Course Outline
Understanding the Ransomware Ecosystem
- The evolution and current trends in ransomware
- Standard attack vectors, tactics, techniques, and procedures (TTPs)
- Identifying specific ransomware groups and their affiliates
Ransomware Incident Lifecycle
- Initial compromise and lateral movement across the network
- The data exfiltration and encryption phases of an attack
- Communication patterns observed with threat actors post-attack
Negotiation Principles and Frameworks
- Core strategies for cyber crisis negotiation
- Understanding adversary motives and leverage points
- Communication tactics aimed at containment and resolution
Practical Ransomware Negotiation Exercises
- Simulated negotiations with threat actors to rehearse real-world scenarios
- Managing escalation and time pressure during critical discussions
- Documenting negotiation outcomes for future reference and analysis
Threat Intelligence for Ransomware Defense
- Collection and correlation of ransomware indicators of compromise (IOCs)
- Leveraging threat intelligence platforms to enrich investigations and strengthen defenses
- Monitoring ransomware groups and their ongoing campaign activities
Decision-Making Under Pressure
- Business continuity planning and legal considerations during an active attack
- Collaborating with leadership, internal teams, and external partners to manage the incident
- Weighing the option of payment against data recovery pathways
Post-Incident Improvement
- Conducting lessons-learned sessions and reporting on incident details
- Enhancing detection and monitoring capabilities to prevent recurrence
- Hardening systems against known and emerging ransomware threats
Advanced Intelligence & Strategic Readiness
- Developing long-term threat profiles for specific ransomware groups
- Integrating external intelligence feeds into broader defense strategies
- Implementing proactive measures and predictive analysis to stay ahead of threats
Summary and Next Steps
Requirements
- A solid grasp of cybersecurity fundamentals
- Professional experience in incident response or Security Operations Center (SOC) operations
- Working knowledge of threat intelligence concepts and associated tools
Target Audience:
- Cybersecurity professionals engaged in incident response
- Threat intelligence analysts
- Security teams preparing for potential ransomware events
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 2600 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.