Tracks
CYCyber resiliencePractitioner

Cyber Resilience

Hold when the defences have already failed

Cyber resilience starts where cybersecurity ends: when the attacker is already inside. This path connects incident response and business continuity, works the ransomware scenario end to end — from the disconnection decision to rebuilding a trusted directory — and shows how to design arrangements that survive compromise of their own administration tooling.

What you will be able to do

  • Connect CSIRT, crisis team and business continuity
  • Run the first six hours of a ransomware incident
  • Decide on a mass disconnection and own its consequences
  • Rebuild a trusted foundation after compromise
  • Design backups that survive a compromised administrator

Intended audience

  • CISOs and SOC teams
  • Continuity leads
  • Crisis teams
  • IT leadership

Courses in this track

  1. 1CY-101FoundationFreeCyber Resilience FundamentalsDesigning for after the compromise 3 lessons 37 min
  2. 2CY-201PractitionerResponding to ransomwareThe first six hours, decision by decision 3 lessons 40 min
  3. 3CY-202PractitionerConnecting cyber and continuityTwo management systems, one capability 2 lessons 27 min