Course Overview

This learning path equips learners with the skills to design a robust incident response strategy, implement operational workflows, align with GDPR compliance, and define measurable KPIs. Through practical and strategic insights, you'll explore every stage of the incident response lifecycle—from planning and detection to reporting and continuous improvement.

What You Will Learn

  • Develop an actionable incident response strategy and policy.
  • Implement GDPR-aligned security response workflows.
  • Measure and improve incident response performance using KPIs.
  • Handle real-world cyber incidents with structured processes.

Program Curriculum

Content
  • Chapter 1: Introduction
  • Chapter 2: Incident Response in Cyber Security
  • Chapter 3: Building a Security Operations Center (SOC)
  • Chapter 4: GDPR and Incident Response
  • Chapter 5: GDPR Incident Response Methodologies (IRM)
  • Chapter 6: Incident Response Tools for GDPR compliance - Free vs Enterprise
  • Chapter 7: Banking Challenges Related to Cyber Risk
  • Chapter 8: Financial malware history with examples
  • Chapter 9: Making a Business Case for Financial Malware
  • Chapter 10: Some simple hacking attempts- demo
  • Chapter 11: Conclusion

Content
  • Chapter 1: Introduction to Incident Response
  • Chapter 2: Risk Models in Incident Response
  • Chapter 3: Metrics Programs in Incident Response
  • Chapter 4: Detection and Identification Phase Metrics
  • Chapter 5: Response Phase Metrics
  • Chapter 6: Containment & Eradication Metrics
  • Chapter 7: Post-Incident Analysis Phase Metrics
  • Chapter 8: Reporting
  • Chapter 9: Course Recap and Next Steps

Content
  • Chapter 1: Introduction
  • Chapter 2: Preparation
  • Chapter 3: Identification
  • Chapter 4: Containment
  • Chapter 5: Eradication
  • Chapter 6: Recovery
  • Chapter 7: Lesson Learned

Content
  • Chapter 1: What is Threat Modelling?
  • Chapter 2: Building a Computer Security Incident Response Team (CSIRT)
  • Chapter 3: Security Incident Report
Load more modules

Instructor

Roland Costea

Roland is a cybersecurity, privacy, and cloud leader and strategist with a demonstrated experience in running cybersecurity & cloud business units, practices, divisions from zero to maturity with year over year quality growth and quota over-achievement (projects of more >50 million euro/year). Roland has the following certifications: CISSP, CIPM, CIPT, CIPP/E, CRISC, CISM, CCSK v4, CCSP, LPT, CEH, ISO 27001LA, TOGAF.

Mohammad Adly Adly

Dr. Mohammad Adly Ph. D. Networks and Cybersecurity, Faculty of Electronic Engineering, Menoufiya University, Egypt, 2014 M. Sc. Computer Science and Engineering, Faculty of Electronic Engineering, Menoufiya University, Egypt, 2005 Researcher in IRISA, Rennes University, France, 2001 B. Sc. Communication and Electronic Engineering, Cairo University, 1998, Egypt Main research interests include computer networks and protocols, cybersecurity, congestion control, QoS, and multimedia networking Published more than 10 papers in reputed international journals proceedings and supervised more than 50 graduation projects

Cristian Calinescu

Cristian Calinescu is a Microsoft certified Senior Infrastructure Engineer and Infrastructure Security Operations Manager. His areas of expertise are Microsoft Windows Server 2008 R2, 2012 R2, 2016, 2019, Microsoft Active Directory, Azure Active Directory, Microsoft Exchange (2003 - 2019), Virtualization (Hyper-V, VMWare), Linux OS, PowerShell (including scripting). Cristian has been involved in various maintenance and/or implementation projects based on the technologies mentioned above. He has also participated in network design and implementations projects as well as assisting customers migrating to the latest technologies.

Ryan Wisniewski

Ryan is a distinguished cybersecurity leader renowned for his remarkable accomplishments across diverse industries. With an illustrious track record of building highly successful security programs, portfolios, and organizations, Ryan specializes in Incident Response. His unwavering dedication to empathetic leadership, fostering a blameless culture, and instigating sustainable change management principles sets him apart as a guiding force in the cybersecurity landscape. As the current Incident Response Lead at Obsidian Security, Ryan channels his expertise into delivering elite incident response solutions that cater to the unique needs of each customer. He is committed to delivering actionable insights, advanced threat intelligence, and expeditious remediation strategies to reduce the impact of cyber security incidents around the world. Ryan's professional journey includes his role as the Incident Response Lead at Elastic N.V., where he orchestrated the development, enhancement, and seamless operation of Incident Response. He masterminded the Distributed Dynamic Response Program, aligning the organization with security frameworks such as MITRE ATT&CK and NIST 800-61. By implementing a Threat Intelligence Driven Response operating model, he optimized security event and response consistency and efficiency. Prior to his tenure at Elastic, Ryan held pivotal positions at prestigious companies including Paylocity, Zurich Insurance, ACH Food Companies, and McMaster-Carr Supply. His achievements span a spectrum, from establishing and nurturing successful security teams to orchestrating transformative security technology implementations. Ryan's credentials include renowned industry certifications such as Certified Information Systems Security Professional (CISSP), GIAC Information Security Professional (GISP), GIAC Strategic Planning, Policy, and Leadership (GSTRT), GIAC Certified Incident Handler (GCIH), GIAC Security Essentials (GSEC), GIAC Cloud Penetration Tester (GCPN), and SANS Security Awareness Professional (SSAP). Ryan's educational journey continues in pursuit of a master’s degree in information security from the esteemed SANS Technical Institute, alongside a master’s in business administration with a specialized focus on Organizational Change Leadership from Northern Illinois University. Ryan Wisniewski stands as a beacon of expertise and innovation within the realms of incident response, security architecture, and risk management. His unwavering dedication to excellence continues to make a resounding impact in the field.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering video-based learning with 840+ courses and diverse Learning Paths to enhance your skills.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 840+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro and

  • 1400+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month

Related Learning Paths

1 of 50

Quick View

Design, Build and Implement Security Incident Response

Skip to product information
1 of 1
What's included
  • Full Video Access
  • Self-Paced Study Guide
  • 6 months of access to virtual labs
  • Once redeemed, this bundle will be valid for 12 months
  • Self-Paced Study Guide
  • Exam Voucher + Retake
View full details

Design, Build and Implement Security Incident Response

Design, Build and Implement Security Incident Response