Course Overview
Ransomware has evolved from a criminal nuisance into a geopolitical weapon. State-sponsored groups now deploy ransomware to generate revenue for sanctioned regimes, to disrupt critical infrastructure, and to exert political pressure on adversaries. The Lazarus Group, Sandworm, and their affiliates have demonstrated that ransomware can simultaneously fund prohibited weapons programmes while crippling hospitals, logistics networks, and government services.
This two-day practitioner programme goes beyond incident response. It addresses the attribution challenge, the policy landscape around ransom payments, the role of cyber insurance, the legal obligations on organisations and governments when state-sponsored ransomware strikes, and how to contribute to national-level response frameworks. Delegates leave with the skills to advise leadership, coordinate with law enforcement, and communicate credibly with regulators and insurers.
Hands-On Learning
Attribution analysis exercise: map a real-world ransomware campaign to a threat actor using technical and contextual indicators
Mentor-Led Sessions
Live debrief with a practitioner who has managed state-sponsored ransomware incidents in government or financial services contexts
Career-Ready Skills
State-actor attribution analysis, OFAC compliance advising, ransomware crisis communications, incident coordination with law enforcement, and ransom policy framework design.
Learning Outcomes
Distinguish state-sponsored ransomware from criminal campaigns using attribution methodology.
Apply the attribution confidence scale to communicate uncertainty appropriately to leadership.
Advise the board on ransom payment decisions with reference to legal and sanctions obligations.
Coordinate organisational response with law enforcement and government agencies during a state-sponsored incident.
Design tabletop exercises that simulate state-sponsored ransomware scenarios for executive teams.
Contribute meaningfully to national threat intelligence sharing mechanisms.
Prerequisites
Completion of Cyber Warfare Foundations (X-CWF-F) or equivalent awareness.
Working knowledge of incident response processes.
Familiarity with ransomware mechanics at a conceptual level.
Detailed Syllabus
Step-by-step learning journey from basics to professional practice
Topics Covered
- Pre-reading: NCSC and CISA joint advisory on state-sponsored ransomware groups
- Accessing course materials, case study packs, and collaboration workspace
- Course objectives, participant role mapping, and learning agreement
- Introduction to the attribution confidence framework used throughout the programme
Skills You'll Gain
Master these in-demand skills through hands-on practice
Career Progression
A clear view of the roles this programme supports, what typically comes next, and where learners progress over time
Ways to Learn
Choose the learning format that works best for you and your team
Live Online
Instructor-Led Training
Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.
- Live instructor interaction (real-time)
- Trainer-led walkthroughs and real examples
- Guided resources and session notes provided
- Structured Q&A and practical discussion
Price per person
Group enrolments and early planning options available.
All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.
Prefer a Faster, Personalised Route into IT?
Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.
"Many learners choose 1-to-1 when they want understanding, not memorisation."
Exam & Certification Information
Everything you need to know about the certification exams
Important Information
You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.
Credential
Certificate of Completion
On successful completion of State-Sponsored Ransomware: Attribution, Response and National Policy, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.
Frequently Asked Questions
Everything you need to know about this course
Yes. The course is designed for cross-functional teams. Legal, compliance, and risk professionals are core delegates alongside technical leads. Attribution, policy, and legal obligation modules require no coding or tool knowledge.
Ready to Start Your Learning Journey?
Take the next step in your professional development