Course Overview

Security incident response is a crucial component of GDPR compliance, ensuring that organizations can effectively detect, respond to, and mitigate data breaches. With the increasing frequency of cyber threats targeting personal data, businesses must establish a robust incident response framework to meet regulatory requirements and protect sensitive information. This course provides a comprehensive guide to building a security incident response system tailored for GDPR compliance, covering essential cybersecurity strategies, SOC implementation, and real-world threat scenarios.

This course begins with an introduction to incident response, explaining its necessity, processes, and tools, including SIEM and automation. It then explores the creation and management of a Security Operations Center (SOC) and the integration of Network Operations Centers (NOCs). The GDPR section focuses on incident response planning, data breach management, and regulatory requirements. Learners will also study real-world attack methodologies, banking sector challenges, financial malware threats, and fraud risk management. Hands-on hacking attempt demonstrations provide practical insights into cyber threats and security countermeasures.

By the end of this course, learners will be equipped with the knowledge and tools to build an effective security incident response system, ensuring GDPR compliance and enhancing organizational cybersecurity resilience.

What You Will Learn

  • Understand what incident response is
  • Will have a list of templates to use
  • Will have a list of incident response tools and resources
  • Will have a list of incident response playbooks

Program Curriculum

  • Welcome & intro
  • Set your expectations
  • A 1st touch of what you will really get in the course
  • $7 Million Cybersecurity Scholarship by EC-Council

  • What is Incident Response and why do I need it?
  • Incident Response Team
  • Incident Response Process and Procedures
  • Types of Security Incidents
  • Incident Response Tools - general
  • What is a SIEM?
  • Incident Response Training
  • What is automation in incident response
  • Chapter 2 Quiz

  • What is a NOC?
  • What is a SOC?
  • Integrated NOC and SOC
  • Mission, Team and Required Training
  • Types of SOC
  • Building a SOC
  • Cheat Sheets to help you in configuring your systems
  • Chapter 3 Quiz

  • GDPR intro
  • GDPR effects on Incident Response
  • How to create an effective IR plan
  • GDPR Incident Response Process
  • Let’s draft the IRM Procedure
  • How to treat data breaches
  • Chapter 4 Quiz

  • IRM1 - Worm Infection
  • IRM2 - Windows Intrusion
  • IRM3 - Unix/Linux Intrusion Detection
  • IRM4 - DDoS
  • IRM5 - Malicious Network Behavior
  • IRM6 - Website Defacement
  • IRM7 - Windows malware detection
  • IRM8 - Blackmail
  • IRM9 - Smartphone Malware
  • IRM10 - Social Engineering
  • IRM11 - Information Leakage
  • IRM12 - Insider Abuse
  • IRM13 - Phishing
  • IRM14 - Scam
  • IRM15 - Ransomware
  • Chapter 5 Quiz

  • Lessons learned by working in a SOC
  • A list of open source tools to use
  • ATP incident response
  • Chapter 6 Quiz

  • Today’s Challenges
  • Target and Distribution
  • Attack Methods
  • Infection Vectors
  • Targeted attacks against financial institutions
  • Mobile platform and email scams
  • Takedowns and Conclusions
  • Chapter 7 Quiz

  • Past 3 decades of malware (part 1)
  • Past 3 decades of malware (part 2)
  • The architecture of financial malware
  • Zeus
  • Zeus GameOver
  • SpyEye
  • IceIX
  • Citadel
  • Carberp
  • Shylock
  • Bugat
  • Dyre
  • Dridex
  • Shifu
  • Tinba
  • Chapter 8 Quiz

  • Why Fraud Risk Engines fail
  • How to bypass 2 factor authentication (2FA)
  • Fraud Prevention Technology
  • Compliance and Legal Issues
  • Customer impact
  • Selecting the right cybercrime solution
  • Malware detection
  • Malware detection - Advanced
  • Malware detection - how technology can help
  • Criminal Detection & Account Takeover
  • Account Takeover - Product Architecture
  • What about mobile banking?
  • Chapter 9 Quiz

  • Simple lab setup
  • XSRF attack
  • Compromising Public server
  • Break-In: Compromising the victim computer
  • Other Web Application Attack Example
  • Locky Ransomware
  • Gathering Info & Exfiltrate
  • Chapter 10 Quiz

  • Final thoughts and conclusion
Load more modules

Instructor

Roland Costea

Roland is a cybersecurity, privacy, and cloud leader and strategist with a demonstrated experience in running cybersecurity & cloud business units, practices, divisions from zero to maturity with year over year quality growth and quota over-achievement (projects of more >50 million euro/year). Roland has the following certifications: CISSP, CIPM, CIPT, CIPP/E, CRISC, CISM, CCSK v4, CCSP, LPT, CEH, ISO 27001LA, TOGAF.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Fastest Way to Level Up Your Cybersecurity Skills

Invest in your future with flexible subscription plans that give you access to the world’s largest online cybersecurity course library. Whether you're exploring cybersecurity courses for beginners or advancing your expertise,
access in-demand courses, practical labs, and CTF challenges designed to support continuous learning.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Build your cybersecurity skills with 900+ bite-sized courses and curated learning paths designed for continuous learning.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 880+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Develop real-world cybersecurity skills through hands-on labs and CTF challenges designed for practical learning.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro, Plus:

  • 1600+ Hands-on lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Hands-on Labs and Challenges added every month

Related Courses

1 of 50