Guide Ransomware : De la crise à la maîtrise
Download resourcesAbout this session
Ajay Sood, head of security sales for Google Cloud Canada and founder of FireEye/Mandiant's Canadian operation, runs an interactive 'mini workshop' built around a fictional ransomware scenario: an electric-vehicle maker's sales VP is phished via a spoofed text message, his credentials are stolen, attackers move laterally from cloud into the OT network, and manufacturing stops. He repeatedly pauses to poll the room (who talks to the hacker, do you pay, do you have a plan) and uses real anecdotes, hackers listening in on a client's crisis Teams call, ransom notes threatening executives' children, a bribed insider, to argue that responding is a business decision, not a technical one. He distinguishes disaster recovery from cyber recovery, stresses that cyber insurance never pays the ransom itself, recommends pre-negotiated secure communication channels and a bridge-coach or IR firm on retainer, and closes on business continuity, disaster recovery and cyber recovery plans tested through red team and tabletop exercises, plus three questions every organization should ask itself about its own worst case.
Cette présentation vous guidera à travers un scénario détaillé de rançongiciel, du moment de la détection initiale jusqu'aux dernières étapes de la récupération et de la remédiation. Nous irons au-delà des aspects purement techniques d'une attaque pour nous concentrer sur l'élément humain crucial et la prise de décision stratégique qui sont essentiels pour gérer efficacement une cybercrise. Notre session décomposera la réponse à l'incident en phases clés, identifiant les parties prenantes qui doivent être impliquées à chaque étape et leurs rôles spécifiques. Nous mettrons en lumière les décisions cruciales, souvent difficiles, qui doivent être prises sous une pression extrême, notamment : Qui informer en premier ? (Ressources internes ou externes) Faut-il payer la rançon ? (Évaluation des risques et des conséquences) Comment communiquer avec les parties prenantes ? (Clients, employés et organismes de réglementation) En analysant un scénario concret, vous obtiendrez un guide pratique pour bâtir une équipe d'intervention résiliente et multifonctionnelle. Cette session vous fournira les outils nécessaires pour préparer votre organisation à la prochaine attaque majeure, en vous assurant qu'en cas de crise, vous avez un plan clair et une équipe prête à l'exécuter.
Key takeaways
- Decide before a crisis, not during it, who is authorized to communicate with a ransomware actor (typically an external bridge coach or negotiator, not the CEO or CISO directly).
- Set up a pre-negotiated secure, out-of-band communication channel (dedicated secured phones, a signal/telegram crisis group) since your email and Teams may be compromised and read by the attacker.
- Understand that cyber insurance covers ransomware-related damages, not the ransom payment itself; do not budget or plan on the assumption it will pay the ransom.
- Build and test business continuity, disaster recovery and cyber recovery plans separately, cyber recovery specifically must account for unknown attacker dwell time and possible insider involvement before trusting any backup.
- Run red team and tabletop exercises that simulate executive unavailability or a compromised CISO, and ask three standing questions: how would I hack us, how would we know, and what is our Cyber Armageddon.
Speakers

As the Head of Security Sales for Canada at Google Cloud, Ajay K. Sood is a recognized leader in the cybersecurity industry with a career spanning over 25 years. He has a deep passion for building and growing innovative security companies, having… Read moreRead less
As the Head of Security Sales for Canada at Google Cloud, Ajay K. Sood is a recognized leader in the cybersecurity industry with a career spanning over 25 years. He has a deep passion for building and growing innovative security companies, having been an integral part of some of Canada's most successful cybersecurity practices. In his current role, Ajay is responsible for bringing Google's powerful security portfolio to the Canadian market. This includes overseeing the go-to-market strategy for both Mandiant's world-class threat intelligence and incident response services, as well as Google's cutting-edge cloud security products. His expertise lies in helping organizations navigate today's complex threat landscape and build resilient security programs. En français: En tant que responsable des ventes en sécurité pour le Canada chez Google Cloud, Ajay K. Sood est un leader reconnu dans le secteur de la cybersécurité, avec une carrière de plus de 25 ans. Il a une profonde passion pour la création et la croissance d'entreprises de sécurité novatrices, ayant été partie intégrante de certaines des entreprises de cybersécurité les plus prospères au Canada. Dans son rôle actuel, Ajay est chargé d'introduire le puissant portefeuille de sécurité de Google sur le marché canadien. Il supervise la stratégie de mise sur le marché des services de renseignement sur les menaces et de réponse aux incidents de Mandiant, ainsi que des produits de sécurité infonuagique de pointe de Google. Son expertise consiste à aider les entreprises à naviguer dans le paysage complexe des menaces d'aujourd'hui et à bâtir des programmes de sécurité résilients.

