homepage
Menu
Open menu
  • Training
    Go one level top Back

    Training

    • Courses

      Build cyber prowess with training from renowned experts

    • Hands-On Simulations

      Hands-on learning exercises keep you at the top of your cyber game

    • Certifications

      Demonstrate cybersecurity expertise with GIAC certifications

    • Ways to Train

      Multiple training options to best fit your schedule and preferred learning style

    • Training Events & Summits

      Expert-led training at locations around the world

    • Free Training Events

      Upcoming workshops, webinars and local events

    • Security Awareness

      Harden enterprise security with end-user and role-based training

    Featured

    Get a Free Hour of SANS Training

    Free Course Demos

    Can't find what you are looking for?

    Let us help.
    Contact us
  • Learning Paths
    Go one level top Back

    Learning Paths

    • By Focus Area

      Chart your path to job-specific training courses

    • By NICE Framework

      Navigate cybersecurity training through NICE framework roles

    • DoDD 8140 Work Roles

      US DoD 8140 Directive Frameworks

    • By European Skills Framework

      Align your enterprise cyber skills with ECSF profiles

    • By Skills Roadmap

      Find the right training path based on critical skills

    • New to Cyber

      Give your cybersecurity career the right foundation for success

    • Leadership

      Training designed to help security leaders reduce organizational risk

    • Degree and Certificate Programs

      Gain the skills, certifications, and confidence to launch or advance your cybersecurity career.

    Featured: Solutions for Emerging Risks

    New to Cyber resources

    Start your career
  • Community Resources
    Go one level top Back

    Community Resources

    Watch & Listen

    • Webinars
    • Live Streams
    • Podcasts

    Read

    • Blog
    • Newsletters
    • White Papers
    • Internet Storm Center

    Download

    • Open Source Tools
    • Posters & Cheat Sheets
    • Policy Templates
    • Summit Presentations
    • SANS Community Benefits

      Connect, learn, and share with other cybersecurity professionals

    • CISO Network

      Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders

  • For Organizations
    Go one level top Back

    For Organizations

    Team Development

    • Why Partner with SANS
    • Group Purchasing
    • Skills & Talent Assessments
    • Private & Custom Training

    Leadership Development

    • Leadership Courses & Accreditation
    • Executive Cybersecurity Exercises
    • CISO Network

    Security Awareness

    • End-User Training
    • Phishing Simulation
    • Specialized Role-Based Training
    • Risk Assessments
    • Public Sector Partnerships

      Explore industry-specific programming and customized training solutions

    • Sponsorship Opportunities

      Sponsor a SANS event or research paper

    Interested in developing a training plan to fit your organization’s needs?

    We're here to help.
    Contact us
  • Talk with an expert
  • Log In
  • Join - it's free
  • Account
    • Account Dashboard
    • Log Out
  1. Home >
  2. Blog >
  3. LDR553: Cyber Incident Management – Now 5 Days!
Steve_Armstrong-Godwin_340x340.png
Steve Armstrong-Godwin

LDR553: Cyber Incident Management – Now 5 Days!

What’s new and why it matters

July 31, 2023

Just over a year ago I was launched the BETA of the MGT553 2-day Cyber Incident Management Course with the SANS Institute. The MGT553 course was originally developed in response to a Law Enforcement request to help them train their staff to better support major incidents that are regularly hitting large and small organisations.

I think what we built was unique in the market, and content wise, full of real-world cases and examples -- well I have been doing this for a while (my LinkedIn profile). The course sold well especially OnDemand and as it was written during COVID with that modality in mind.

The problem we had was the two-day limit - so sorry if you were in one of my classes that ran past 5pm. However, just over six months after MGT553 went into full production I was asked to expand it to five days! So if you wondered why I've been quiet on here, I've been writing 3 days of courseware and 18 new labs(!)

The new course, now branded under the Leadership abbreviation LDR (LDR553) being five days allows us to expand out some important topics (staff development and training) and to deep dive into lots of different incident types.

Below, I'll outline some of the new elements and to explain some of the design choices made.

Changes over MGT553

As you can imagine the main change is having the extra three days which has allowed me to bring some great new elements to the course. I'll touch on a few of the big additions in this post and over the coming months I'll pick out some others to highlight.

Team Development and IM Training - this was at the end of an already busy session two, but we have moved it to session three and have expanded it to talk about how to build good exercises and how to have fun with them. We cover how plan your exercises and how to run some great Table Top eXercises (TTXs) with almost no props and only about 30 mins planning.

So what new stuff did we add? Well..... here's some of the bigger chunks:

Cyber Threat Intelligence (CTI), is common place in many SOC/IR teams, but outside of these security teams awareness is generally low. As a result, CTTI is often that untaped resource in terms of incident support. So we look at what CTI can provide before and during incidents. So when you call for help they have templates of what they can do and how.

I've found that by considering what you might need before an incident you can get the CTI staff draft some glossy one-pager guides on Tactics, Techniques and Procedures (TTPs) used by the threat actors CTI are tracking as most likely to hit your organisation. This means you are super prepared with a quality product you can share with Execs and IM teams to inform them about their current adversary.

Timing wise we positioned this module before Supply Chain Attacks as many's-a-time my team has been tasked to undertake some Open Source Intelligence (OSINT) analysis of our partners to see if we can learn more about their just-notified attack and/or the attacker.

But some of you are probably thinking:

"Steve, in an supply chain attack there is no IR/IM work to do, what you covering?"

Well, I'm glad you asked!

Communication is an underlying theme on this course and a Supply Chain Attack is probably the pinnacle: Here, our goal is to assess the supplier notifications, comprehend the associated impact, and solicit further details as required. To support this we look at planning communications with suppliers (assuming that an opportunity for direct dialogue arises) and possibly leveraging our relationship (contractual and personal) to get the most information possible and the assurances we need for our execs (whom will then need briefing).

The accompanying Supply Chain Attack labs are fun, real-world-level frustrating and built upon actual cases. As we battle some of the tactics deployed by vendors to avoid direct answers we hope to equip students with the ability to identify such techniques but also allows us to try to defeat them, or at least learn these dark ways incase they need to stall in the future.

Having dealt with numerous instances of Business Email Compromise (BEC), I included a comprehensive module on these financially devastating attacks. By delving into the origins of such attacks and analysing the six distinct types of BEC, attendees have a deeper understanding of the attack's origins and can potentially support Legal as they work to allocate responsibility for ensuing financial losses. Our lab exercises have a captivating head-scratcher scenario inspired by real-life cases that make them my personal favourite.

Ransomware is a big subject and something that is probably one of the top risks for most businesses and because it leverages many of the issues we cover throughout the course we put this at the end. In this longer module we consider the stages of a ransomware attack, the relationship between Ransomware as a Service (RaaS) operators, Initial Access Brokers and Credential Theft attackers as well as the parts they play.

As we are not a technical course (try Ryan Chapman's Ransomware for Incident Responders course (FOR528) for that), we will look at the decisions/options that Execs will want to have, the types and volume of information they will need to make those decisions and how you get better at responding.

We'll dig into the sorts of things you want to be fast at for the the Golden Hour from initial impact and the challenges and goals for the first 24 hours. We will then review several public ransomware cases to see where things when wrong for the victims and if their response was the best course of action.

The Capstone lab is a time-sensitive high stress one that we believe will work both live in person, LiveOnline and OnDemand the main thing that will change is the number of people on you team and thus the level of work you will need to complete to be the best.

Sharing Experience

One of the different approaches we will be trying on this course is the use of open Polls to let people see how others think. As we go through the course and labs we will pose questions as we would in class about different aspects of incidents, labs and hot topics. To link Live, LiveOnline and OnDemand students we will use open polls where we pose a question, students go to a site and answer the question (the Poll) and after voting they get to see how others have voted. This will hopefully allow people to see if their thinking aligns with that of others.

Availability and Formats

We are launching the LDR553 in a BETA at the October London conference and in early 2024 it should be available on general release and OnDemand.

We haven't worked out the dates of the 2024 teaches, but given SANS finds the Hybrid (Live in person and LiveOnline) formats popular, I believe all teaches will be in this format. Location wise, I'm hoping to teach in the US and EU/APAC on alternative months to enable people to get to a Live in person event within a reasonable traveling distance.

Tune In To My Webcast

  1. On Wednesday, 13 September at 10 am ET | 1400 UTC | 1500 BST I am hosting a new webcast and would love to have you join me. You came with that plan? You’re braver than I thought! will look at how to start running some fun IR incidents that you can scale super easily. We'll look at how you optimise inter-team relations and start to significantly reduce your response and decisive reaction times.

Learning Objectives:

  • Learn how to develop Fun Tabletop Exercises
  • Learn how to easily set low cost up quick technical artifacts for exercises
  • Understand who else can get involved for key incident experience
  • See how to develop a 6-month exercise plan to mature selected team aspects

Registration is free. If you cannot make it at the scheduled time, you can still register and download the slides and view the recording afterwards.

Wrap up

So there you go, that's a high level summary of some of the key changes we introduced when we developed LDR553. I think it's a solid base, I've been able to include the common attacks that impact all organisations, so students will be prepared to develop and improve their organisations to better detect, respond and recover for major attacks and incidents.

A reminder that the October course is a BETA (it's a reduced price as this is the first classroom run of the course), some things might not run to plan like class timings, but they should be close. Offered in Live in Person and LiveOnline at the October Event in London it will be a hoot. The post BETA class will not start until about February 2024 and the OnDemand version will probably not be until about February/March 2024.

I'd love to see you at the BETA, but hurry, it's only been announced two days and already it's selling well. There is about £1500 discount (1800 Euros) over the regular price.

Learn more about LDR553: Cyber Incident Management.

Share:
TwitterLinkedInFacebook
Copy url Url was copied to clipboard
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Cote D'ivoire
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Macedonia
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania, United Republic Of
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City State
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Recommended Training

  • LDR519: Cybersecurity Risk Management and Compliance™
  • LDR512: Security Leadership Essentials for Managers™
  • LDR514: Security Strategic Planning, Policy, and Leadership™

Tags:
  • Cybersecurity Leadership

Related Content

Blog
leadership blog image.png
Cybersecurity Leadership
May 13, 2024
A Visual Summary of SANS Cybersecurity Leadership Summit 2024
Check out these graphic recordings created in real-time throughout the event for SANS Cybersecurity Leadership Summit 2024
No Headshot Available
Alison Kim
read more
Blog
SANS Cybersecurity Leadership
Cybersecurity Leadership
February 16, 2024
A Three-Slide Executive Presentation?
Learn all about the newly updated Security Strategic Planning, Policy, and Leadership Course; LDR514.
370x370_Frank-Kim.jpg
Frank Kim
read more
Blog
CurriculumTile_340_x_340.png
Cybersecurity Leadership
December 5, 2023
New Challenge Coin for SANS LDR521 Security Culture for Leaders!
Perceptions. Attitudes. Beliefs. Explain the why then simplify.
370x370_Lance-Spitzner.jpg
Lance Spitzner
read more
  • Company
  • Mission
  • Instructors
  • About
  • FAQ
  • Press
  • Contact Us
  • Careers
  • Policies
  • Training Programs
  • Work Study
  • Academies & Scholarships
  • Public Sector Partnerships
  • Law Enforcement
  • SkillsFuture Singapore
  • Degree Programs
  • Get Involved
  • Join the Community
  • Become an Instructor
  • Become a Sponsor
  • Speak at a Summit
  • Join the CISO Network
  • Award Programs
  • Partner Portal
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Cote D'ivoire
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Macedonia
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania, United Republic Of
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City State
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
  • Privacy Policy
  • Terms and Conditions
  • Do Not Sell/Share My Personal Information
  • Contact
  • Careers
© 2025 The Escal Institute of Advanced Technologies, Inc. d/b/a SANS Institute. Our Terms and Conditions detail our trademark and copyright rights. Any unauthorized use is expressly prohibited.
  • Twitter
  • Facebook
  • Youtube
  • LinkedIn