Event details
Mandiant Academy Training Event
- Course: Incident Response for Everyone
- Date: Monday, March 24, 2025 – Wednesday, March 26, 2025
- Time: 8:00 AM–2:30 PM, daily
- Time Zone: (UTC-08:00) Pacific Time (US & Canada)
- Cost: $3,000 USD or 3 EOD units
- Delivery Method: Instructor-led, virtual delivery
- Location: Google Meet
At a glance
This course is designed to teach non-technical support staff about how to respond to an incident and how to work with investigators during an incident response event. This course includes a series of hands-on exercises that highlight all phases of the investigation life cycle.
Participants can learn how to respond to a detected incident, describe the incident to stakeholders, differentiate among different evidence acquisition methods, understand how investigators conduct an investigation, evaluate different remediation methods, and review an investigative report. By the end of this course, participants can actively provide non-technical support to an investigation by understanding the full scope of incident response processes and procedures.
The course consists of the following topics with exercises included throughout the course.
- Incident discovery: Incident discovery, notifying stakeholders, initial documentation, triggered processes and procedures
- Incident description: Describing the incident, evidence collection for trusted partners
- Evidence acquisition: Evidence collection capabilities, trusted partner evidence collection, evidence preservation
- Analysis: Planning for analysis, analysis gaps, analysis methodologies
- Remediation: Remediation plan concepts, remediation plan customizations, remediation timing
- Reporting results
Course goals
After completing this course, learners should be able to:
- Determine how to respond to an incident immediately after initial notification
- Summarize an incident for relaying to a trusted partner
- Choose an investigation plan most suited to investigate your organization’s incident
- Choose a remediation plan best suited to investigate your organization’s incident
- Evaluate an investigative report for quality
- Summarize the events described in an incident report
Who this course helps
The audience for this course includes all members of an organization that are commonly asked to work with or as part of an investigative team, such as personnel involved in information security (information security, information technology), counsel (general or third-party, cyber policy lawyers, breach coaches), or communications (internal or external communications).
What to bring
Students are required to bring their own laptop with an internet connection and a modern browser. Learners will receive a lab book and all required class materials.
Course materials
Students will receive a lab book and access to all required class materials and tools.