Group Purchasing
Group Purchasing
AI SKILLS

LDR553: Cyber Incident Management

LDR553Cybersecurity Leadership, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Steve Armstrong-Godwin
Steve Armstrong-Godwin
LDR553: Cyber Incident Management
Course authored by:
Steve Armstrong-Godwin
Steve Armstrong-Godwin
  • GIAC Cyber Incident Leader (GCIL)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 28 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Develop essential leadership skills to effectively manage major cyber incidents from discovery to resolution, providing clear direction when your organization needs it most.

Course Overview

While technical teams work to identify and remove attackers, they require strategic direction, management, and support to maximize their effectiveness. Cyber Incident Management focuses on the critical non-technical challenges facing leaders during high-pressure security incidents. This course equips you to lead incident management teams by providing a comprehensive understanding of immediate, short, and medium-term challenges organizations face during security breaches.

You will learn to build and manage teams, distill critical data for briefings, and communicate effectively with executives, board members, and other stakeholders. Through nine detailed case studies, you will gain hands-on experience in incident management methodology and practices applicable to various cybersecurity scenarios.

Strategic Cyber Incident Leadership & Management

While you cannot predict when a major cyber incident will hit your organization, you can control how ready you are to face it. In the aftermath, when incident response teams are engrossed in unraveling the attacker's moves within your networks, they often find themselves overwhelmed. This is where your incident management team steps in, taking charge of managing findings, communications, regulatory notifications, and remediation. With a multitude of tasks and challenges to address, many teams are unseasoned and unprepared for the magnitude of the responsibilities.

This course equips you to play a leading role in cyber incident management, whether as an incident commander, a manager, a team member, or a stakeholder who needs to guide and support the response. You will gain a comprehensive understanding of the immediate, short, and medium-term issues an organization might encounter. Beyond familiarizing yourself with the terminology, you will grasp preparatory actions at different stages to stay ahead of the situation. LDR553 is designed for efficient management of diverse incidents, with a primary focus on cyber, but you can apply the methodology, concepts, and guidance to various regular major and critical incidents.

Cyber Incident Management (IM) sits above Incident Response (IR) and manages incidents that get too big for the Security Operations Center (SOC) and IR. These tend to be the more impactful or larger scale incidents that IR is not staffed to handle, as these incidents require significant liaison with internal and external partners to coordinate the investigation, forensics, planning, recovery, and remediation, and to brief the corporate comms, C-level staff and board as needed.

A strong IR lead can sometimes fulfill the IM role, but during critical incidents IR teams are often shoulder-deep in malware, systems, logs and images to process, to the point where all technically capable IR staff are kept focused on technical tasks. More business focused than technical, the IM team will take the output from IR and relay it to the necessary teams as they coordinate wider investigations and conduct hardening, hygiene, and impact assessments, planning towards recovery.

Author Statement

"Of my 28 years in cyber security, I've spent over 12 of them in incident response and later incident management. This course is designed to demystify incident management, to provide attendees with a framework to not only deal with the matters at hand, but also to plan for the subsequent phases, so they are technically ready and mentally prepared. When you are prepared and ready, you can respond better and faster, and get control of the situation quicker, facilitating a rapid return to business as usual."

- Steve Armstrong-Godwin

What You'll Learn

  • Run briefings under pressure with minimal prep and deliver real impact
  • Lead meetings when the team is stressed, the facts are incomplete, and execs are impatient
  • Build and test your own GenAI tools to draft briefs, simulate reactions, and organize chaos
  • Survive a supply chain breach with minimal 3rd party support
  • Distinguish between technical facts, assumptions, and noise during incident response
  • Use the CIMTK framework to prioritize tasks and drive progress
  • Track attacker behavior, infrastructure risk, and team readiness in real time

Business Takeaways

  • Develop expert cyber incident management capabilities
  • Accelerate incident resolution with streamlined processes
  • Foster better vendor and legal coordination during third-party breach escalation
  • Improve team performance during critical incidents
  • Reduce workload without increasing risk with the integration of GenAI
  • Build stronger bridge between technical and non-technical functions during cyber events
  • Integrate threat intelligence to anticipate threats

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR553: Cyber Incident Management.

Section 1Understanding the Incident, Building the Team With GenAI, Scoping & Tracking the Impact

Section 1 focuses on understanding incidents, standardizing language, and defining objectives. You will gather information, set goals for the Incident Management team, and assign responsibilities. The section introduces the Cyber Incident Management Tool Kit (CIMTK), team composition, task tracking, and GenAI support.

Topics covered

  • Initial Information Gathering
  • Using Common Language
  • Defining Your Objectives
  • Who's On Our Team?
  • Building Our Communications Plan

Labs

  • Initial Setup at the Start of the Course
  • Initial Incident Briefing
  • CIMKT: The Grid and AIM-RADAR
  • Setting Objectives and Developing the Commander’s Intent
  • Making GPTs in OpenAI

Overview

In Section 1 we will focus on understanding the incident, gathering information from different groups, and standardizing our language. To assist in this, students will review some common terms, abbreviations and incident types to ensure we mean communicate accurately. From there we will define what the Incident Management (IM) group will seek to achieve, so we can state and focus on our objectives. The cornerstone of this phase is the Cyber Incident Management Tool Kit (CIMTK), specifically a key component called "The Grid." This comprehensive set of questions and core Incident Management (IM) tasks expedites our response. Identifying these tasks early allows for concurrent activities within support teams (Incident Response, Information Technology, Human Resources, Legal, etc.) and the IM team.

Defining objectives early is important, as retaining focus can be hard when our work gets busy. Once defined, we will leverage the “Commander’s Intent” as a method to brief teams, as we look at how to inform the wider group what our short- and medium-term goals are.

We segway into IM Platforms as we consider what we need to be able to do and where is safest to operate from as we review how attackers access defenders’ infrastructure to prevent their removal from the network.

Recognizing that effective Incident Management hinges on a strong team, we delve into assessing team composition and the unique contributions required from different groups to fulfill the mission. New for 2025, we are then including GenAI on the team bench, and throughout the course we will show how GenAI can augment and support the team. As we close off Section 1, we will consider the contribution from GenAI as we also build our first GPT for class use.

Note: The class uses a SANS provided OpenAI ChatGPT UI for the student’s use. We will extensively leverage this during the course. Students may use their own or different GenAI tools, but we will focus on and support ChatGPT.

Full Lab Details

  • Initial Setup at the Start of the Course
  • Initial incident briefing
  • CIMKT: The Grid and AIM-RADAR
  • Setting Objectives and Developing the Commander’s Intent
  • Making GPTs in OpenAI

Full Topic Details

  • Initial Information Gathering
    • Using common language
    • Categorizing the Incident
    • IR Frameworks, NIST Changes, OODA loops and non-zero-sum games
    • Tracking the incident in the AIM-RADAR
    • Scoping your initial tasks
  • Defining your Objectives
    • What are typical objectives in IR/IM?
    • Combat Information Overload with Commander's Intent
    • Mapping attacks to business impacts
  • Tracking the Incident, tasks, people and progress
    • Review of the functions we might want to include in our IM solution
    • Incident Trackers and what they can look like
    • Evidence management
    • Task and work tracking
    • Building the right solution for the organization
  • Who's on our Team?
    • Understanding the skills needed
    • Where should the team be located?
    • How big does the team need to be?
  • What GenAI is on your team?
    • Support IM with GenAI
  • Bonus Content
    • Using Google Docs as an emergency IM Platform

Section 2Communications, Planning and Executing Remediations

Section 2 explores communications in great depth as we look at interactions with executives, attackers, our staff and the public/customers. You will learn approaches that can buy time to address issues and prevent data leaks. You will categorize network and data damage, prioritize remediation tasks, and eliminate vulnerabilities.

Topics covered

  • Engaging with attackers
  • Tracking incidents and progress
  • Remediating damage and evaluating attacker removal options
  • Utilizing Root Cause Analysis (RAC) methods
  • Reporting and documenting cases

Labs

  • Crisis Comms: Briefing Executives and the Wider Organization
  • Crisis Comms: Dealing with Attackers
  • Crisis Comms: Drafting a Public Statement
  • Planning Data and System Remediation
  • Conducting Root Cause Analysis (RAC)

Overview

Following a quick recap, we commence a focused exploration of crisis communications, beginning with executive briefings on incident scope, objectives, and forward plans, using the Three What’s approach. From there, we examine strategies for managing communications with threat actors. While ransom payment may not feature in an organization’s plans, engaging in dialogue can sometimes buy valuable time to address vulnerabilities they have exposed or to avert potential data leaks. This is, of course, a contentious practice, with varying opinions across the industry; nonetheless, understanding the available options is essential. Lessons and labs will guide students through how such dialogue might occur, and the factors influencing both decision-making and process design.

We then turn to the remediation of network and data damage. Students will receive in-depth training in categorizing the impact of attacker activity, mapping the required remediation work, prioritizing actions, and ensuring all vulnerabilities are addressed. Particular attention will be paid to the often-overlooked presence of secrets within stolen data or compromised systems, and the implications these may have for future operations.

In the reporting and documentation phase, we review outputs from the Incident Management (IM) process. While a strong Incident Response (IR) report is important, students will explore additional elements needed to adapt it for IM purposes. This integration is vital, as Incident Management frequently guides the direction of Incident Response, allowing for a more coherent report and enabling the delegation of certain aspects to appropriate teams.

Finally, when planning for incident closure, we examine which remediation and vulnerability management tasks should transition into standard operational projects rather than remain under incident status. We will define effective reflection sessions to capture Root Cause Analysis (RCA) outputs and lessons learned, introducing the Five Whys method with examples of both strong and flawed applications.

The GenAI support on Section 2 is focused on producing briefs and formatting unstructured text for a consistent style and layout. Additionally, we use it for parsing information for a second opinion on received communications and ours before transmission to wider groups. More importantly we show how to cross-check before releasing work under our own name and reputation.

Full Lab Details

  • Crisis Comms: Briefing Execs
  • Crisis Comms: Dealing with the Attackers
  • Crisis Comms: Drafting a Public Statement
  • Crisis Comms: Briefing the Wider Organization
  • Planning Data and System Remediation
  • Conducting Root Cause Analysis (RAC)

Full Topic Details

  • How to Brief Executives
    • Structure, modality and frequency
  • Talking to or working with the attackers
    • Understanding what results the attackers are trying to achieve
    • Choosing a communications medium
    • Attacker media and comms methods
    • Proxies, trusted third parties and attacker reputation
    • Trying to control the narrative
    • Understanding what the attackers have
    • Options and impacts - The cost of doing nothing
  • Building our Communications Plan
    • Communications planning
    • Communicating with execs, teams, and third parties
  • Team Welfare and Battle Rhythm
    • Managing people to create productive teams
    • Stress, pressure and grief in the Workplace
  • Remediation of network and data damage
    • Types of remediation system & data
    • Tracking the remediation
    • CIMTK: Counter Compromise of systems and users impacted
    • Categorizing exposed assets
    • Identifying who owns the data
    • Documenting and notifying impacted parties - Counter Compromise Activities
  • Root Cause Analysis methods and outcomes
    • Understanding the need for a Root Cause Analysis meeting
    • Planning a good RCA (PALPATE)
  • Reporting and documenting the case
    • When do you start the report?
    • Types of reports
    • What goes in the report?
    • Graphics are great!
    • Getting input, support and consensus
    • Control and access to the reports
  • Planning the closure of the Incident
    • Reviewing the task and key objectives
    • Understanding Business-as-Usual (BAU) for impacted teams
    • Running an FRCA
    • Handing the ongoing initiatives to project managers
    • Breaking up the IM team

Section 3Training, Leveraging Cyber Threat Intelligence, Bug Bounties

Section 3 explores training IR teams and the broader organization. You will learn to develop effective training programs based on organizational maturity and specific needs. We examine integrating Cyber Threat Intelligence (CTI) into IR efforts and deep dive into developing strategies for managing supply chain and third-party compromises.

Topics covered

  • Developing the wider team
  • Analyzing training needs
  • Developing the SOC/IR/IM team
  • Leveraging Cyber Threat Intelligence
  • Third-Party Supply Chain Compromise

Labs

  • Choosing Cyber Training Exercises
  • Planning a Hotseat exercise
  • Submitting a Request For Intelligence (RFI)
  • Complete Third-Party Supply Chain Exercises

Overview

In this section, we dive deep into the training of Incident Response (IR) and Incident Management (IM), not only within our own teams but extending to the wider organization. We will explore the imperative need for training, considering the type of training required based on organizational maturity. Students will gain practical insights engaging in hands-on labs, including an exercise exemplifying the onboarding of non-IR personnel to cyber incidents.

Turning our attention to team training, we assess historical practices and their limitations in fostering individual growth and development. Emphasizing both long-term training strategies and engaging tactical exercises, we address specific gaps and areas where practical experience is needed, moving beyond mere frequency compliance.

Delving into the realm of Cyber Threat Intelligence (CTI), often featured prominently in the press, we address the common challenge of integrating CTI effectively into IR/IM efforts. Beyond its acquisition, we tackle the issue of maintaining CTI availability during an incident. Equipping participants with critical knowledge and a prep list, we empower them to leverage high-quality CTI during a Ransomware incident, supporting IR/IM efforts and executive decision-making. Furthermore, we explore how to provide input to the CTI team to optimize their skills and tools for local and strategic needs.

With the increasing prevalence of supply chain or third-party compromises, we extensively dissect the limitations when handling these incidents and strategies to improve our position. Through an in-depth case study of our Submarine Studios, we guide students to understand the scope, impact, and immediate remediation options, as well as investigative actions falling within our purview. We unravel the intricacies of planning a call with the third party, ensuring clarity of objectives, and navigating scenarios where required information may not be readily available. Lastly, we tackle the crucial aspect of when and how to effectively close a third-party incident.

The GenAI elements of Section 3 again fall into either validating the Incident Commanders ideas or parsing external information to simplify and clarify the meaning. This significantly unburdens the leaders allowing them time to focus on response. We will again build several bespoke GPTs to further enhance the tuning of our needs and to speed up future use of the configuration.

Full Lab Details

  • Choosing Cyber Training Exercises
  • Planning a Hotseat exercise
  • Submitting a Request For Intelligence (RFI)
  • Third-Party Supply Chain: Reviewing the incident notification
  • Third-Party Supply Chain: Assessing the impact and developing an RFI
  • Third-Party Supply Chain: Handling the Third-Party Call
  • Third-Party Supply Chain: Updating the Execs
  • Example table-top exercise for non-IM Specialists (homework lab)

Full Topic Details

  • Developing the wider team
    • Why train others?
    • Training the wider organization
    • Planning enterprise-wide training
    • Developing and running Cyber Incident Exercises
  • Developing the wider team
    • Types of training
    • Learning needs analysis
    • Maturity of exercises
  • Developing the SOC/IR/IM team
    • Working with and developing people in the exercises
    • Who to include in the exercises
    • External groups to include in exercises
    • Planning and running hotseat exercises
  • Leveraging Cyber Threat Intelligence
    • What is CTI?
    • Strategic/Operational/Tactical products
    • What can CTI produce for IM?
    • Developing CTI requirements
    • Generating a PIR
    • Avoiding common mistakes
    • Intelligence feedback loops
  • Third-Party Supply Chain Compromise
    • What is a supply chain and why is it attacked?
    • Notification routes
    • CIMTK: Third-Party compromise IM Planning
    • Analysis of the exposure
    • Planning around the data void
    • Developing a Request for Information (RFI) from the third party
    • Planning the third-party meeting
    • Closing third-party incidents

Section 4Cloud Incidents, Business Email Compromise, Credential Theft Attacks and Incident Metrics

In section 4 you will gain a comprehensive view, visualize incident timelines and address complex attack scenarios. You will learn to create timelines tailored to different audiences, understand credential theft attacks and the MITRE framework, and explore Business Email Compromise (BEC), as well as cloud-based attacks and management console breaches.

Topics covered

  • Timelines for Visualization
  • Defining Cloud Attacks
  • Credential Theft Attacks
  • Business Email Compromise (BEC)
  • Cloud Assets and Management Console Attacks

Labs

  • Reviewing Incident Timelines
  • Credential Loss Impact Assessment
  • BEC attack response
  • Cloud Management attack response

Overview

In response to the escalating complexity of incidents, our focus turns to visualizing key facts, with timelines as a powerful tool. However, we stress the importance of careful scoping, because a poorly conceived timeline that is not tailored to the target audience risks confusion and fails to convey the intended message. Our exploration delves into the art of scoping timelines, exploring various styles, and drawing insights from case studies that exemplify different perspectives on the same incident.

Before delving into Business Email Compromise (BEC) and other Cloud-focused attacks, we clarify aspects of responsibility and attack focuses, referring to prevalent cloud and MITRE models. Credential attacks take center stage, probing what attackers seek to obtain and how they leverage credentials, intricately linking back to the MITRE framework. We analyze attacker options, from breaking in and harvesting credentials to purchasing access. We scrutinize concepts like Initial Access Brokers, Underground Marketplaces, and various user targeting strategies, including MFA fatigue and Illicit Consent Attacks.

With stolen credentials as our foundation, we embark on an in-depth exploration of BEC, elucidating its stages and examining the crucial Incident Management (IM) support it necessitates. This extends to supporting legal arguments, determining liability, and directing Incident Response (IR) efforts for forensics. Addressing the aftermath of a third-party compromise, we unravel the complexities of discussions where a supplier's compromise impacts the client's financial loss.

We continue by dissecting the nuances of the six-plus types of BEC attacks, delineating the attacker's position and the affected parties. Our detailed breakdown serves as a template for easier BEC investigations, complemented by a hands-on lab in which we challenge participants with an underrated investigative influence: Doubt in everything you see and are told.

Navigating the cloud model, our focus shifts to Infrastructure as a Service (IaaS) host compromise, examining vectors, impacts, investigation requirements, and the nuanced management of cleanup for completeness.

We explore cloud management console compromises, assessing their impact, investigative approaches, and the requisite cleanup strategies. We also touch on preventive controls and the origins of the attacker's credentials, emphasizing that, for certain attackers, the management console is a means to an end, shaped by attacker motivation rather than the defensive measures of the blue team.

We conclude this section by looking at how to improve the team by working with others, linking to other teams and groups. We will consider KPIs and internal metrics: what they can show you, and what they can hide. As IM is largely focused on big impact incidents, we will look at the wider DR for the organization and how you can tap into those teams, processes and exercises for a smoother operation.

There are no set GenAI labs for this Section as the labs focus around updating and reviewing progress in various trackers, something that GenAI struggles with. Additionally, the BEC is too complex for GenAI to reliably identify the attacker or the altered documents. This reinforces the fact that GenAI is a great support tool but cannot replace all the activities of a capable IR and IM team.

Full Lab Details

  • Reviewing Incident Timelines
  • Credential Loss Impact Assessment
  • We paid the wrong account! (BEC)
  • The cloud bill is vast (Cloud Management attack)

Full Topic Details

  • Timelines for visualization
    • Scoping the timeline
    • Considering the audience
    • Levels of detail
  • Defining Cloud Attacks
    • Shared responsibility models
    • MITRE for Cloud reference
  • Credential Theft Attacks
    • What attackers are after and why
    • BYOD vectors
    • How do attackers get the access they want?
    • Credential Harvesting
    • Underground Marketplaces
    • Initial Access Brokers
    • Malicious Browser Extensions
    • Password Manager Attacks
    • MFA Fatigue
    • Illicit Consent Grant Attacks
    • CIMTK: Credential Loss Immediate Actions (CLIA)
  • Business Email Compromise (BEC)
    • Stages of BEC
    • MITRE Refence to O365
    • Where does liability fall?
    • Supporting Legal staff
    • Detailed step through the 6+ types of BEC
    • Points to understand to support BEC
    • Inbox investigations
    • Multi-site and multi-vendor compromises
    • CIMTK: BEC Initial Actions (BECIA)
  • Cloud Asset Attack
    • MITRE TTPs for Cloud Assets
    • Differences between Cloud and On-Prem
    • Finding the Pivot
    • How do we Forensicate the Cloud Virtual Machines?
    • Closing Policy Holes and Network Gaps
  • Cloud Management Console Attacks
    • Defining the attack and the goals
    • Goals for the Attacker
    • Focusing the team
    • Policy Checks and leveraging Auditors
    • Considering the other vectors to 'touch' the console
    • Cloud Focused RCA
    • Reporting the Incident
  • Improving IR/IM
    • Policies, playbooks and run books
    • People vs. Tools
    • Metrics vs. KPIs, what's the difference?
    • The message behind the metrics
    • Leveraging outside groups
    • Getting in on the DR party
    • Relationship management and approaches with different groups

Section 5AI for Incidents, Attacker Extortion, Ransomware, and Capstone Exercise

Section 5 examines AI applications, including Large Language Models and Generative AI. You will gain in-depth knowledge of ransomware incidents from examining historic cases and considering how to prepare and train to deal with encryption events.

Topics covered

  • Leveraging AI for IM
  • Ransomware
  • Summary and review
  • Capstone Exercise

Labs

  • Updating the public statement
  • Leveraging AI and LLM in IM
  • Reviewing Ransomware cases
  • Capstone exercise

Overview

In this final section, we will address some of the wider issues organization’s face when dealing with ransomware. Before doing so, we conclude our Submarine Studios scenario by considering a return to the public domain with a final press statement announcing the arrest of our attackers. This transitional lab challenges students to consider the notion that “there is no such thing as bad PR.”

Having made extensive use of Generative AI throughout the course, it is essential to conclude by examining the potential pitfalls and threats associated with its use. We begin by unpacking the often loosely applied term Artificial Intelligence, breaking it into its distinct categories — including Natural Language Processing (NLP), Neural Networks, Generative AI, Machine Learning, and Robotics — before narrowing our focus to Large Language Models (LLMs) and Generative AI tools (such as ChatGPT).

With this clearer understanding, we can make more informed decisions about where, when, and how to apply these technologies effectively. We will also address the inherent risks of AI, with particular attention to the issue of hallucinations, and explore strategies to minimize their impact.

Finally, as part of our LLM exercise, students will engage with a deliberately compromised chatbot to assess its behavior, identify indicators of compromise, and determine whether vulnerabilities are present. This hands-on investigation mirrors the real-world incident in which Submarine Studios’ third-party provider was compromised, enabling participants to connect theoretical learning with a practical case study.

Ransomware dominates cybersecurity headlines and remains one of the most significant threats keeping CISOs and Boards awake at night. In this section, we will explore its evolution — from early attacks to the sophisticated operations of today — and dissect the stages of a ransomware compromise. Students will examine where detection opportunities were missed as attackers progressed from initial access to the final stage of encryption.

We will discuss how to direct the Incident Response (IR) team in investigating the attack, while examining the Incident Manager’s (IM) role in coordinating efforts, maintaining context, and pressing executives for timely decisions. Building on knowledge from earlier sessions — including team exercises, planning, cloud compromises, and credential-based attacks — we will develop strategies to reduce the impact of ransomware incidents and preserve both network integrity and organizational operations.

Students will analyze the alerts commonly signaling the onset of a ransomware event, linking them to specific stages of the attack and clarifying what has occurred. We will cross-map these indicators with potential “instant checks” and consider how automation could provide early warning during an adversary’s preparatory phase.

Clear, decisive communication will be a recurring focus — ensuring that executives fully understand the available options and their consequences. We will introduce the concept of “no-regret” options and discuss the operational implications of “going dark.” Building on earlier discussions of attacker engagement, we will explore the planning and execution of ransom negotiations, supported by practical exercises.

Finally, we will address the importance of conducting investigations in parallel with remediation, enabling the organization to prevent repeat compromises regardless of the decision to pay or refuse a ransom. We will consider the technical and procedural requirements for network rebuilding and identify the records and evidence needed to support recovery. Students will also recognize the critical value of documenting all decisions, recording impacts, and maintaining detailed system and availability data — ensuring that in the inevitable hindsight review, there is a complete and accountable record of who knew what, when, and where.

Full Lab Details

  • Updating the public statement
  • Leveraging AI and LLM in IM
  • Reviewing Ransomware cases
  • Capstone exercise

Full Topic Details

  • Leveraging AI for IM
    • What do we mean by AI?
    • What AI can we use, and where?
    • What is a Large Language Model (LLM), and are they all the same?
    • Risks associated with leveraging LLMs
    • Is there such a thing as a bad LLM? Are they evil?
    • ChatGPT syntax and prompt considerations
  • Ransomware
    • The history of ransomware
    • The stages of a ransomware compromise from start to end
    • How the dirty get dirtier
    • Does size matter?
    • Planning to meet the threat
    • Exercising to meet the threat
    • What are the DR options?
    • What are the key questions to answer?
    • What do executives really want?
    • Remember to breathe
    • Documenting the impacts/reports and decisions
    • If you do nothing else, do this when you get back to work
    • CIMTK: Ransomware Initial Actions (RIA)
  • Summary and review of the sessions
    • How to use the understanding from the course
    • What to do on Monday/Day 1 when back in the office
    • How to move the super tanker
    • What does success look like?
    • How to continue to grow and improve
  • Capstone Exercise
    • Address a multi-stage time-sensitive incident
    • Conduct analysis of reports
    • Read policies and procedures and create plans
    • Brief Leadership and Executives on your plans
    • Develop an initial end-of-day summary

Things You Need To Know

Important! Bring your own system configured according to these instructions!

A laptop or mobile device with the latest web browser is required to access the Cloud stored files (Google Docs or Dropbox) that form the Cyber Incident Management Tool Kit (CIMTK) used in the course.

The CIMTK used in this course was built and is hosted on Google Drive and Google Suite. Students must have a computer that can connect to either Dropbox or Google Suite services. Corporate machines may have a VPN, intercepting proxy, or egress firewall filter that causes connection issues communicating with AS. Students must be able to configure or disable these services to be able to access Google Suite.

Due to the interoperability between MS Office and Google Docs and Google Spreadsheets, students will be able to complete all course labs using MS Office. Some of the takeaway files and components of the CIMKT were built on Google Spreadsheets, and we are 99% confident that they will work on MS Office. However, due to the frequent updates and changes to both platforms we cannot guarantee this, so students will be asked to use Google Docs if they find their Office-based program is not functioning as expected.

Students will be issued a SANS ChatGPT account for use during the course. While they are welcome to use other Generative AI tools, primary support will be provided for the OpenAI-based toolset.

If you have additional questions about the laptop specifications, please contact customer service.

LDR553 training is recommended for a diverse range of individuals, including:

  • Security Managers
    • Newly appointed information security officers who will be leading incidents
    • Recently promoted security leaders who want to understand incident management better
  • Security Professionals
    • Technically skilled security staff who have recently been given incident commander responsibilities
    • Team leads with responsibility to support cyber incidents and who may need to remediate systems
  • Managers
    • Managers who want to understand how to manage technical people during an incident
    • Leaders who need an understanding of cyber incidents from a management perspective
  • Legal/HR/PR staff
    • Staff who are new to cyber incident management but may be called upon to provide critical support in tense situations and who want to understand better what may be expected from them

The GIAC Cyber Incident Leader (GCIL) certification validates a practitioner’s ability to manage cyber incidents and lead a diverse incident management (IM) team to restore normal operations. GCIL holders demonstrate expertise in preparing for, assessing, handling, tracking, and documenting incidents; developing IM teams; managing vulnerabilities, threats, and attacks; facilitating communication; and improving IM processes.

  • Preparing for, assessing, remediating and closing an incident
  • Developing, managing and improving the IM team and process
  • Identifying threats, vulnerabilities and common malicious attacks, and handling each incident type
  • Managing incident tasks and facilitating communications

More Certification Details

  • Printed course books
  • Online Electronic workbook for all the lab exercises
  • The Cyber Incident Management Tool Kit
  • MP3 audio files of the complete course lecture
  • Detailed video walkthroughs of the lab exercises
  • Access to a new Slack and a Discord server to chat about the course
  • Immediate actions for dealing with Ransomware
  • Training plans, report templates, incident frameworks and other cheat sheets

This course covers the core areas of cyber incident management and assumes a basic understanding of technology, networks, and security. For those new to the field with no background knowledge, the recommended starting point is SEC401: Security Essentials – Network, Endpoint, and Cloud.

LDR553: Cyber Incident Management is part of the SANS Cybersecurity Leadership curriculum and the Cyber Risk Officer Triad, alongside LDR512: Security Leadership Essentials for Managers and LDR519: Cybersecurity Risk Management and Compliance. Together, these three courses provide a holistic blueprint for modern cyber risk officers—whether stepping into leadership from technical ranks or leveling up within executive roles. The triad develops leaders who not only understand how to build, govern, and respond, but who can unify teams under pressure and steer organizations through complexity with clarity and resilience.

Cyber Incident Management coordinates the response to significant security breaches that overwhelm regular SOC/IR teams. It focuses on business impacts, stakeholder communications, and strategic decisions rather than on technical details. Managers lead cross-functional teams, communicate with executives, and orchestrate recovery while IR handles technical investigation.

This is a unique offering, no other vendor covers Incident Management in such depth, supported by an entire-course real-world scenario where every lab is based upon a real case handled by the author a veteran of IR and IM. This course develops highly in-demand leadership skills for managing critical incidents. You will gain expertise in team coordination, executive communication, and strategic decision-making during cyber crises—capabilities increasingly needed as organizations face sophisticated attacks. The practical case studies provide confidence in handling real-world scenarios, positioning you for advancement to security leadership roles.

Relevant Job Roles

Cyber Risk Officer

Cybersecurity Leadership

Lead cybersecurity risk strategy at the highest level.

Explore learning path

Incident Management (USUP)

Skills Framework for the Information Age

Co-ordination of detection, response, and recovery activities across teams and systems. Emphasis is placed on minimising impact, restoring services, and maintaining clear communication during disruptions.

Explore learning path

Cyber Incident Responder Training, Salary, and Career Path

European Cybersecurity Skills Framework

Monitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.

Explore learning path

Systems Security Management (OPM 722)

NICE: Oversight and Governance

Responsible for managing the cybersecurity of a program, organization, system, or enclave.

Explore learning path

Senior Security Leader

Cybersecurity Leadership

Daily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.

Explore learning path

Governance (GOVN)

Skills Framework for the Information Age

Development of frameworks that align technology use with business objectives and regulatory requirements. Focus areas include policy design, risk controls, and enterprise accountability structures.

Explore learning path

Cybersecurity Instruction (OPM 712)

NICE: Oversight and Governance

Responsible for developing and conducting cybersecurity awareness, training, or education.

Explore learning path

SOC Manager

Cybersecurity Leadership

Security Operations Center (SOC) managers bridge the gap between business processes and the highly technical work that goes on in the SOC. They direct SOC operations and are responsible for hiring and training, creating and executing cybersecurity strategy, and leading the company’s response to major security threats.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 13

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources