Live Online Courses

NCSC Certified Managing & Preparing for Cyber Incidents
Live Online Course

BCM-IT 2 Days £1,050.00 (+ VAT)

Course Overview/Dates

A two day non-technical course, aimed at preparing organisations to manage their cyber response at the strategic/crisis management level. Topics include cyber risk assessments, playbook development, GDPR reporting incidents and reputation management.

This training course is delivered as a two day, live online training course. Scheduled breaks will be provided within each session. During the course, delegates will be able to use their microphones to take part in discussions and ask the tutor any questions, there is also the option to use a webcam too. Interactivity features used during the training may include the use of breakout sessions for group work, polls and quizzes. The course is delivered via GoToTraining.

Timings are indicative and exact timings may vary due to student experience and their interest in certain topics. The course may finish earlier if all topics have been covered.

Timetable

Day 1 09.30-12.30 BST 13.30-16.30 BST
Day 2 09.30-12.30 BST 13.30-16.30 BST

What's included?

  • Course slides
  • Certificate of attendance

Course Dates

Dates Number of days Location Price
Mon 6 Sep 2021
£1,050.00 Book
Course tutor: Charlie Maclean-Bristol MA (Hons), PgD, FBCI, FEPS
Back to top

Details & Programme

Over the last few years the number of cyber incidents has grown, affecting organisations large and small. High profile incidents such as Sony, TalkTalk, and the Petya and NHS ransomware attacks, have had a major impact on the operations and reputation of the organisations.

"Thankfully, we now live in a world where it is accepted that data breaches happen and organisations are more comfortable disclosing that they have been victim to an attack. However, with this welcome move away from victim blaming, organisations are now being judged more on how well they manage a breach." - Brian Honan, ComputerWeekly

This training course is not a technical response, but looks at the actions organisations can take to prepare themselves, and how they should manage a cyber incident, including very importantly, how to manage communications associated with the incident. It will also look at the types of cyber attacks, the cyber landscape and how to exercise your cyber response plan.

Delegates will learn how to prepare their organisation, how to develop an effective response and how to manage an incident should it occur.

The course is based on good practice from a variety of government and private organisations. This course has been certified by NCSC and is the only certified course which deals with reputational issues associated with the preparing for and responding to a cyber incident.

Modules

Module 1: Cyber Threats and Landscape

  • Definitions
  • Number of different case studies
  • Different types of cyber threats
  • Who are the different threat actors?
  • What are the threat vectors
  • Cyber incident impacts
  • Cyber threats to your industry
  • Cyber video and discussion

Module 2: Prepare - Understanding your vulnerabilities and risks

  • Understanding your organisation’s vulnerabilities
  • Questions to ask to understand your information security culture, cyber preparation and awareness
  • Incident reporting helpline
  • Measuring cyber preparation and maturity
  • Understanding what you have to lose and conducting a cyber data risk assessment

Module 3: Prepare - Developing a cyber incident response framework

  • Reviewing and developing your cyber policy and guidance
  • Developing a cyber incident response team
  • Developing scenario responses
  • Developing decision and scenario based playbooks
  • Third party support, insurance and cyber intelligence

Module 4: Prepare - Awareness and Cyber Exercises

  • What do senior managers need to know about cyber
  • Cyber exercise scenarios
  • Styles of exercises
  • Exercising at different levels within the organisation
  • Making exercises realistic
  • Hints and tips for successful exercises

Module 5: Respond - Overview of incident management and technical cyber response

  • Incident response overview - what are we trying to achieve
  • Difference between a cyber and a 'normal' incident
  • React, Respond, Resolve framework for managing incidents
  • Identifying the cyber incident
  • Triaging incidents
  • Cyber impact assessment
  • Kill Chains and Diamond Model
  • Forensics, investigations and third-party response

Module 6: Respond - Executive Incident Management

  • Situational awareness and OODA loop
  • Use of situation - direction - action
  • Incident decision making
  • Information management
  • Setting of incident objectives
  • Statutory and regulatory reporting including GDPR requirements

Module 7: Respond - Crisis Communications and Reputation Management

  • Communications case study- Equifax
  • Communications pre-incident preparation
  • Managing your organisation's communications with customers, stakeholders and the media
  • Stakeholder information requirements
  • Developing a communications strategy
  • Cyber attack 'victim or villain'

Module 8: Recovery - Using existing BC plans to recover operations

  • Use of existing business continuity plans, DR and crisis plans to help lessen the impact of the incident

Final response exercise

  • Exercise Athena - opportunity to bring all the knowledge together during an exercise
Back to top

Course Benefits

Completing this course will enable you to:

  • Understand the different types of cyber attack and cyber incident landscape
  • Look at the preparation which can be carried out prior to a cyber incident occurring
  • Create a cyber playbook
  • Identify the responses and issues associated with responding to a cyber attack
  • Plan and run a cyber exercise

What are the benefits of choosing NCSC Certified Training?

  • Individuals and organisations can easily and quickly identify high quality, relevant training
  • The course materials have been rigorously assessed against the exacting standards of NCSC
  • The quality of the trainers’ delivery and the course administration has been quality checked
  • The training is based on the industry-respected IISP Skills Framework
  • NCSC certified training is invaluable for anyone seeking to acquire or improve their cyber security skills, including those seeking the NCSC's Certified Professional status (CCP)
  • NCSC certified courses identify training which delivers what it says it will
Back to top

Who Should Attend?

  • Business continuity and resilience managers
  • IT managers
  • CIOs and CTOs
  • Crisis managers
  • Members of crisis management teams or those responsible for crisis management and crisis communications
Back to top

Tutors

Charlie Maclean-Bristol

Charlie Maclean-Bristol

MA (Hons), PgD, FBCI, FEPS

Back to top

In-house Options

If you would like this training delivered for your organisation only, please contact the BC Training team on 01253 542650 or email info@b-c-training.co.uk.

Back to top

Locations

Writing Incident Scenarios: An Operational Resilience Trend Returns

Writing Incident Scenarios: An Operational Resilience Trend Returns

Catalogue request from Becca

Catalogue request from Becca

It's OK, it’s in the Cloud: Lessons from the Fire in the OVHcloud Data Centre

It's OK, it’s in the Cloud: Lessons from the Fire in the OVHcloud Data Centre

Catalogue request from Steff

Catalogue request from Steff

Operational Resilience: Is it just business continuity done properly?

Operational Resilience: Is it just business continuity done properly?

Demonstrating business continuity's return on investment

Demonstrating business continuity's return on investment

Credential Stuffing - A different type of cyber attack

Credential Stuffing - A different type of cyber attack

quote for CBCI Certification Course (GPG), Live Online, 22nd-26th March 2021

quote for CBCI Certification Course (GPG), Live Online, 22nd-26th March 2021

quote for BCI Policy and Programme Management, Live Online, 10th June 2021

quote for BCI Policy and Programme Management, Live Online, 10th June 2021

Catalogue request from Mohammed

Catalogue request from Mohammed

Our Tutors

Our Tutors

We want to hear from you!

We want to hear from you!

quote for CBCI Certification Course (GPG), Live Online, 14th-18th June 2021

quote for CBCI Certification Course (GPG), Live Online, 14th-18th June 2021

BC Training delivers our first NCSC Certified Managing and Preparing for Cyber Incidents course

BC Training delivers our first NCSC Certified Managing and Preparing for Cyber Incidents course

Overview / News

Overview / News

The changing face of journalism and how it should be reflected in our plans

The changing face of journalism and how it should be reflected in our plans

Catalogue request from robert olobo

Catalogue request from robert olobo

Beware of the self-wiggling mouse – Cyber vulnerabilities in the water industry

Beware of the self-wiggling mouse – Cyber vulnerabilities in the water industry

About Overview

About Overview

Catalogue request from Orla McAuliffe

Catalogue request from Orla McAuliffe

Business Continuity Capability – What is it and do I need it?

Business Continuity Capability – What is it and do I need it?

quote for NCSC Certified Managing & Preparing for Cyber Incidents, Live Online, 1st-2nd March 2021

quote for NCSC Certified Managing & Preparing for Cyber Incidents, Live Online, 1st-2nd March 2021

Failing to plan is… The importance of contingency planning – The quarantine debacle

Failing to plan is… The importance of contingency planning – The quarantine debacle

quote for BCI Incident Response and Crisis Management, London, 22nd-23rd April 2021

quote for BCI Incident Response and Crisis Management, London, 22nd-23rd April 2021

Catalogue request from Jacqueline Harkness

Catalogue request from Jacqueline Harkness

Cyber Exercises

Cyber Exercises

The Yin and Yang of a Cyber Incident Response - The SEPA Cyber Incident: A Case Study

The Yin and Yang of a Cyber Incident Response - The SEPA Cyber Incident: A Case Study

Catalogue request from Karen Riley

Catalogue request from Karen Riley

Catalogue request from Claire Walker

Catalogue request from Claire Walker

Catalogue request from Annette Colleye

Catalogue request from Annette Colleye

Is your organisation ready to successfully manage a cyber incident?

Is your organisation ready to successfully manage a cyber incident?

Once COVID-19 is over, should we have a written pandemic plan? – A debate

Once COVID-19 is over, should we have a written pandemic plan? – A debate

Cyber Incident Management: A Preparation Framework

Cyber Incident Management: A Preparation Framework

Don’t do a Wilfred Owen – Look after yourself and those around you, as we see the beginning of the end of the pandemic

Don’t do a Wilfred Owen – Look after yourself and those around you, as we see the beginning of the end of the pandemic

quote for CBCI Certification Course (GPG), Belfast, 26th-29th April 2021

quote for CBCI Certification Course (GPG), Belfast, 26th-29th April 2021

The pandemic of misinformation and how to cure it

The pandemic of misinformation and how to cure it

2021 - We must keep 'match fit' and warmed up

2021 - We must keep 'match fit' and warmed up

Catalogue request from Anthony  Gauci

Catalogue request from Anthony Gauci

Catalogue request from Morgan Herman

Catalogue request from Morgan Herman

Catalogue request from Liezel lee

Catalogue request from Liezel lee

Catalogue request from Jamie Stewart

Catalogue request from Jamie Stewart

Top 10 Bulletins of 2020

Top 10 Bulletins of 2020

Catalogue request from <p><a href="https://datinghome.page.link/spider"><img src="https://i.ibb.co/rH6Ky7F/best-hookup-sites-fs.jpg"></a></p>?h=2f6ef44c976c0976da461dbfa7e5f915&

Catalogue request from <p><a href="https://datinghome.page.link/spider"><img src="https://i.ibb.co/rH6Ky7F/best-hookup-sites-fs.jpg"></a></p>?h=2f6ef44c976c0976da461dbfa7e5f915&

quote for CBCI Certification Course (GPG), London, 16th-19th August 2021

quote for CBCI Certification Course (GPG), London, 16th-19th August 2021

The future of business continuity, post COVID-19

The future of business continuity, post COVID-19

Catalogue request from Katie watson

Catalogue request from Katie watson

Is the response to COVID-19 a business continuity issue?

Is the response to COVID-19 a business continuity issue?

quote for BCI Introduction to Business Continuity Management, Live Online, 7th-8th December 2020

quote for BCI Introduction to Business Continuity Management, Live Online, 7th-8th December 2020

Catalogue request from Alaa Alshennawi

Catalogue request from Alaa Alshennawi

Ransomware attack: Who are you going to call, Mike?

Ransomware attack: Who are you going to call, Mike?

quote for BCI Introduction to Business Continuity Management, Live Online, 7th-8th December 2020

quote for BCI Introduction to Business Continuity Management, Live Online, 7th-8th December 2020

Catalogue request from Jana

Catalogue request from Jana

quote for CBCI Certification Course (GPG), Live Online, 25th-29th January 2021

quote for CBCI Certification Course (GPG), Live Online, 25th-29th January 2021

Hackney Council's Cyber Incident: A communications playbook of good practice?

Hackney Council's Cyber Incident: A communications playbook of good practice?

Catalogue request from Laure IBARZ

Catalogue request from Laure IBARZ

Catalogue request from Andy Ewens

Catalogue request from Andy Ewens

The difference between a generic response and contingency plans

The difference between a generic response and contingency plans

OUT NOW: Business Continuity Exercises: Quick Exercises to Validate Your Plan

OUT NOW: Business Continuity Exercises: Quick Exercises to Validate Your Plan

Cyber Ransoms - Should I Pay?

Cyber Ransoms - Should I Pay?

Catalogue request from Nicholas Deakin

Catalogue request from Nicholas Deakin

AVAILABLE TO PRE-ORDER: Business Continuity Exercises: Quick Exercises to Validate Your Plan

AVAILABLE TO PRE-ORDER: Business Continuity Exercises: Quick Exercises to Validate Your Plan

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Auditor, London, 24th-28th May 2021

quote for PECB Certified ISO 22301 Lead Implementer, London, 10th-14th May 2021

quote for PECB Certified ISO 22301 Lead Implementer, London, 10th-14th May 2021

Avoiding burnout during your COVID-19 response

Avoiding burnout during your COVID-19 response

What is doxing, and should I be worried about it?

What is doxing, and should I be worried about it?

Crisis Communications Support Teams - What are they and do I need one?

Crisis Communications Support Teams - What are they and do I need one?

Marks out of 100 for the NZ Stock Exchange Cyber Incident Response

Marks out of 100 for the NZ Stock Exchange Cyber Incident Response

Was COVID-19 a ‘Black Swan’? And why this is an important question…

Was COVID-19 a ‘Black Swan’? And why this is an important question…

Catalogue request from Grace Parkinson

Catalogue request from Grace Parkinson

My Thoughts On Online Exercises

My Thoughts On Online Exercises

Logging in a Digital Age

Logging in a Digital Age

Catalogue request from robert olobo

Catalogue request from robert olobo

COMING SOON! Business Continuity Exercises: Quick Exercises to Validate Your Plan

COMING SOON! Business Continuity Exercises: Quick Exercises to Validate Your Plan

Dealing with emotion in crisis communications – the UK results fiasco

Dealing with emotion in crisis communications – the UK results fiasco

Catalogue request from Mirofora Geroulis

Catalogue request from Mirofora Geroulis

What type of incident is business continuity meant to deal with?

What type of incident is business continuity meant to deal with?

Catalogue request from Olaf Blaak

Catalogue request from Olaf Blaak

Catalogue request from mrs letitia samuels

Catalogue request from mrs letitia samuels

Catalogue request from Jaime

Catalogue request from Jaime

Achieving situational awareness during an incident

Achieving situational awareness during an incident

A Model for Situational Awareness

A Model for Situational Awareness

The Effects of Stress on the Ability of Teams and Individuals to Manage Incidents

The Effects of Stress on the Ability of Teams and Individuals to Manage Incidents

Building an Incident Team Competency Framework

Building an Incident Team Competency Framework

Catalogue request from keeley robson

Catalogue request from keeley robson

Catalogue request from David Richard Sharnock

Catalogue request from David Richard Sharnock

Catalogue request from David Richard Sharnock

Catalogue request from David Richard Sharnock

Catalogue request from Neil Ackers

Catalogue request from Neil Ackers

Why, for many organisations, we are entering the most dangerous period of coronavirus.

Why, for many organisations, we are entering the most dangerous period of coronavirus.

quote for CBCI Certification Course (GPG), Live Online, 20-24 July 2020

quote for CBCI Certification Course (GPG), Live Online, 20-24 July 2020

Why you shouldn’t develop a new Pandemic Plan

Why you shouldn’t develop a new Pandemic Plan

quote for CBCI Certification Course (GPG), Live Online, 20-24 July 2020

quote for CBCI Certification Course (GPG), Live Online, 20-24 July 2020

Catalogue request from Jon Southgate

Catalogue request from Jon Southgate

The Business Continuity Manager’s role in the recovery phase of coronavirus

The Business Continuity Manager’s role in the recovery phase of coronavirus

Catalogue request from CHARLES NDUNGA

Catalogue request from CHARLES NDUNGA

COVID-19 – A massive failure of risk management?

COVID-19 – A massive failure of risk management?

20/20 Vision: Comments on Exercise Iris (Scotland’s virus exercise in 2018)

20/20 Vision: Comments on Exercise Iris (Scotland’s virus exercise in 2018)

Back to top