Group Purchasing
Group Purchasing

What Is the GCIL Certification?

The GCIL certification confirms you can manage a cyber incident from declaration to closure and lead a mixed incident management team back to normal operations. GCIL holders show they can prepare for, assess, handle, track, and document incidents, while building and improving the team and process behind the response.

By the numbers

2 hrs

Exam duration

75

Questions

70%

Min. passing score

What GCIL Covers

The certification's objectives group into five practical domains that match LDR553's five sections.

Incident Preparation and Assessment

Covers Incident Preparation, Incident Assessment, Incident Tracking, and Incident Management Team Preparation, the groundwork for standing up a response.

Communications and Remediation

Covers Incident Communications, Incident Remediation and Closure, and Incident Reporting, the work of briefing stakeholders and closing an incident cleanly.

Team Development and Threat Management

Covers Incident Management Team Development, Incident Management Improvement, Supply Chain Attacks, and Vulnerability and Threat Management.

Attack-Specific Response

Covers Cloud Attacks, Email Attacks, and Credential Attacks, the incident types most incident commanders are called to direct.

Ransomware Response

Covers Ransomware Attacks, the incident type most likely to draw on every other skill in the certification at once.

Prepare With This Course

LDR553: Cyber Incident Management

How LDR553 Prepares You for GCIL

LDR553 is built around the exam objectives that make up the GCIL certification: 

  • Section 1, Understanding the Incident, Building the Team With GenAI, Scoping and Tracking the Impact builds skills tested under Incident Preparation, Incident Assessment, Incident Tracking, and Incident Management Team Preparation.
  • Section 2, Communications, Planning and Executing Remediations aligns with Incident Communications, Incident Remediation and Closure, and Incident Reporting.
  • Section 3, Training, Leveraging Intelligence, Third-Party Compromise, and Bug Bounties builds skills tested under Incident Management Team Development, Incident Management Improvement, Supply Chain Attacks, and Vulnerability and Threat Management.
  • Section 4, Cloud, Business Email Compromise, and Credential Theft Attacks aligns with Cloud Attacks, Email Attacks, and Credential Attacks.
  • Section 5, AI for Incidents, Attacker Extortion, Ransomware, and Capstone Exercise builds skills tested under Ransomware Attacks, pulling the whole course together in a capstone exercise.

Across all five sections, 27 hands-on labs and a capstone exercise built on the continuous Submarine Studios scenario give you the chance to apply each skill in a live incident scenario before you sit the exam. 

Read the full GCIL certification overview 

LDR553 Author

Steve Armstrong-Godwin
Steve Armstrong-Godwin

Steve Armstrong-Godwin

Lead of Security Incident Response and Threat Management at Danske Bank

Steve Armstrong-Godwin brings 30+ years in incident management and response across defence, consulting, multinational business, financial services, gaming, and national military cyber operations.

Read more about Steve Armstrong-Godwin

Who Should Pursue GCIL

Newly Appointed Incident Managers

Security and SOC Managers

Security Professionals Given IR Responsibility

CISOs and Information Security Officers

Legal, HR, and Communications Staff

Compliance and Privacy Officers

Frequently Asked Questions

The GCIL certification proves you can manage a cyber incident from declaration to closure and lead a mixed incident management team back to normal operations. GCIL holders show they can prepare for, assess, handle, track, and document incidents, develop and improve the incident management team and process, and identify and respond to the specific incident types (cloud, email, credential, ransomware, and supply chain attacks) that make up the bulk of major incidents. 

The GCIL exam is one proctored exam with 75 questions over 2 hours, with a minimum passing score of 70%. GIAC periodically reviews exam specifications, so confirm the current format in your GIAC account before you sit the exam. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GCIL is built for security professionals responsible for managing incidents, incident managers, security and information security managers and team leads, SOC managers, IR team leads, compliance and privacy officers, CISOs and information security officers, and legal, HR, PR, and communications staff who need to know what will be expected of them once an incident is declared. It also fits newly appointed security officers and technically skilled staff who've recently been given incident commander responsibilities. 

LDR553: Cyber Incident Management is the SANS course built to prepare you for the GCIL exam. It's a 5-day, 30-hour course, available in-person, live virtual, or OnDemand self-paced, built around a single continuous incident scenario that maps directly to the certification's exam objectives across its five sections. LDR553: Cyber Incident Management 

Ready to earn your GCIL certification?

Add the GCIL exam attempt when you register for LDR553.

Already trained? Register for the exam directly through GIAC here.