Home/Training/Certified Incident Handler

Programme Detail

Certified Incident Handler

The Certified Incident Handler programme teaches a structured approach to preparing for, detecting, containing, investigating, eradicating, and recovering from...

Incident ResponseRegistration Open

Programme overview

The Certified Incident Handler programme teaches a structured approach to preparing for, detecting, containing, investigating, eradicating, and recovering from cybersecurity incidents. It addresses malware, email, network, web, cloud, insider, and endpoint incidents together with evidence handling and reporting. Participants will apply incident-response processes to technical and tabletop scenarios, including triage, evidence handling, containment, recovery, communication, and lessons learned.

Programmes can be delivered via

HRD Corp Claimable
Yayasan Peneraju aligned
EC-Council

At a glance

Course code
EC-015
Provider
EC-Council
Category
Incident Response
Status
Registration Open
Duration
3 days
Price
RM 4,700

What participants should gain

  • Establish an incident-response process and supporting policies
  • Triage events and determine incident scope and severity
  • Contain and investigate common attack scenarios
  • Collect and preserve evidence using defensible practices
  • Coordinate recovery, reporting, and post-incident improvement

Participant readiness

  • Basic knowledge of cybersecurity, networking, and operating systems
  • Experience in IT operations, SOC, security administration, or support is beneficial
  • Familiarity with logs and common attack techniques is recommended

Who this course is for

  • Incident responders, SOC analysts, security engineers, administrators, and team leaders
  • Professionals responsible for cyber incident preparation, coordination, investigation, or recovery
  • IT, risk, audit, legal, or management personnel supporting incident-response activities

How the course is delivered

This programme will be conducted through interactive lectures, incident walkthroughs, tabletop exercises, technical demonstrations, evidence-handling activities, playbook development, group discussions, and post-incident reviews.

This programme will be conducted through interactive lectures, incident walkthroughs, tabletop exercises, technical demonstrations, evidence-handling activities, playbook development, group discussions, and post-incident reviews | By enquiry

Course outline

Module and topic breakdown

Module 1: Introduction to Incident Handling and Response

Incident classification, severity, ownership, escalation, response lifecycle, and coordination

Module 2: Incident Response Preparation and First Response

Preparation, detection, analysis, containment, eradication, recovery, and lessons learned

Module 3: Malware Incident Handling

Incident classification, severity, ownership, escalation, response lifecycle, and coordination

Module 4: Email Security Incident Handling

Incident classification, severity, ownership, escalation, response lifecycle, and coordination

Module 5: Network Security Incident Handling

Incident classification, severity, ownership, escalation, response lifecycle, and coordination

Module 6: Web Application Incident Handling

Incident classification, severity, ownership, escalation, response lifecycle, and coordination

Module 7: Cloud Security Incident Handling

Incident classification, severity, ownership, escalation, response lifecycle, and coordination

Module 8: Insider Threat and Endpoint Incident Handling

Incident classification, severity, ownership, escalation, response lifecycle, and coordination

Module 9: Evidence Collection and Forensic Readiness

Evidence identification, relevance, authority, integrity, preservation, and documentation

Module 10: Containment, Eradication, and Recovery

Short-term and long-term containment strategies based on incident type and business impact

Module 11: Reporting, Lessons Learned, and Improvement

Audience, purpose, scope, methodology, limitations, evidence, and executive summary

Assessment and completion

  • Continuous knowledge checks and facilitator feedback throughout the programme
  • Completion of guided exercises, scenarios, labs, or case-study activities applicable to the course
  • Final review or practical activity to confirm understanding of the stated course objectives
  • Official EC-Council examination and certification requirements depend on the selected training package and current exam version

Availability

This programme has a public intake path. Use the enquiry form below to confirm the next available session or a private cohort.

Programme enquiry

Discuss pricing, delivery, or corporate customisation

Use this form to confirm availability, request pricing clarification, or discuss a private cohort for your organisation.