SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsOn this month's SANS Stay Ahead of Ransomware livestream, we explored the critical role of communications during cyber incidents with special guest Kelly Miller, Managing Director at FTI Consulting. With extensive experience leading communications responses for high-profile data breaches, Kelly provided valuable insights on how to communicate effectively before, during, and after a ransomware incident.
Kelly emphasized that while organizations are no longer harshly judged simply for experiencing a breach, they are scrutinized for how they handle the response. Around 2020, when ransomware attacks became more prevalent, the focus of media criticism shifted from technical security failures to communication deficiencies—specifically, how clearly organizations communicated and how quickly they responded.
We discussed how every organization has its own personality when responding to incidents, with some being more transparent while others take a more conservative approach. Kelly stressed that communication plans must be tailored to each organization's unique culture and audience needs.
A key theme throughout our discussion was the importance of preparation:
When an incident is first detected, Kelly recommended:
For communicating with external stakeholders, we discussed:
Many organizations lack dedicated PR resources. Kelly suggested general counsel often serves as a good point of contact for communications, as legal strategy should guide all external messaging. Additionally, HR or marketing teams can play important roles, but collaboration across departments is essential.
We explored several ways communication can go wrong:
To mitigate these issues, Kelly recommended providing employees with clear guidance on what they can say, reminding them of social media policies, and explaining why consistent messaging matters.
The conversation highlighted that experiencing an incident, while challenging, provides valuable learning opportunities that strengthen an organization. Many organizations take preparedness much more seriously after experiencing even a minor incident.
Executive Cybersecurity Exercises: A practical training exercise through a simulated cyberattack to enhance and test your team's tactical and strategic cyber resilience.
LDR533: Cyber Incident Management: This course equips you to not just be a member of the incident management team but a leader or incident commander.
Mari DeGrazia loves the satisfaction of solving a good puzzle. That fascination paired with her technical abilities has made digital forensics the perfect career fit. "There is nothing like the adrenaline rush of figuring out a tough case when you find that smoking gun or vital clue that will help solve it," she says.
Read more about Mari DeGrazia