Security incident management: master response and IT resilience
During a cyberattack, coordination matters as much as technology. Structure incident assessment, handling and follow-up to organise your response effectively. Develop an approach to documenting decisions and learning from incidents.
- Duration
- 3 days 21 hours
- Code
- ARI004FR Code
Presentation
As ransomware, phishing and distributed denial-of-service (DDoS) attacks increase, the question is no longer whether your organisation will be affected, but when. Poorly managed incidents can halt operations, cause critical data loss and damage reputation long term. Without structured processes, panic undermines effectiveness and worsens technical and financial consequences.
This intensive 3-day course develops essential skills for leading agile, professional incident response. Explore international ISO 27035 and NIST frameworks and advanced detection techniques to move from a reactive to a proactive security posture. Through realistic scenario simulations, learn to classify threats, contain attacks and conduct rigorous digital investigations.
By the end, you will be able to coordinate a CSIRT and restore systems securely. Master detection tools such as SIEM and IDS/IPS and crisis communication protocols, including GDPR-related legal notifications. This expertise supports optimal IT resilience against current digital threats.
Objectives
By the end of this course, you will be able to:
- understand incident management's fundamental challenges and methodological principles;
- accurately identify and classify security incidents by type and severity;
- implement a structured response process covering analysis, containment and eradication;
- use advanced technical tools for detection, alerting and log analysis, including SIEM and IDS;
- develop crisis communication and post-incident business continuity plans.
Program
Module 1: Mastering the foundations and preparation
- Defining objectives and analysing incident types: malware, phishing, ransomware and DDoS.
- Understanding reference standards and frameworks, including ISO 27035-1:2023 and NIST.
- Establishing a CSIRT and identifying necessary resources.
Hands-on exercises
- Brainstorm major incidents experienced by a company.
- Create a detailed preparedness plan for a major IT incident.
Module 2: Managing the incident management process
- Organising key stages: identification, analysis, containment, eradication and recovery.
- Clearly defining roles, responsibilities and documentation needs.
- Developing a rigorous management policy and decision workflows.
Hands-on exercises
- Develop an incident management workflow adapted to a company's constraints.
Module 3: Automating threat detection and classification
- Using strategic information sources, including logs, SIEM and IDS/IPS.
- Defining severity and prioritisation criteria and implementing automated alerts.
Hands-on exercises
- Analyse technical logs to identify and assess a security incident.
Module 4: Conducting technical analysis and digital forensics
- Digital evidence collection and preservation methodology.
- Using forensic investigation techniques and tools.
Hands-on exercises
- Simulate a complete forensic analysis of a compromised workstation.
Module 5: Executing response, containment and eradication
- Deploying containment strategies to stop propagation.
- Eradicating root causes and restoring systems securely.
Hands-on exercises
- Deploy a targeted containment plan against a ransomware attack.
Module 6: Structuring communication and continuous improvement
- Managing internal and external communication and crisis public relations.
- Regulatory compliance: notifying authorities under GDPR, including the CNIL.
- Lessons-learned reviews and security procedure updates.
Hands-on exercises
- Write a professional incident report for senior management.
- Develop a post-incident improvement plan to strengthen overall defences.
Module 7: Mastering overall management through full-scale simulation
- Coordinating teams during a multi-vector attack.
- Evaluating response performance and appropriateness.
Hands-on exercises
- Manage a complete incident under realistic conditions through a full-scale simulation.
Audience
This course is intended for professionals ensuring digital service continuity, including:
- CISOs structuring effective response strategies aligned with international standards;
- system and network administrators containing attacks and restoring compromised infrastructure;
- SOC teams and security analysts refining detection methods and digital forensic skills;
- IT project managers integrating resilience and crisis management into project lifecycles;
- anyone involved in incident management seeking a rigorous methodology to limit cyberattack impacts.
Prerequisites
The following prerequisites apply:
- Technical skills: sound general IT security knowledge;
- Infrastructure: good familiarity with operating systems and network architectures.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Full practical immersion: learn through numerous workshops and a comprehensive full-scale simulation reproducing real cyberattacks.
- Global standards alignment: master management processes based on recognised ISO 27035 and NIST frameworks.
- Technical proficiency: use practical detection tools such as SIEM and IDS and forensic tools for immediate technical independence.
- Communication and legal focus: manage GDPR notification obligations and crisis communication to protect organisational reputation.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en