Cyber Incident Response and Recovery

Turn cyber incident response and recovery from a stated policy into a practice your organisation can evidence.

📍 Tripoli🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

Security arrangements around cyber incident response and recovery are tested by adversaries, not by auditors. Most security failures involving response and recovery exploit a process gap rather than a technical one. It is designed for mixed groups, so that this strand of corporate security practice is examined from more than one functional angle. The most reliable predictor of sound cyber incident response and recovery is whether anyone reviews it when nothing has gone wrong. Participants take away a working set of documents supporting the corporate security practice capability, ready to be adapted internally. Cases are chosen to expose the trade-offs in response and recovery rather than to illustrate ideal conditions. The programme is built to be used, and every section of cyber incident response and recovery it covers ends in something applicable. Buying a tool rarely fixes response and recovery; the underlying capability has to be built internally first. The final module sets out how progress on this area of corporate security practice will be evidenced six months later.

Expected Learning Outcomes

01

Align cyber incident response and recovery with the wider objectives of the protected site rather than optimising it in isolation.

02

Assess the current state of response and recovery against a structured set of criteria rather than impressions.

03

Build the investigation capability and evidence handling for cyber incident response and recovery.

04

Verify that improvements to response and recovery have held six months after they were introduced.

05

Identify vulnerabilities in cyber incident response and recovery and rank them by consequence.

06

Design surveillance coverage for response and recovery that supports investigation.

07

Protect information and intellectual property within cyber incident response and recovery.

Who Should Attend

01

Contract managers overseeing outsourced security in cyber incident response and recovery.

02

Facility and site managers accountable for protection of response and recovery.

03

Officers preparing reports on cyber incident response and recovery for boards or oversight committees.

04

Human resources staff handling vetting and insider risk in response and recovery.

05

Business partners who must understand cyber incident response and recovery well enough to challenge it.

06

Guard force supervisors delivering response and recovery.

Course Modules

01

Cyber incident response and recovery: layered controls — deter, detect, delay, respond

2 sessions · 8 points

Session 1Insider risk inside cyber incident response and recovery

  • Set escalation thresholds for cyber incident response and recovery that work out of hours.
  • Report on response and recovery in terms that support an investment decision.
  • Draft the minimum viable security procedure for cyber incident response and recovery.
  • Estimate the resource response and recovery requires to run as designed.

Session 2Coordinating with external authorities on response and recovery

  • Close out actions on cyber incident response and recovery rather than leaving them open indefinitely.
  • Identify the data already collected that bears on response and recovery.
  • Confirm that contractual obligations around cyber incident response and recovery are understood.
  • Supervise and spot-check performance on response and recovery rather than relying on reports.
02

Response and recovery: governance, assurance and investment case

2 sessions · 8 points

Session 1Surveillance on response and recovery that supports an investigation later

  • Prepare the response for the most likely failure in cyber incident response and recovery.
  • Set the review interval for response and recovery and who attends.
  • Prepare the summary of cyber incident response and recovery that senior management will read.
  • Build the internal briefing that explains response and recovery to those affected.

Session 2The first fifteen minutes of an incident involving response and recovery

  • Benchmark the organisation's cyber incident response and recovery against comparable operations.
  • Verify identity checks applied at entry points relevant to response and recovery.
  • Confirm recorded material from cyber incident response and recovery is retained long enough to be useful.
  • Review surveillance coverage for response and recovery against likely approach routes.
03

Response and recovery: procedures, access control and identity

2 sessions · 8 points

Session 1What has to be agreed before work on response and recovery starts

  • Confirm vetting standards applied to staff and contractors in cyber incident response and recovery.
  • Assess insider risk in roles with privileged access to response and recovery.
  • Coordinate arrangements for cyber incident response and recovery with civil defence and police in advance.
  • Check that records of response and recovery answer the questions likely to be asked.

Session 2Building lasting competence in cyber incident response and recovery

  • Establish evidence handling and chain of custody for cyber incident response and recovery.
  • Establish the boundary of response and recovery and record what sits outside it.
  • Protect sensitive information relating to cyber incident response and recovery from casual disclosure.
  • Check that controls on response and recovery cover deterrence, detection, delay and response.
04

Response and recovery: incident response and escalation

2 sessions · 8 points

Session 1Assessing the threat to response and recovery specifically, not generically

  • Arrange the handover of cyber incident response and recovery so capability survives staff changes.
  • Build the threat picture for response and recovery from sources relevant to this site and sector.
  • Verify six months later that changes to cyber incident response and recovery have held.
  • Define the first response actions for an incident involving response and recovery.

Session 2Keeping response and recovery alive after the initial push

  • Review cyber incident response and recovery after every incident, exercise or change in threat.
  • Establish who is informed, consulted and accountable in response and recovery.
  • Exercise the plan for cyber incident response and recovery under realistic conditions and record failures.
  • Set escalation criteria and out-of-hours contacts for response and recovery.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.