Document proactive threat hunting to the level a new engineer could operate it.
Building Proactive Cyber Threat Hunting Strategies
A practical programme in proactive threat hunting for professionals who are accountable for results, not just awareness.
Course Overview
Availability targets for proactive threat hunting are commercial commitments, whatever the engineering team calls them. Most outages involving the wider technology and systems delivery agenda are triggered by a change somebody considered routine. Every module pairs a short input on this strand of technology and systems delivery with structured practice on the participant's own material. The programme builds the judgement to know which parts of proactive threat hunting to standardise and which to leave flexible. This programme builds the technology and systems delivery capability from first principles, without padding and without omitting what matters. It is pitched for practitioners with responsibility for the wider technology and systems delivery agenda, not for observers of it. Where proactive threat hunting is measured, it improves; where it is only discussed, it drifts. The version of this aspect of technology and systems delivery described in the manual and the version practised on the floor tend to diverge over time. Work concludes with a self-assessment of the practice within technology and systems delivery that participants can repeat annually.
Expected Learning Outcomes
Control technical debt in proactive threat hunting deliberately rather than by neglect.
Select indicators that show whether proactive threat hunting is improving, and reject those that only look useful.
Build incident response for proactive threat hunting with defined severity and escalation.
Build the deployment pipeline for proactive threat hunting so releases are routine rather than events.
Assign clear ownership for each element of proactive threat hunting across the functions involved.
Document decisions about proactive threat hunting in a form that remains useful after the people change.
Who Should Attend
Information security specialists protecting proactive threat hunting.
Operations staff who encounter the consequences of proactive threat hunting directly.
Quality and test engineers verifying proactive threat hunting.
Solution architects designing proactive threat hunting.
Project managers delivering changes to proactive threat hunting.
Coordinators responsible for keeping records and documentation of proactive threat hunting current.
Course Modules
Proactive threat hunting: incident response and severity
2 sessions · 8 pointsSession 1What to measure in proactive threat hunting and what to ignore
- Prepare the response for the most likely failure in proactive threat hunting.
- Record what was learned when proactive threat hunting did not go as planned.
- Review logging on proactive threat hunting for coverage and retention.
- Confirm data retention and deletion rules applied within proactive threat hunting.
Session 2Setting availability and recovery targets for proactive threat hunting honestly
- Record the technical debt in proactive threat hunting and schedule repayment.
- State the availability and recovery objectives for proactive threat hunting as numbers.
- Identify single points of dependency in proactive threat hunting and reduce them.
- Set out how exceptions to proactive threat hunting are requested and approved.
Proactive threat hunting: monitoring, alerting and observability
2 sessions · 8 pointsSession 1What has to be agreed before work on proactive threat hunting starts
- Restore a backup of proactive threat hunting in a test environment and time it.
- Set delivery and reliability indicators for proactive threat hunting the team trusts.
- Distinguish symptoms from causes when proactive threat hunting underperforms.
- Define acceptance criteria for proactive threat hunting in advance.
Session 2Making releases of proactive threat hunting routine instead of risky
- Plan the sequence in which improvements to proactive threat hunting will be introduced.
- Benchmark the organisation's proactive threat hunting against comparable operations.
- Decide what will be stopped to create capacity for proactive threat hunting.
- Inventory third-party dependencies inside proactive threat hunting and their update status.
Proactive threat hunting: build, pipeline and release discipline
2 sessions · 8 pointsSession 1Dependencies and supply chain risk in proactive threat hunting
- Confirm that reporting on proactive threat hunting reaches the people who can act.
- Assess the exit route from any cloud or vendor dependency in proactive threat hunting.
- Confirm the support model and escalation path for proactive threat hunting.
- Confirm that those complying with proactive threat hunting understand why it exists.
Session 2Proving the backup of proactive threat hunting by restoring it
- Draft the minimum viable technical standard for proactive threat hunting.
- Build the competence framework that supports proactive threat hunting.
- Apply change control to proactive threat hunting including emergency changes.
- Rank the weaknesses in proactive threat hunting by consequence rather than by ease of fixing.
Proactive threat hunting: architecture and designing for failure
2 sessions · 8 pointsSession 1Building the method for proactive threat hunting step by step
- Identify the single points of failure in proactive threat hunting.
- Build the internal briefing that explains proactive threat hunting to those affected.
- Configure alerting on proactive threat hunting that reflects what users experience.
- Document the runbook for proactive threat hunting to the level a new engineer could use.
Session 2Monitoring proactive threat hunting from the user's point of view
- Establish the boundary of proactive threat hunting and record what sits outside it.
- Review access rights on proactive threat hunting and remove what is no longer needed.
- Measure current load on proactive threat hunting and project it forward twelve months.
- Test the failover for proactive threat hunting rather than assuming it works.
Choose the package that suits you
Silver Package
At least 3 people
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Gold Package
At least 3 people
- 5-night stay in a 5-star hotel
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Complete your registration
We will contact you within one business day to confirm.