Group Purchasing
Group Purchasing
AI SKILLSUPDATED

LDR553: Cyber Incident Management

LDR553Cybersecurity Leadership, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Steve Armstrong-Godwin
Steve Armstrong-Godwin
LDR553: Cyber Incident Management
Course authored by:
Steve Armstrong-Godwin
Steve Armstrong-Godwin
  • GIAC Cyber Incident Leader (GCIL)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 27 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Develop the leadership skills and practical frameworks to command significant cyber incidents with confidence, from the first hour of chaos to the final hand-back.

Course Overview

When a major cyber incident hits, technical teams need more than good tools. They need someone who can take charge, manage the information, direct the effort, and keep the organisation moving. Cyber Incident Management puts you in that role. This course focuses on the critical non-technical challenges facing leaders under pressure: building and running a response team, distilling technical findings into executive briefings, managing communications across legal, HR, comms and external parties, and driving decisions when the facts are incomplete and the clock is running.

Every lab is built on a single, continuous real-world scenario, Submarine Studios, a software and games company under attack by external threat actors. That scenario runs across all five sections, so each skill you develop connects directly to the one before it. By the end of the course you will have worked through a full incident lifecycle, from initial triage to post-incident review, using the tools and frameworks you take home.

Strategic Cyber Incident Leadership and Management

You cannot predict when a major incident will arrive. You can decide in advance how ready you will be when it does. In the aftermath, when the IR team is working through logs, images, and malware at pace, the incident management function is what keeps everything else from unravelling. Communications need to go out. Executives need briefing. Legal and regulatory timelines start running the moment the incident is declared. Third parties need managing. And the team itself needs direction, welfare oversight, and a battle rhythm it can sustain.

This course equips you to lead that function, whether you are stepping into it as a newly appointed incident commander, a senior manager pulled into a response, a technical specialist given wider responsibilities, or a legal, HR, or communications professional who needs to understand what will be expected of you when an incident escalates.

Cyber Incident Management sits above Digital Forensics and Incident Response (DFIR) and takes over when incidents grow beyond what a SOC or IR team can manage on their own. These are the high-impact events that demand coordination across the business with external advisors, regulators, customers, and the media, while the technical investigation continues in parallel. LDR553 is built around exactly those scenarios, with GenAI woven throughout as a practical support tool rather than a theoretical add-on.

The course is built around the Cyber Incident Management Toolkit (CIMTK): a set of frameworks, trackers, and simple reference cards that work during an incident, in the room, not just on a shelf. You will use CIMTK throughout the labs, and you take every component with you at the end of the week. The toolkit includes the AIM-RADAR workbook and many of the CIMTK framework card set covering RAPID, 3-Whats, CURTAIN, CORDS, and TRACE.

Author Statement

"I have spent over 16 years in incident response and incident management, and the gap I kept seeing was not technical, it was the person standing at the front of the room trying to hold it all together without a framework, without sleep, and without a clear picture of what mattered next. This course exists to fix that. It is built on real incidents, run against a real scenario, and designed to give you something you can actually use the week you get back."

– Steve Armstrong-Godwin

What You'll Learn

  • Command a cyber incident response from the first hour through to close-down, using structured frameworks designed for real pressure
  • Run executive briefings under time pressure, with incomplete information, using the 3-Whats approach
  • Build and deploy your own GenAI GPTs to draft briefs, process incoming intelligence, and manage team communications at pace
  • Manage a third-party supply chain breach, including operating in the information void when the vendor goes quiet, using the CURTAIN framework
  • Assess credential theft and identity compromise correctly, and execute eviction in the right order using the TRACE & 7Rs sequence
  • Direct the IR team and coordinate legal, HR, comms and external parties without becoming a bottleneck
  • Handle ransomware, business email compromise, cloud management console attacks, and agentic AI incidents from an incident management perspective

Business Takeaways

  • Reduce incident duration and business impact through faster, better-coordinated management decisions
  • Strengthen executive and board confidence with structured, consistent incident briefings
  • Improve vendor and legal coordination during third-party breach escalation, including regulatory notification timelines
  • Integrate GenAI into the incident management function without introducing additional risk
  • Build a team capable of sustaining a major incident response over days, not just hours
  • Apply CIMTK frameworks immediately: every tool is designed to work from day one, not after a lengthy configuration project
  • Leave with a complete Incident Management Toolkit, including the AIM-RADAR workbook and CIMTK framework card set

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR553: Cyber Incident Management.

Section 1Understanding the Incident, Building the Team With GenAI, Scoping and Tracking the Impact

Section 1 builds your foundation as an Incident Commander. You will establish a common language, define objectives, stand up your team, and start tracking the incident using the CIMTK toolkit, including The Grid, AIM-RADAR, and your first purpose-built GenAI tool.

Topics covered

  • Initial Information Gathering and Using Common Language
  • Categorizing the Incident Using the RAPID Framework
  • Setting Objectives and Developing Commander's Intent
  • Setting Your Incident Management Objectives
  • GenAI as a Team Member: Building Your First GPT

Labs

  • Initial Setup at the Start of the Course
  • Initial Incident Briefing
  • CIMTK: The Grid
  • Setting Objectives and Developing the Commander’s Intent
  • Making GPTs in OpenAI

Overview

In Section 1 we focus on understanding the incident, gathering information, and establishing the language the whole team will use. We review common terms, abbreviations, and incident types so that when we talk to different functions (IR, legal, HR, comms) we mean the same things. From there we categorise the incident using the RAPID framework and define what the Incident Management group is trying to achieve, so that focus is set early and maintained as complexity grows.

The centerpiece of this phase is the CIMTK, specifically The Grid: a structured set of questions and initial tasks that gets the team moving in the right direction from the first hour. Identifying and allocating tasks early allows concurrent activity across support teams: IR, IT, Legal, HR, and the IM function itself. We then use Commander's Intent to brief those teams clearly, communicating short and medium-term goals without creating information dependency.

We move into platform and tooling considerations. Where the team operates from matters, especially when attackers may have visibility of your response infrastructure. Team composition follows: who you need, where they sit, how big the group should be, and how to make it work when it is a mix of internal staff, retained advisors, and external specialists.

We close Section 1 by adding GenAI to the bench. Throughout the course, GenAI is used as a practical support tool: drafting briefs, parsing incoming information, stress-testing decisions. In this section students build their first purpose-built GPT for use in the labs ahead.

Exercises

  • Lab 1.1: Initial Setup at the Start of the Course
  • Lab 1.2: Initial Incident Briefing
  • Lab 1.3: CIMTK: The Grid
  • Lab 1.4: Setting Objectives and Developing the Commander's Intent
  • Lab 1.5: Making GPTs in OpenAI

Topics

  • Initial Information Gathering
    • Using ubiquitous language and categorising the incident with RAPID
    • IR frameworks: PICERL, NIST CSF 2.0, OODA loops
    • Tracking the incident in AIM-RADAR
    • Scoping initial tasks with The Grid
  • Defining Objectives
    • Typical IM objectives and how to set them
    • Commander's Intent and combating information overload
    • Mapping attack activity to business impact
  • Tracking the Incident, Tasks, People and Progress
    • IM platform requirements and safe operating environments
    • Task, evidence, and impact tracking
    • Building the right solution for the organisation
  • Who's on Our Team?
    • Skills, size, location, and follow-the-sun vs centralize-and-focus
    • Making hybrid and multi-location teams work
  • What GenAI Is on Your Team?
    • Using GenAI to support IM tasks
    • Building and configuring GPTs for incident use

Section 2Communications, Planning and Executing Remediations

Section 2 is built around communications with executives, the public, and the wider organization. You will learn to brief clearly under pressure using the 3-Whats framework, draft public statements, coordinate remediation across systems and data, and conduct root cause analysis. The section closes with incident reporting and planning for closure.

Topics covered

  • Planning and delivering Executive briefings
  • Pre-emptive and Reactive Public Statements
  • Briefing the Wider Organization
  • Prioritizing Data and System Remediation
  • Root Cause Analysis and Incident Closure

Labs

  • Crisis Comms: Briefing Executives
  • Crisis Comms: Pre-emptive or Reactive Public Statements
  • Crisis Comms: Briefing the Wider Organization
  • What Is a Good RCA?
  • Prioritizing the Data and System Remediation

Overview

Section 2 opens with executive briefings. Using the 3-Whats structure (What Happened, What Is Happening Now, What Is Happening Next) we give the IC a repeatable format for briefing the board and leadership team at any stage of the incident, with any level of completeness. The format works when facts are still emerging and when the exec audience is impatient.

We move into public communications, both pre-emptive and reactive. Students work through when and how to get ahead of a story versus when to respond, what goes into a public statement, and how to manage the tone and legal exposure of external communications. Lab 2.2 works through both approaches against the Submarine Studios scenario.

Briefing the wider organization presents different challenges: the audience is larger, the information needs to be controlled, and the message must hold up across different functions simultaneously. Lab 2.3 covers how to construct and deliver that briefing without inadvertently spreading panic or leaking details to the wrong audience.

The remediation section covers categorizing the damage, mapping the work, prioritizing actions, and ensuring nothing is missed. Attention goes to secrets within stolen data and compromised systems (credentials, API keys, certificates) and the downstream implications these carry for future operations.

We close with root cause analysis and incident reporting. A strong IR report is necessary but not sufficient for IM purposes; the IC needs to understand what additional material is required, how to get input from teams under pressure, and how to manage access and control over sensitive documentation. Lab 2.4 examines examples of poor root cause analysis meetings. As an outsider, the student spots the dysfunction more easily than those sitting in it and is better placed to avoid the same traps when running their own RCA. Lab 2.5 covers remediation prioritization across systems and data, to give the student a glimpse of how a remediation rebuild plan looks and demonstrates how you can build one when you lack project management support.

GenAI in Section 2 focuses on producing briefs, reformatting unstructured text, and cross-checking communications before release, pressure-testing your own output before it goes to the exec. As always these are supportive functions that the AI is performing and not replacing any staff member or IC task.

Exercises

  • Lab 2.0: How They Said It (optional pre-class reading on press statements and making better AI Configs)
  • Lab 2.1: Crisis Comms: Briefing Executives
  • Lab 2.2: Crisis Comms: Pre-emptive or Reactive Public Statements
  • Lab 2.3: Crisis Comms: Briefing the Wider Organization
  • Lab 2.4: What Is a Good RCA?
  • Lab 2.5: Prioritizing the Data and System Remediation

Topics

  • How to Brief Executives
    • Structure, modality, and frequency of exec briefings
    • Planning, delivering exec style briefings
  • Public Communications: Pre-emptive and Reactive
    • When to get ahead of a story and when to wait to respond
    • Drafting public statements and managing legal exposure
  • Briefing the Wider Organization
    • Controlling information and managing different audience needs
    • Battle rhythm and team welfare
  • Remediation of System and Data Damage
    • Categorizing damage and tracking remediation
    • Counter Compromise Activity planning and execution
    • Identifying secrets in stolen data and their downstream implications
  • Root Cause Analysis
    • Planning a good RCA
    • Five Whys: strong and flawed applications
  • Reporting and Closure
    • Report types, content, access control
    • Transitioning from incident status to BAU projects
    • Breaking up the IM team

Section 3Training, Leveraging Intelligence, Third-Party Compromise, and Bug Bounties

Section 3 develops the capabilities that support major incidents: training IR and IM teams, integrating Cyber Threat Intelligence into response operations, and conducting a deep investigation into a key supplier that is compromised. The section closes with bug bounty and vulnerability reporting programs.

Topics covered

  • Developing IR and IM Training Programs and Exercises
  • Integrating Cyber Threat Intelligence into Response
  • Managing Third-Party and Supply Chain Compromise
  • Developing Supplier Assurance Question Sets
  • Bug Bounty and Vulnerability Reporting Programmes

Labs

  • Choosing Cyber Training Exercises
  • Planning a Hotseat exercise
  • Working with Cyber Threat Intelligence
  • Reviewing a Third-Party Notice and Building Your SAQS
  • Comms During a Third-Party Incident

Overview

Section 3 opens with team development. We examine what good training looks like for IR and IM functions: not frequency compliance, but targeted development against specific capability gaps. Students work through exercise selection (Lab 3.1) and plan a hot seat exercise (Lab 3.2), with guidance on how to build exercises that challenge teams without overwhelming them. This is one of the most important sections of the course; no other zero-cost change will improve your organization's IM capabilities more than running good exercises.

Cyber Threat Intelligence is talked up far more than it is used well during real incidents. In this section we address why that is, and how to fix it. We cover the intelligence cycle from a practitioner perspective: what CTI can produce for an IM team, how to generate Priority Intelligence Requirements, and how to maintain CTI access during a fast-moving incident. Lab 3.3 has the student develop a request for CTI Support for threat actor profiles relevant to the Submarine Studios scenario and then leveraging OpenCTI they see how it looks in a live platform as they compare it with a written report from an Intel vendor.

The third-party compromise module runs across two long labs and is the most substantial element of the section. Starting with an optional pre-class lab reviewing real third-party incident reports, students then work through the full lifecycle of a supply chain incident using the CURTAIN framework. It runs as seven parallel swim lanes rather than a sequential checklist, coordinated by the IC and worked while the supplier is still telling you almost nothing. Lab 3.4 covers reviewing a third-party notification and building a Supplier Assurance Question Set (SAQS), the structured set of questions you put to a vendor when information is scarce. Lab 3.5 turns to the communications that run alongside the investigation: the vendor call, the internal team brief, and the executive update.

The section closes with bug bounty and vulnerability reporting programs: understanding how researchers and third parties approach you, what their motivations are, and how to manage those relationships without losing control of the narrative or the timeline. The incident management function is involved from the first report. What looks like a routine vulnerability disclosure can, once investigated, reveal a significant compromise that has been running undetected for months, and judging when a disclosure becomes an incident is an IM decision rather than a technical one.

Exercises

  • Lab 3.0: Reviewing Third-Party Supply Incident Reports (optional pre-class reading)
  • Lab 3.1: Choosing Cyber Training Exercises
  • Lab 3.2: Planning a Hot Seat Exercise
  • Lab 3.3: Working with Cyber Threat Intelligence
  • Lab 3.4: Reviewing a Third-Party Notice and Building a SAQS
  • Lab 3.5: Comms During a Third-Party Incident

Topics

  • Developing IR/IM Training and Exercises
    • Exercise types, maturity levels, and learning needs analysis
    • Planning and running hot seat exercises
    • Who to include and what to assess
  • Leveraging Cyber Threat Intelligence
    • Strategic, operational, and tactical CTI products
    • Generating PIRs and avoiding common integration failures
    • Using OpenCTI with threat actor intelligence
  • Third-Party Supply Chain Compromise
    • Why they are so impactful and what caused the increase in reports
    • CIMTK: CURTAIN framework for managing the supplier incident
    • Building a Supplier Assurance Question Set (SAQS)
    • Third-party communications: the vendor call, the team brief, and the exec update
    • Closing third-party incidents
  • Bug Bounty and Vulnerability Reporting Programs
    • Researcher types and their motivations
    • Managing disclosure timelines and narrative control

Section 4Cloud, Business Email Compromise, and Credential Theft Attacks

Section 4 examines the attack types an Incident Commander is most likely to face: credential theft and identity compromise, Business Email Compromise, cloud-based attacks, and the emerging challenge of agentic AI. Credential eviction gets particular attention, because doing it in the wrong order lets the attacker straight back in.

Topics covered

  • Credential Theft, Identity Compromise, and how to secure accounts after compromise
  • Business Email Compromise: Types, Investigation, and IM Support
  • Cloud Asset and Management Console Attacks
  • Agentic AI Governance During Incidents
  • Timelines for Incident Visualization

Labs

  • Reviewing Incident Timelines
  • Credential Loss Impact Assessment
  • We Paid the Wrong Account! (BEC)
  • The Cloud Bill Is Vast! (Cloud Management Console Attack)
  • Crisis Comms: Updating the Public Statement

Overview

Section 4 opens with an optional pre-class lab reviewing high-impact credential compromise cases, before moving into timeline visualization. A well-scoped timeline is a powerful communication tool; a poorly scoped one creates confusion. We work through how to build timelines for different audiences at different stages of an incident.

Credential theft and identity compromise take centre stage, and this is where the TRACE framework does its primary work. The core teaching point is one that catches organizations repeatedly: resetting a password does not evict an attacker who holds a valid refresh token. The 7Rs is a sequence, not a checklist: Restrict (lock the account; this stops Entra issuing new tokens), Revoke active sessions, Revoke refresh tokens, Reset credentials, Review MFA methods and trusted devices, Re-enroll MFA, Re-enable the account. Run them out of order and the attacker stays in. Lab 4.2 builds the full credential exposure picture for the Submarine Studios scenario and works through eviction planning using the TRACE tabs in AIM-RADAR.

Business Email Compromise is examined in depth: its stages, the six-plus attack types, where liability falls, how to support legal arguments, and what the IC needs to direct IR forensics effectively. Lab 4.3 puts students inside a BEC investigation where the operative challenge is doubt: doubt what you see and are told.

The section introduces agentic AI as an incident management challenge. As AI agents become more common in enterprise environments, incident managers need a framework for what happens when an agent behaves unexpectedly or when a vendor's agent is in scope during a third-party incident. The CORDS framework (Confirm, Own, Restrain, Document, Sanction) provides that structure, with graduated restraint options (from pausing the queue through to full termination) and an emphasis on evidence preservation before any reset or redeployment.

Lab 4.4 covers cloud management console attacks as a homework exercise. Lab 4.5 returns to the Submarine Studios scenario for a public statement update, applying the communications skills from Section 2 with the fuller picture now available.

Exercises

  • Lab 4.0: Devastating Credential Compromises (optional)
  • Lab 4.1: Reviewing Incident Timelines
  • Lab 4.2: Credential Loss Impact Assessment
  • Lab 4.3: We Paid the Wrong Account! (BEC)
  • Lab 4.4: The Cloud Bill Is Vast!
  • Lab 4.5: Crisis Comms: Updating the Public Statement

Topics

  • Timelines for Visualization
    • Scoping, audience, and levels of detail
  • Credential Theft and Identity Compromise
    • What attackers seek and how they use stolen credentials
    • MFA fatigue, OAuth consent attacks, AiTM phishing, and infostealer techniques
    • CIMTK: TRACE framework: Track, Reset, Assess reach, Compare, Extend monitoring
    • The 7Rs eviction sequence: Restrict, Revoke sessions, Revoke refresh tokens, Reset, Review MFA, Re-enroll MFA, Re-enable
    • Why order matters: token lifetime, tenant boundaries, and federation traps
  • Business Email Compromise
    • Stages of BEC and the six-plus attack types
    • Liability, legal support, and inbox investigation
    • Multi-site and multi-vendor compromise scenarios
  • Cloud Asset and Management Console Attacks
    • IaaS host compromise: vectors, impact, investigation, and clean-up
    • Management console compromise: attacker goals, policy checks, and RCA
  • Agentic AI During Incidents
    • What changes when an AI agent is in scope
    • CIMTK: CORDS framework: Confirm, Own, Restrain, Document, Sanction
    • Graduated restraint options and evidence preservation requirements
    • Pairing CORDS and CURTAIN when a vendor's agent is in play

Section 5AI for Incidents, Attacker Extortion, Ransomware, and Capstone Exercise

Section 5 examines AI risk in incident management before turning to ransomware, which remains the most significant operational threat facing most organizations. The section closes with a comprehensive capstone exercise available to all delivery formats, including OnDemand.

Topics covered

  • AI and LLM Risk in the Incident Management Context
  • Managing an Agent Incident
  • Ransomware: History, Stages, and Response Direction
  • Attacker Extortion, Negotiations, and No-Regret Options
  • Capstone Exercise

Labs

  • Reviewing Ransomware Cases (Optional pre-class)
  • Managing an Agent Incident
  • Managing Hostile Communications
  • Capstone

Overview

The industry uses the term artificial intelligence loosely. Section 5 does not: we break it into its actual categories before narrowing to LLMs and the GenAI tools used throughout the course. We examine hallucination risk, the governance implications of deploying AI in a response context, and where AI adds genuine value versus where it introduces risk that outweighs the benefit. Lab 5.1 works through an agent incident (building on the CORDS framework introduced in Section 4) where students investigate an AI agent behaving outside its intended scope.

Lab 5.2 covers hostile communications: managing dialogue with threat actors, understanding what the attacker is trying to achieve, and keeping executives informed of options and their consequences. This builds directly on the attacker engagement content in Section 2.

Ransomware occupies the second half of the section. We cover its evolution, the stages of a compromise from initial access to encryption, and where detection opportunities were missed. The IC's role is clear: direct IR, maintain context, press executives for decisions, and keep the organization's options open for as long as possible. We work through no-regret options, the implications of going dark, negotiation planning, and the evidence and documentation requirements that determine whether the post-incident review is productive or a liability exercise.

Students close with the capstone: a full multi-stage exercise running across live and OnDemand formats, drawing on every section of the course.

Exercises

  • Lab 5.0: Reviewing Ransomware Cases (Optional)
  • Lab 5.1: Managing an Agent Incident
  • Lab 5.2: Managing Hostile Communications
  • Lab 5.3: Capstone

Topics

  • AI and LLM Risk in IM
    • Defining AI categories and understanding LLMs
    • Hallucination risk and governance implications of AI in response contexts
    • Where AI supports IM and where it introduces new risk
  • Managing an Agent Incident
    • Applying the CORDS framework under incident conditions
    • Investigating agent behavior and scope violations
  • Managing Hostile Communications
    • Attacker engagement: options, risks, and what dialogue can and cannot achieve
    • Keeping executives informed of options and consequences
  • Ransomware
    • History, evolution, and current operator tradecraft
    • Stages from initial access to encryption, where detection was possible
    • Directing IR and pressing execs for timely decisions
    • No-regret options, going dark, and negotiation planning
    • Documenting impacts, decisions, and system availability for the hindsight review
  • Capstone Exercise
    • Multi-stage time-pressured incident drawing on all five sections
    • Available to live in-person, live online, and OnDemand students

Things You Need To Know

Important! Bring your own system configured according to these instructions!

A laptop or mobile device with a current web browser is required to access the cloud-hosted course files and CIMTK materials. The CIMTK toolkit is provided on Google Drive, Dropbox or Proton; students must be able to connect to one these services. Corporate machines with VPN, intercepting proxies, or egress filtering must be configured to permit access, or students should bring a personal device.

Microsoft Office and LibreOffice are both supported. Files are maintained in Google first for multi-user collaboration capability; downloads are available in Office-compatible formats.

Students are issued a SANS ChatGPT account for the duration of the course. Other GenAI tools are welcome, but primary support is provided for the OpenAI-based toolset. Some labs use image generation and computer vision features; students relying on non-OpenAI tools should request a SANS ChatGPT account for those specific exercises.

If you have additional questions about the laptop specifications, please contact customer service.

Security Managers

  • Newly appointed information security officers who will be leading incident response
  • Recently promoted security leaders who want to understand the incident management function in depth

Security Professionals

  • Technically skilled security staff who have recently been given incident commander responsibilities
  • Team leads with responsibility for supporting cyber incidents who may also need to coordinate remediation

Managers

  • Managers who need to understand how to direct technical teams during a major incident
  • Leaders who require a management-level understanding of cyber incidents to fulfil their governance responsibilities

Legal, HR, and Communications Staff

  • Staff who are new to cyber incident management but will be called on to provide critical support under pressure, and who want to understand what will be expected of them

The GIAC Cyber Incident Leader (GCIL) certification validates a practitioner’s ability to manage cyber incidents and lead a diverse incident management (IM) team to restore normal operations. GCIL holders demonstrate expertise in preparing for, assessing, handling, tracking, and documenting incidents; developing IM teams; managing vulnerabilities, threats, and attacks; facilitating communication; and improving IM processes.

  • Preparing for, assessing, remediating and closing an incident
  • Developing, managing and improving the IM team and process
  • Identifying threats, vulnerabilities and common malicious attacks, and handling each incident type
  • Managing incident tasks and facilitating communications

More Certification Details

  • Printed course books
  • Online Electronic Workbook for all lab exercises
  • The Cyber Incident Management Toolkit (CIMTK), including the AIM-RADAR workbook and framework card set
  • CIMTK framework reference cards for RAPID, 3-Whats, CURTAIN, CORDS, and TRACE
  • MP3 audio files of the course lecture
  • Detailed video walkthroughs of all lab exercises
  • Access to the course Slack communities
  • Training plans, report templates, incident frameworks, and reference cards

This course covers the core areas of cyber incident management and assumes a basic understanding of technology, networks, and security concepts. It does not require hands-on technical experience. The focus throughout is management and leadership, not forensics or malware analysis. For those new to the field with no background knowledge, the recommended starting point is SEC401: Security Essentials

LDR553: Cyber Incident Management is part of the SANS Cybersecurity Leadership curriculum and the Cyber Risk Officer Triad, alongside LDR512: Security Leadership Essentials for Managers and LDR519: Cybersecurity Risk Management and Compliance. Together, these three courses provide a holistic blueprint for modern cyber risk officers—whether stepping into leadership from technical ranks or leveling up within executive roles. The triad develops leaders who not only understand how to build, govern, and respond, but who can unify teams under pressure and steer organizations through complexity with clarity and resilience.

Cyber Incident Management coordinates the response to significant security breaches that exceed the capacity of regular SOC and IR teams. It sits above the technical investigation, handling business impact, stakeholder communications, regulatory obligations, and strategic decisions. An Incident Manager leads cross-functional teams, keeps executives informed, and drives the organization toward recovery while IR handles the technical work. As incidents grow in scale and sophistication, the demand for capable people in this role continues to grow faster than the supply. 

No other course covers incident management at this depth, supported by a single continuous real-world scenario where every lab connects to the one before it. LDR553 develops the leadership, communication, and decision-making skills that are genuinely scarce in the market, and that organizations are increasingly willing to pay for. The GCIL certification provides a recognized credential; the CIMTK toolkit provides something you can use from the day you get back. Students regularly apply specific tools and frameworks within days of completing the course. 

Relevant Job Roles

Cyber Risk Officer

Cybersecurity Leadership

Lead cybersecurity risk strategy at the highest level.

Explore learning path

Incident Management (USUP)

Skills Framework for the Information Age

Co-ordination of detection, response, and recovery activities across teams and systems. Emphasis is placed on minimising impact, restoring services, and maintaining clear communication during disruptions.

Explore learning path

Cyber Incident Responder Training, Salary, and Career Path

European Cybersecurity Skills Framework

Monitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.

Explore learning path

Systems Security Management (OPM 722)

NICE: Oversight and Governance

Responsible for managing the cybersecurity of a program, organization, system, or enclave.

Explore learning path

Senior Security Leader

Cybersecurity Leadership

Daily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.

Explore learning path

Governance (GOVN)

Skills Framework for the Information Age

Development of frameworks that align technology use with business objectives and regulatory requirements. Focus areas include policy design, risk controls, and enterprise accountability structures.

Explore learning path

Cybersecurity Instruction (OPM 712)

NICE: Oversight and Governance

Responsible for developing and conducting cybersecurity awareness, training, or education.

Explore learning path

SOC Manager

Cybersecurity Leadership

Security Operations Center (SOC) managers bridge the gap between business processes and the highly technical work that goes on in the SOC. They direct SOC operations and are responsible for hiring and training, creating and executing cybersecurity strategy, and leading the company’s response to major security threats.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 13

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources