Cyber Incident Response and Digital Crisis Management

Turn cyber incident response from a stated policy into a practice your organisation can evidence.

📍 Abu Dhabi🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

Boards are asking for measurable returns from cyber incident response, not demonstrations. The constraint on the practice within digital and data-driven work is rarely the model or the platform — it is the data and the operating discipline behind it. Teams frequently over-invest in documenting this area of digital and data-driven work and under-invest in testing it. It is appropriate for those preparing to take on wider responsibility for cyber incident response. Benchmarking exercises repeatedly place this strand of digital and data-driven work among the areas with the widest performance spread. Every module pairs a short input on the practice within digital and data-driven work with structured practice on the participant's own material. The programme is built to be used, and every section of cyber incident response it covers ends in something applicable. The result is the confidence to make and defend decisions about this strand of digital and data-driven work under scrutiny. The programme ends where implementation begins, with this part of digital and data-driven work broken into steps someone can start on Monday.

Expected Learning Outcomes

01

Prepare the human side of cyber incident response: who is retrained, who is redeployed, and when they are told.

02

Establish what evidence would demonstrate that cyber incident response is under control.

03

Agree the retirement plan for the legacy process cyber incident response replaces.

04

Translate policy on cyber incident response into procedures that hold up under day-to-day pressure.

05

Plan the migration path for cyber incident response without an extended outage or a parallel-running trap.

06

Design the pilot for cyber incident response so its result is decisive rather than merely encouraging.

07

Plan the handover of cyber incident response so that capability is not lost when key staff move on.

Who Should Attend

01

Consultants and advisers supporting clients on cyber incident response.

02

Coordinators responsible for keeping records and documentation of cyber incident response current.

03

Business analysts translating requirements for cyber incident response.

04

Risk and compliance staff assessing the controls around cyber incident response.

05

Chief information officers accountable for the investment in cyber incident response.

06

Solution architects designing how cyber incident response fits the existing estate.

Course Modules

01

Cyber incident response: business case, scope and the data it depends on

2 sessions · 8 points

Session 1Choosing a supplier for cyber incident response without being captured

  • Identify every system cyber incident response must read from or write to.
  • Measure the current quality of the data feeding cyber incident response before assuming it is usable.
  • Confirm that reporting on cyber incident response reaches the people who can act.
  • Define the exit route from the supplier supporting cyber incident response.

Session 2The data question everyone skips at the start of cyber incident response

  • Estimate compute and licensing cost for cyber incident response at expected and at peak load.
  • Set the metrics that will show whether cyber incident response is drifting from its intended behaviour.
  • Distinguish symptoms from causes when cyber incident response underperforms.
  • List the data sources cyber incident response consumes and confirm each has a named owner.
02

Cyber incident response: architecture, integration and the existing estate

2 sessions · 8 points

Session 1Making cyber incident response work when resources are constrained

  • Identify where judgement in cyber incident response is legitimate and where it is not.
  • Establish who is informed, consulted and accountable in cyber incident response.
  • Build the competence framework that supports cyber incident response.
  • Test the procedure for cyber incident response against a realistic scenario.

Session 2The pilot that actually settles the argument about cyber incident response

  • Set escalation thresholds for cyber incident response that work out of hours.
  • Prepare the summary of cyber incident response that senior management will read.
  • Agree who is on call for cyber incident response outside working hours.
  • Design the pilot for cyber incident response so that a negative result is still useful.
03

Cyber incident response: vendor selection and avoiding lock-in

2 sessions · 8 points

Session 1Who owns cyber incident response once the project team disbands

  • Remove steps in cyber incident response that add effort without adding assurance.
  • Plan the sequence in which improvements to cyber incident response will be introduced.
  • Assess the regulatory obligations cyber incident response triggers in each jurisdiction.
  • Close out actions on cyber incident response rather than leaving them open indefinitely.

Session 2Comparing cyber incident response with recognised practice

  • Confirm the retention and deletion rules applied to data inside cyber incident response.
  • Identify the skills the team lacks to operate cyber incident response independently.
  • Record what was learned when cyber incident response did not go as planned.
  • Verify that cyber incident response still performs when input volume doubles unexpectedly.
04

Cyber incident response: cost, licensing and total running expense

2 sessions · 8 points

Session 1The cost of cyber incident response and how to present it

  • Rehearse the briefing on cyber incident response that would follow an incident.
  • Compare the cost of cyber incident response with the cost of its absence.
  • Estimate the resource cyber incident response requires to run as designed.
  • Decide which legacy process cyber incident response retires, and set the date.

Session 2Making cyber incident response secure without making it unusable

  • Specify the fallback path when cyber incident response is unavailable.
  • Classify the data in cyber incident response and apply access controls that match the classification.
  • Build the user briefing that explains what cyber incident response does and does not decide.
  • Confirm that contractual obligations around cyber incident response are understood.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.