Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Ransomware and Cyber Extortion Response

Ransomware response is an operational problem before it becomes a forensic one. This course walks the whole event: containing spread, working out how far the attacker reached, deciding whether data left the building, and restarting the business in a sensible order.

The extortion side is covered honestly too, including how negotiation actually works, what payment does and does not buy, and the Canadian reporting obligations that follow a breach.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
Advanced Incident Response and Threat Hunting
Class size
Capped at 12 learners
Ransomware and Cyber Extortion Response

What you will be able to do

  • Contain an active ransomware event without erasing the evidence you need
  • Identify the initial access point and the accounts the attacker controlled
  • Assess whether backups were reached and whether they can be trusted
  • Build an evidence-based position on whether data was exfiltrated
  • Sequence recovery so identity and core services come back first
  • Brief executives on options, costs and unknowns without guessing
  • Explain how PIPEDA breach reporting duties are triggered by your findings
  • Produce a hardening plan that closes the path actually used

Course outline

6 modules

  • Confirming what you are actually dealing with
  • Containment that does not destroy evidence
  • Isolating domain controllers, hypervisors and backup systems
  • Standing up out of band communications
  • Deciding who to call, in what order, and why

What you need before you start

  • Incident response experience or the advanced hunting course
  • Familiarity with Windows domains, backups and virtualisation
  • A machine capable of running two virtual machines at once
  • Willingness to take part in exercises that involve decisions under pressure

Who this course is for

  • Incident responders who will lead ransomware engagements
  • IT and infrastructure leads responsible for recovery
  • Security managers who must brief executives during an event
  • Consultants supporting clients and insurers through extortion cases
  • Business continuity staff who plan for destructive attacks

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.