13 seats left.
Register by Sunday, July 6, 2025.

Event details

Mandiant Academy Training Event

  • Course: Cyber Team Response Lead (CTRL)
  • Date: Monday, July 14, 2025 – Friday, July 18, 2025
  • Time: 8:30 AM–4:30 PM, daily
  • Time Zone: (UTC+10:00) Sydney
  • Cost: $5,750 USD or 5 EOD units
  • Delivery Method: Instructor-led, in-person delivery
  • Location: Google Sydney
    48 Pirrama Rd
    Pyrmont NSW 2009
    Australia

At a glance

This 5-day instructor-led training is designed to prepare cyber team leads to manage common cyber response capabilities, such as a SOC or CSIRT during a response. The course will prepare learners to lead complex cyber incident management, focusing on the foundational elements across the incident response lifecycle.

Course goals

This course is focused on enabling cyber team leads to manage a technical team during a response by providing foundational theory knowledge and opportunities for practical implementation through discussion-based activities, such as tabletop discussions. The course is complemented by Mandiant experts providing practical advice on operationalising and validating capabilities.

After completing this course, learners should be able to:

  • Establish an effective cyber response team posture.
  • Discuss risk management considerations when responding to a variety of cyber incidents.
  • Explain the purpose and structure of key documents within the cyber governance ecosystem.
  • Describe the integration of threat intelligence in cyber operations.
  • Explain the roles and responsibilities of a cyber response team in each phase of the incident lifecycle.
  • Describe communication considerations throughout a cyber incident response.

Who this course helps

Cyber incident response managers, Security Operation Centre managers and technical staff in senior cyber security roles including those who need to understand the processes, considerations, actions and decisions which may be required while performing as the cyber team lead during a response to a cyber incident.

This course is designed for senior responders or technical managers with a background in IM and cyber response. Background courses including Windows Enterprise IR (EIR) and Linux EIR provide good technical foundations or otherwise a background in forensic analysis and incident response will support course outcomes.

What to bring

Students should bring their own laptop computer with the latest browser of choice and the ability to connect to the Internet. Students will receive class handouts and material during the activity.

Course materials

Students will receive an activity book and access to all required class materials and tools.