Secure the software supply chain and dependencies within critical cyber incident response.
Designing Response Strategies for Critical Cyber Incidents
Practical training in critical cyber incident response, grounded in real cases and applied to your own operation.
Course Overview
Security and delivery speed are traded against each other in critical cyber incident response whether or not anyone says so. Systems supporting incident response fail in ways that are obvious afterwards and invisible before. Participants who influence the practice within technology and systems delivery without directly controlling it will find the content directly usable. The outcome is a practitioner who can hold a position on critical cyber incident response and revise it on evidence. The course covers this aspect of technology and systems delivery at the level of detail needed to act, and stops there. The programme uses small-group work so that each participant's treatment of incident response is examined, not just described. Most organisations already have a policy on critical cyber incident response; far fewer can show it working. Post-incident reviews keep identifying weaknesses in incident response that were visible long before the incident. The course ends by identifying what the participant will stop doing to make this part of technology and systems delivery sustainable.
Expected Learning Outcomes
Translate policy on incident response into procedures that hold up under day-to-day pressure.
Document critical cyber incident response to the level a new engineer could operate it.
Design backup and recovery for incident response and prove it by restoring.
Assign clear ownership for each element of critical cyber incident response across the functions involved.
Reduce avoidable variation in how incident response is carried out across teams.
Assess and manage third-party and cloud dependencies in critical cyber incident response.
Who Should Attend
Network and communications engineers supporting critical cyber incident response.
Solution architects designing incident response.
Team leaders and supervisors who put critical cyber incident response into practice day to day.
Planning staff whose forecasts and budgets are affected by incident response.
Software engineers and technical leads building critical cyber incident response.
IT managers and service owners responsible for incident response.
Course Modules
Critical cyber incident response: security, identity and least privilege
2 sessions · 8 pointsSession 1Retiring the legacy part of critical cyber incident response
- Inventory third-party dependencies inside critical cyber incident response and their update status.
- Configure alerting on incident response that reflects what users experience.
- Check that critical cyber incident response still works when volumes rise unexpectedly.
- Review logging on incident response for coverage and retention.
Session 2The cost of incident response and how to present it
- Define incident severity levels for critical cyber incident response and the response each triggers.
- Prepare the response for the most likely failure in incident response.
- Confirm every release of critical cyber incident response can be rolled back within a defined time.
- Restore a backup of incident response in a test environment and time it.
Incident response: build, pipeline and release discipline
2 sessions · 8 pointsSession 1The hard cases in incident response and how to reason about them
- Decide what will be stopped to create capacity for critical cyber incident response.
- State the availability and recovery objectives for incident response as numbers.
- Establish who is informed, consulted and accountable in critical cyber incident response.
- Identify the single points of failure in incident response.
Session 2The change to incident response that caused the last outage
- Apply change control to critical cyber incident response including emergency changes.
- Confirm that those complying with incident response understand why it exists.
- Record the technical debt in critical cyber incident response and schedule repayment.
- Measure current load on incident response and project it forward twelve months.
Incident response: documentation, support and handover
2 sessions · 8 pointsSession 1Escalation and decision rights in incident response
- Reduce the variation in how critical cyber incident response is carried out between teams.
- Build the competence framework that supports incident response.
- Name a single owner for each element of critical cyber incident response.
- Set delivery and reliability indicators for incident response the team trusts.
Session 2Documenting critical cyber incident response so someone else can operate it
- Confirm data retention and deletion rules applied within critical cyber incident response.
- Distinguish symptoms from causes when incident response underperforms.
- Test the procedure for critical cyber incident response against a realistic scenario.
- Establish what evidence demonstrates incident response is under control.
Incident response: change control and rollback
2 sessions · 8 pointsSession 1Proving the backup of incident response by restoring it
- Assess the exit route from any cloud or vendor dependency in critical cyber incident response.
- Write down the assumptions underpinning the approach to incident response.
- Test the failover for critical cyber incident response rather than assuming it works.
- Identify the data already collected that bears on incident response.
Session 2Designing incident response around how it will fail
- Anticipate the objections critical cyber incident response will raise and prepare the answers.
- Document the runbook for incident response to the level a new engineer could use.
- Assign responsibility for keeping documentation of critical cyber incident response current.
- Define the trigger that would require incident response to be redesigned.
Choose the package that suits you
Silver Package
At least 3 people
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Gold Package
At least 3 people
- 5-night stay in a 5-star hotel
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Complete your registration
We will contact you within one business day to confirm.