Anticipate and manage a cyber crisis to protect your organisation
A crisis is easier to manage when roles and scenarios have been prepared. Structure your response arrangements, clarify decisions and organise coordination between stakeholders. Strengthen your ability to anticipate disruptions and support business continuity.
- Duration
- 2 days 14 hours
- Code
- ARI003FR Code
Presentation
A cyberattack is no longer a question of if, but when. During an incident, every minute lost has a cost in data, reputation and money. This intensive 2-day course turns panic into a structured response, helping you manage a crisis with the same confidence as a planned shutdown.
Beyond technical considerations, you will define key roles, validate the cyber crisis management plan and train your team to detect early warning signs before they become crippling. Internal communication, media management and evidence preservation: each scenario is simulated in real time, under time pressure, with video feedback.
You will leave with a ready-to-use crisis playbook, a step-by-step remediation procedure and a lessons-learned methodology. The result: faster recovery, a protected reputation and reliable indicators to help management justify security investments.
Objectives
By the end of this course, you will be able to:
- understand the specific characteristics and dynamics of a cyber crisis;
- structure and establish an effective crisis management organisation;
- detect early warning signs to identify a cyberattack as soon as possible;
- activate the Crisis Management Plan (CMP) and Business Continuity Plan (BCP);
- manage crisis communication with employees and the media;
- use lessons learned to strengthen crisis management arrangements.
Program
Module 1: Understanding how a cyber crisis unfolds
- The fundamentals and specific challenges of a cyber-related crisis.
- Overview of current threats and their potential impact.
Case studies
- Analysis of recent major incidents.
Module 2: Preparing for and anticipating an attack
- Establishing operational crisis management arrangements.
- Developing and testing contingency plans: BCP and CMP.
- Identifying critical assets and mapping vulnerabilities.
- Raising employee awareness and training staff in secure behaviours.
Module 3: Detecting the incident and activating the crisis team
- Recognising early warning signs and indicators of compromise.
- The escalation process and rapid team mobilisation.
- Activating technical, decision-making and communications teams.
- Coordinating with authorities and external stakeholders.
Module 4: Leading the operational response
- Technical containment and attack remediation.
- Mobilising internal teams and managing specialist providers.
- Managing communication: developing key messages and media relations.
- Complying with legal and reporting obligations involving CNIL, ANSSI and insurers.
Module 5: Organising the return to normal operations
- Planning the gradual resumption of activities.
- Accurately assessing damage and strengthening systems.
- Conducting a lessons-learned review and developing a continuous improvement plan.
- Implementing lasting new security measures.
Audience
This course is intended for decision-makers and operational resilience stakeholders, including:
- CISOs and CIOs leading the operational response and coordinating technical teams under pressure;
- senior leaders and executive committee members who bear legal responsibility and must make rapid strategic decisions;
- risk and business continuity managers responsible for activating BCPs to limit business impact;
- functional crisis team members in communications, legal and HR who manage reputation, reporting obligations and the internal working climate.
Prerequisites
The following prerequisite applies:
- Basic knowledge: familiarity with cybersecurity and crisis management fundamentals is recommended to maximise the benefits of the course.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Case study
Course highlights
- Immersive learning: test your responses through crisis simulations and realistic scenarios.
- Cross-functional approach: address the crisis from technical, legal, organisational and communications perspectives.
- Operational deliverables: work on developing your CMP and BCP and leave with usable practical guides.
- Field expertise: benefit from certified experts with real experience managing cyber incidents.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
#CybersecurityGovernance
fr
en