically used by threat actors post-attack.

Negotiation Principles and Frameworks

  • The foundational elements of cyber crisis negotiation strategies.
  • Analyzing the motivations and leverage points of adversaries.
  • Communication approaches aimed at containment and resolution.

Practical Ransomware Negotiation Exercises

  • Simulated interactions with threat actors to rehearse realistic scenarios.
  • Techniques for managing escalation and time constraints during negotiations.
  • Proper documentation of negotiation outcomes for future review and analysis.

Threat Intelligence for Ransomware Defense

  • Gathering and correlating indicators of compromise (IOCs) related to ransomware.
  • Leveraging threat intelligence platforms to enhance investigations and fortify defenses.
  • Monitoring the activities and ongoing campaigns of specific ransomware groups.

Decision-Making Under Pressure

  • Addressing business continuity planning and legal implications during an attack.
  • Coordinating with leadership, internal teams, and external partners to manage the incident.
  • Weighing the option of payment against alternative data recovery pathways.

Post-Incident Improvement

  • Holding lessons-learned sessions and producing comprehensive incident reports.
  • Enhancing detection and monitoring capabilities to mitigate future risks.
  • Strengthening systems against both known and emerging ransomware threats.

Advanced Intelligence & Strategic Readiness

  • Developing long-term threat profiles for specific ransomware groups.
  • Integrating external intelligence feeds into overall defense strategies.
  • Adopting proactive measures and predictive analysis to stay ahead of evolving threats.

Summary and Next Steps

Requirements

  • A solid grasp of cybersecurity fundamentals.
  • Practical experience in incident response or Security Operations Center (SOC) operations.
  • Working knowledge of threat intelligence concepts and associated tools.

Target Audience:

  • Cybersecurity specialists engaged in incident response activities.
  • Analysts focused on threat intelligence.
  • Security teams preparing for potential ransomware events.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories