Cyber incident management and first response

Cyberattacks can cause rapid damage and paralyse a business within hours. In this context, a structured methodology and trained teams are essential. This course gives IT and SOC teams the skills to detect, assess and handle a security incident through realistic case studies and hands-on exercises. You will learn to apply incident management best practices and respond more effectively in a crisis.

Programme

Day 1 - Fundamentals of incident management

Morning – 9 a.m. to 12:30 p.m.

Introduction to security incident management

  • Understanding what a security incident is and its impact on the business
  • Overview of common threats (ransomware, phishing, account compromise)
  • Roles and responsibilities within a response team
  • Incident lifecycle: detection, analysis, containment, eradication, recovery

Methodology and tools

  • Frameworks and best practices (ISO 27035, NIST, ANSSI)
  • Detection and correlation tools (SIEM, EDR, system logs)
  • Incident classification and prioritisation
  • Documentation and traceability of actions taken

Afternoon – 2 p.m. to 5:30 p.m.

Incident response procedures

  • Triage and escalation procedures
  • Containment and isolation strategies
  • Digital evidence preservation
  • Internal and external communication during an incident

Case studies and practical exercises

  • Ransomware attack scenario
  • Administrator account compromise scenario
  • Team-based simulated incident response
  • Debriefing and lessons learned

Day 2 - Crisis management and post-incident review

Morning – 9 a.m. to 12:30 p.m.

Real-time management

  • Setting up a crisis cell (war room)
  • Coordination between technical, legal and communications teams
  • Managing deadlines and priorities in an emergency
  • Interaction with authorities and external providers

Post-mortem analysis

  • Root cause analysis
  • Identifying areas for improvement
  • Writing an incident report
  • Knowledge sharing and procedure updates

Afternoon – 2 p.m. to 5:30 p.m.

Crisis management plan

  • Designing and structuring a cyber crisis management plan
  • Business continuity and recovery plans
  • Regulatory obligations and incident notification
  • Simulation exercise (tabletop exercise)

Wrap-up session

  • Summary of course learnings
  • Developing a personalised action plan
  • Overview of certifications and CPF procedures
  • Q&A

General information

€4,500 excl. VAT

Objective

Train teams to detect a cyber incident and respond effectively

Target audience

IT teams, SOC, system administrators

Level

Intermediate / Advanced

Duration

2 days

This course is delivered in partnership with Académie Cyber, a certified training provider. It is Qualiopi certified and eligible for CPF funding.

Qualiopi certification
Mon Compte Formation
Contact us

Other training courses offered by De Shagan Network

  • Application security and DevSecOps

    A simple bug can be an entry point for a cyberattack. Ensure your developers apply OWASP Top 10 best practices.

    Audience

    Developers, DevOps, IT teams

    Level

    Intermediate / Advanced

    Duration

    2 days

    Discover this course
  • Cloud environment security (AWS, Azure, Google Cloud)

    Cloud solutions (AWS, Azure, Google Cloud...) open the door to many cyber risks. Protect your business from data leaks or API attacks.

    Audience

    IT teams, cloud architects, DevOps

    Level

    Intermediate

    Duration

    1 day

    Discover this course