Ransomware & BEC Awareness Training
Two attacks account for most of the money Malaysian companies lose to cybercrime, and neither of them needs a sophisticated hacker. Ransomware arrives through an attachment, a stolen password or an unpatched remote access service. Business email compromise arrives through a convincing message asking someone in finance to change a bank account. This programme takes both apart in front of the people most likely to meet them, then rehearses the response until it becomes reflex rather than panic.
Programme Agenda
How Ransomware Actually Gets In
The four routes that account for almost every case: phishing attachments, credential reuse, exposed remote desktop, and an unpatched internet-facing device. Real Malaysian and regional incidents traced from first click to encrypted file server.
The Hour After the Screen Changes
Who disconnects what, who calls whom, and the decisions that quietly destroy evidence. Isolation without powering down, preserving logs, and why the ransom note is not the first thing to read.
Backups That Survive the Attack
Why the backup is usually encrypted too. Offline and immutable copies, restore testing, and the uncomfortable question of how long a full restore actually takes for your systems.
Business Email Compromise: the Long Con
Mailbox compromise, thread hijacking and lookalike domains. How an attacker sits inside a conversation for weeks before sending the message that matters, and the small tells that give it away.
Invoice Redirection and Bank Change Fraud
The single control that stops most losses: verifying a bank detail change out of band, against a number you already held. Building it into the payment process so it cannot be skipped under pressure.
Executive Impersonation and Urgency Pressure
Why a message from the managing director asking for a quiet, urgent transfer works. Authority, secrecy and time pressure as attack tools, and giving staff explicit permission to slow down.
Reporting: Internally, and to the Authorities
Escalation inside the company, the PDPA notification clock where personal data is involved, reporting to the bank in time to attempt a recall, and lodging with the police and the National Scam Response Centre.
Tabletop: Friday Afternoon, Encrypted Servers
A facilitated scenario run against your own environment. Participants make the calls in sequence and the group reviews where the plan held and where it did not.
Learning Outcomes:
Recognise the common delivery routes for ransomware before the payload runs
Take the right first three actions when a device shows signs of encryption
Judge whether a backup strategy would actually survive a ransomware event
Spot thread hijacking, lookalike domains and mailbox compromise in day-to-day email
Apply out-of-band verification to every bank detail change without exception
Resist urgency and authority pressure in payment requests
Escalate and report an incident within the internal, banking and regulatory deadlines
Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Beginner
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Cybersecurity
- Cybersecurity for Finance Teams · All levels, 1 day
- Cybersecurity for Executives and the Board · Leadership, 1 day
- Practical Cybersecurity for Business and IT · Intermediate, 2 days
- Information Security and Risk Management · Intermediate, 2 days
- Cybersecurity Advanced and Governance · Advanced, 2 days
- Cyber Security Act 2024 (Act 854) and NACSA Readiness · All levels, 1 day
- Data Breach Response and Incident Management · All levels, 1 day
- Incident Response and Digital Forensics · Intermediate, 2 days