Live Online Course

BCT Certificate in Cyber Incident Management (NCSC Assured Training) (Live Online)

2 Days
£1,500.00 + VAT 

Our BCT Certificate in Cyber Incident Management course is a two day non-technical course, aimed at preparing organisations to manage their cyber response at the strategic/crisis management level. Topics include cyber risk assessments, playbook development, GDPR reporting incidents and reputation management. The course includes a 1 hour multiple choice exam taken individually after the training.

What’s included?

  • Electronic course slides
  • Electronic certificate
  • Exam

Details

Course Description 

“Thankfully, we now live in a world where it is accepted that data breaches happen and organisations are more comfortable disclosing that they have been victim to an attack. However, with this welcome move away from victim blaming, organisations are now being judged more on how well they manage a breach.” – Brian Honan, ComputerWeekly

Over the last few years the number of cyber incidents has grown, affecting organisations large and small. High profile incidents such as Sony, TalkTalk, and the Petya and NHS ransomware attacks, have had a major impact on the operations and reputation of the organisations.

Our BCT Certificate in Cyber Incident Management training course is not a technical response, but looks at the actions organisations can take to prepare themselves, and how they should manage a cyber incident, including very importantly, how to manage communications associated with the incident. It will also look at the types of cyber attacks, the cyber landscape and how to exercise your cyber response plan.

Delegates will learn how to prepare their organisation, how to develop an effective response and how to manage an incident should it occur.

The BCT Certificate in Cyber Incident Management course is based on good practice from a variety of government and private organisations. The course has been certified by NCSC and is the only certified course which deals with reputational issues associated with the preparing for and responding to a cyber incident.

This Cyber Incident Management course includes a 1 hour multiple choice exam taken individually after the training. Once you have been registered for the exam, you will have 30 days to complete it. Delegates will receive an email from APMG by the end of day 1 of the course to set up an account and access the exam. A score of 70% is required to pass.

The BCT Certificate in Cyber Incident Management training course is delivered as a two day, live online training course. Scheduled breaks will be provided within each session. During the course, delegates will be able to use their microphones to take part in discussions and ask the tutor any questions, there is also the option to use a webcam too. Interactivity features used during the training may include the use of breakout sessions for group work, polls and quizzes. The course is delivered via GoToTraining.

We recommend purchasing the online knowledge check questions to help with revision. With a pool of over 125 questions based on the course and unlimited attempts during the 30 days’ access, they are the ideal revision tool.

The timings for this training are 9am-4pm UK time.

The cost of this course (ex VAT) is £1,500.00 / €1,760.00 / $1,910.00.

Course Modules

Module 1 - Cyber Incident Threat Landscape and Essential Knowledge
  • Definitions
  • Number of different case studies
  • Different types of cyber threats
  • Who are the different threat actors?
  • What are the threat vectors
  • Cyber incident impacts
  • Cyber threats to your industry
  • Cyber video and discussion
Module 2 - Prepare - Understanding your Impacts, Vulnerabilities and Risks
  • Understanding your organisation’s vulnerabilities
  • Questions to ask to understand your information security culture, cyber preparation and awareness
  • Incident reporting helpline
  • Measuring cyber preparation and maturity
  • Understanding what you have to lose and conducting a cyber data risk assessment
Module 3 - Prepare - Developing a Cyber Incident Management Framework
  • Reviewing and developing your cyber policy and guidance
  • Developing a cyber incident response team
  • Developing scenario responses
  • Developing decision and scenario based playbooks
  • Third party support, insurance and cyber intelligence
Module 4 - Prepare - Awareness & Cyber Exercises
  • What do senior managers need to know about cyber
  • Cyber exercise scenarios
  • Styles of exercises
  • Exercising at different levels within the organisation
  • Making exercises realistic
  • Hints and tips for successful exercises
Module 5 - Respond - Overview of Incident Management and Technical Cyber Response
  • Incident response overview – what are we trying to achieve
  • Difference between a cyber and a ‘normal’ incident
  • React, Respond, Resolve framework for managing incidents
  • Identifying the cyber incident
  • Triaging incidents
  • Cyber impact assessment
  • Kill Chains and Diamond Model
  • Forensics, investigations and third-party response
Module 6 - Crisis Management & Reporting
  • Situational awareness and OODA loop
  • Use of situation – direction – action
  • Incident decision making
  • Information management
  • Setting of incident objectives
  • Statutory and regulatory reporting including GDPR requirements
Module 7 - Respond - Crisis Communications and Reputation Management
  • Communications case study – Equifax
  • Communications pre-incident preparation
  • Managing your organisation’s communications with customers, stakeholders and the media
  • Stakeholder information requirements
  • Developing a communications strategy
  • Cyber attack ‘victim or villain’
Module 8 - Recovery
  • Use of existing business continuity plans, DR and crisis plans to help lessen the impact of the incident
Final Response Exercise
  • Exercise Athena – opportunity to bring all the knowledge together during an exercise

Upcoming Courses

Just looking for a price?

Request a quote below to have a member of the team come back to you with a price tailored to you.

Request Quote

Download Course Details

Download Brochure - BCT Certificate in Cyber Incident Management (NCSC Assured Training) (Live Online)

Download your own copy of the brochure below, with full details on the course, including course content and FAQs.

Programme

Day 1
Day 2
Day 1
09:00 - 09:15
Introduction
09:15 - 10:30
Module 1 - Cyber Incident Threat Landscape and Essential Knowledge
- Definitions - Number of different case studies - Different types of cyber threats - Who are the different threat actors? - What are the threat vectors - Cyber incident impacts - Cyber threats to your industry - Cyber video and discussion
10:30 - 10:45
Break
10:45 - 12:00
Module 2 - Prepare - Understanding your Impacts, Vulnerabilities and Risks
- Understanding your organisation’s vulnerabilities - Questions to ask to understand your information security culture, cyber preparation and awareness - Incident reporting helpline - Measuring cyber preparation and maturity - Understanding what you have to lose and conducting a cyber data risk assessment
12:00 - 13:00
Lunch
13:00 - 13:45
Module 3 - Prepare - Developing a Cyber Incident Management Framework
- Reviewing and developing your cyber policy and guidance - Developing a cyber incident response team - Developing scenario responses - Developing decision and scenario based playbooks - Third party support, insurance and cyber intelligence
13:45 - 14:30
Module 4 - Prepare - Awareness & Cyber Exercises
- What do senior managers need to know about cyber - Cyber exercise scenarios - Styles of exercises - Exercising at different levels within the organisation - Making exercises realistic - Hints and tips for successful exercises
14:30 - 14:45
Break
14:45 - 15:45
Module 5 - Respond - Overview of Incident Management and Technical Cyber Response
- Incident response overview - what are we trying to achieve - Difference between a cyber and a 'normal' incident - React, Respond, Resolve framework for managing incidents - Identifying the cyber incident - Triaging incidents - Cyber impact assessment - Kill Chains and Diamond Model - Forensics, investigations and third-party response
15:45 - 16:00
Review of Day 1
Day 2

Please note, timings are indicative and exact timings may vary due to delegate experience and their interest in certain topics. The course may finish earlier if all topics have been covered.

Course Benefits

By the end of the BCT Certificate in Cyber Incident Management course you will be able to:

  • Understand the different types of cyber attack and cyber incident landscape
  • Look at the preparation which can be carried out prior to a cyber incident occurring
  • Create a cyber playbook
  • Identify the responses and issues associated with responding to a cyber attack
  • Plan and run a cyber exercise

What are the benefits of choosing NCSC Assured Training?

  • Individuals and organisations can easily and quickly identify high quality, relevant training
  • The course materials have been rigorously assessed against the exacting standards of NCSC
  • The quality of the trainers’ delivery and the course administration has been quality checked
  • The training is based on the industry-respected IISP Skills Framework
  • NCSC assured training is invaluable for anyone seeking to acquire or improve their cyber security skills, including those seeking the NCSC’s Certified Professional status (CCP)
  • NCSC assured courses identify training which delivers what it says it will

Completing this course will contribute towards your BCI Continuing Professional Development (CPD). Further information can be found on the BCI’s website here.

Who Should Attend?

  • Business continuity and resilience managers
  • IT managers
  • CIOs and CTOs
  • Crisis managers
  • Members of crisis management teams or those responsible for crisis management and crisis communications

Exam FAQs

Is the cost of the exam included in the cost of the BCT Certificate in Cyber Incident Management course?

The cost of the exam is included in the course cost.

What does the exam consist of?

The examination consists of 50 multiple choice questions which the candidate will have 1 hour to complete.

What is the pass mark?

A score of 70% is required to pass the exam.

Is it a closed or open book exam?

The exam is closed book.

When can I take the exam?

The exam is taken online by delegates individually after the training. The exam must be taken within 30 days and we recommend sitting the exam within 7 days of completing the course. Please note, if you require an extension to your exam access, an admin fee will apply.

Delegates will receive an email from APMG by the end of day 1 of the course to set up an account and access the exam.

How can I prepare for the exam?

We advise reading through the course materials and revising thoroughly before sitting the exam (we recommend a minimum of 10 hours of individual study). The more preparation you do, the better prepared you will be for the exam. We recommend purchasing the online knowledge check questions to help with your revision. With a pool of over 125 questions based on the course and unlimited attempts during your 30 days’ access, they are the ideal revision tool. Access to the recordings of the training sessions to help with revision are available upon request.

What are the technical requirements for the exam?

It is strongly recommended to use a personal computer and a wired internet connection (ideally with a minimum speed of 10 Mbps Download, 5 Mbps Upload). Sitting this examination will involve software installation and proctor control over your computer. If you are planning to take the exam at work, please speak to your IT Department and thoroughly read through the ProctorU FAQs linked below.

Before the examination begins, the proctor will go through some administration which can take approximately 20 minutes. During this time, the proctor will complete technical checks, take an ID picture and go through the exam rules. We advise ensuring your schedule is clear for at least 1 hour after your exam is scheduled to finish in case of any delays.

Please click on the following link for further information regarding online exam registration for online ProctorU exams: https://www.b-c-training.com/i…

Please click on the following link to ProctorU FAQs: https://www.b-c-training.com/i…

What language can I sit the exam in?

The exam is only available in English.

In-House Options

If you would like the BCT Certificate in Cyber Incident Management course delivered privately for your organisation, please contact the BC Training team on 01253 542650 or email info@b-c-training.co.uk.

Testimonials

“Charlie [Maclean-Bristol] was a great tutor, both knowledgeable and approachable. A great course!”

Gary Stevenson

Student Loans Company

“Eamonn [Keane] is a very friendly, funny and likeable character, with extensive knowledge and a clear passion for his profession.”

Daron Parmar

British Gas

“Great instructor, excellent background in the subject area, wonderful discussions with the group. I found the whole experience fantastic. Great group of people and good course. Will recommend.”

Alison Brown

Kyndryl

Sign-up to our Newsletter

"*" indicates required fields