Incident-as-a-Service

GC Agenda: March 2026 | Practical Law The Journal | Reuters

The 48-Hour Rule in action. This incident happened, we converted it into operational training, and your team can apply the controls immediately.

73% vs 12% Retention Lift
18.5h Breach to Training
847 Organisations
48h Action Window
Built for:
  • Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and understanding the full incident lifecycle from initial compromise to containment.
  • IT Administrator: Will gain crucial insights into infrastructure hardening, access control implementation, and secure configuration to prevent similar breaches in their environment.
  • Compliance Officer: Will learn to map technical security controls from this incident to regulatory requirements like GDPR and NIS2, strengthening audit and reporting processes.

30-day guarantee. Instant access after payment. Lifetime updates for this incident package.

How This Course Is Structured

Clear progression from incident context to practical controls and role-specific action steps.

1. Incident Breakdown

Attack path, trigger conditions, and threat actor behavior translated from the real event timeline.

2. Defensive Controls

Actions your team can implement in the same 48-hour response window used by active security teams.

3. Evidence & Reporting

Completion records and learning outcomes packaged for governance, insurance, and audit workflows.

Course Outline

4 modules · 16 lessons · ~192 min total

1

Module 1: Threat Intelligence

Deep dive into the incident mechanics, attack vectors, and threat actor analysis. Learn to recognise indicators of compromise.

4 lessons ~180 min
πŸ“– 1.1 GC Agenda: March 2026 Breach Deep Dive 45 min
πŸ“– 1.2 Data Breach Campaign Analysis 45 min
πŸ“– 1.3 Data Exfiltration Vector Analysis 45 min
πŸ“– 1.4 Data Breach Indicators of Compromise 45 min
πŸ“– 2.1 SIEM Detection for Data Exfiltration 45 min
πŸ“– 2.2 Endpoint Analysis for Data Theft 45 min
πŸ“– 2.3 Data Breach Response Playbook 45 min
πŸ“– 2.4 Forensics for Data Breach Incidents 45 min
πŸ“– 3.1 Authentication for Data Protection 45 min
πŸ“– 3.2 Data-Centric Access Control 45 min
πŸ“– 3.3 Network Segmentation for Data Security 45 min
πŸ“– 3.4 Zero Trust for Data Breach Prevention 45 min
πŸ“– 4.1 Data Handling Awareness Programmes 45 min
πŸ“– 4.2 Communicating Data Breach Risk to the Board 45 min
πŸ“– 4.3 Vendor Risk Management for Data Privacy 45 min
πŸ“– 4.4 Compliance Integration for Data Breaches 45 min

Free Sample Lesson

Read one full lesson before purchasing. No signup required.

Free Lesson Access

GC Agenda Breach Deep Dive

Lesson 1 of 16

Lesson 1.1: GC Agenda Breach Deep Dive

Compliance Framework Mapping

Framework Control Requirement
DORA Article 5 Establish and maintain an ICT risk management framework
ISO 27001 A.5.24 Information security incident management planning and preparation
NIST CSF DE.CM-1 The network is monitored to detect potential cybersecurity events
NIS2 Article 21 Security policies and risk management measures
SOC 2 CC7.1 The entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities
GDPR Article 32 Security of processing

Introduction

Welcome to Lesson 1.1: GC Agenda Breach Deep Dive! Over the next 45 minutes, we will explore the anatomy of a modern data breach, from the initial intrusion to the final exfiltration of sensitive information.

But first, let me tell you about Marcus Webb.

It's 10:17 on a Tuesday in March. Marcus Webb, a senior legal counsel at a multinational defence contractor in London, is reviewing a draft contract. The office is quiet, the only sound the hum of the air conditioning and the faint click of his keyboard. He sips his lukewarm coffee, focused on the dense legal text on his screen.

A notification pops up in the corner of his screen: 'Your calendar has been updated.' He ignores it, assuming it's a routine meeting change from his assistant. A few minutes later, another notification appears: 'New document shared: GC_Agenda_March_2026_Confidential.pdf.' He frowns. He wasn't expecting this file. He clicks the link to open it.

Nothing happens. The PDF doesn't open. He clicks again, then shrugs and returns to his contract. He doesn't notice the brief flicker of his network icon, nor the new, hidden process that has just started running in the background of his computer. The decision to click that link, to dismiss the oddity, has already been made.

This is the story of a data breach. By the end of this lesson, you'll understand exactly why Marcus never stood a chance, and more importantly, what could have saved him.


Content Section 1: What is a Data Breach?

A data breach isn't a single event; it's a process. Think of it like a burglary. The thief doesn't just appear in your living room. They case the joint, find a weak lock, pick it, get inside, take what they want, and leave without a trace. A data breach follows the same stages.

Key Characteristics

A data breach involves the unauthorised access, acquisition, or disclosure of protected information. This can be personal data, intellectual property, financial records, or strategic plans.

The goal is rarely destruction. The goal is theft and persistence. The attacker wants to stay inside your network, learn your layout, and take what is valuable over time, often without you knowing.

The impact isn't just the data lost. It's the loss of trust, the regulatory fines, the legal costs, and the operational disruption that follows. The stolen data is just the beginning of the problem.

The Attacker's Business Model

For many attackers, stolen data is a commodity. It's packaged, sold, and traded on dark web forums. A bundle of corporate login credentials might sell for a few hundred pounds. A cache of sensitive legal documents or defence contracts could be worth much more to a competitor or a state-sponsored group.

Research suggests the time between a breach and its discovery can be long, giving attackers plenty of time to monetise the data. The longer they go undetected, the more value they can extract.

Think about that last point for a moment. The real cost of a breach is often the clean-up, not the initial theft.

DORA Article 5 DORA Article 5 requires financial entities to have a strong ICT risk management framework. This means not just having defences, but understanding the full lifecycle of a breach to effectively manage the risk.

ISO A.5.24 ISO 27001 A.5.24 mandates planning and preparation for incident management. Understanding the characteristics of a breach is the first step in preparing to handle one.



Content Section 2: The Attack Flow

Understanding the stages of a breach reveals why it's so effective. Let me show you exactly how Marcus was compromised.

Step-by-Step Compromise

Step 1: Initial Access. In Marcus's case, it was a phishing email with a malicious link disguised as a calendar update or document share. This is a common entry point. The link either downloaded a malicious file or tricked him into entering his corporate credentials on a fake login page.

Step 2: Execution & Persistence. Once the attacker had a foothold on Marcus's computer, they installed malware. This malware was designed to run quietly, establish a connection back to the attacker's server, and ensure it would restart if the computer rebooted.

Step 3: Discovery & Lateral Movement. The attacker then explored Marcus's computer and the network. They looked for other systems, user accounts, and file shares. Using stolen credentials or network vulnerabilities, they moved from Marcus's workstation to more valuable servers, like the document management system or email server.

Exfiltration

Step 4: Data Collection. The attacker identified their target dataβ€”likely the 'GC Agenda' and other confidential legal and defence documents. They gathered these files into a hidden folder on a compromised server.

Step 5: Data Theft. Finally, they transferred the stolen data out of the network. To avoid detection, they might have done this slowly, trickling files out over days or weeks using encrypted channels that blended with normal web traffic.

Why Traditional Defences Fail

Defence MethodHow It's BypassedResult
Signature-based AntivirusUses new, unknown malware or living-off-the-land tools (like built-in system scripts)Fails to detect the initial payload
Basic Email FilteringUses highly targeted, convincing phishing emails with legitimate-looking linksLets the phishing email through to the inbox
Perimeter FirewallAttackers use encrypted web traffic (HTTPS) or compromised employee credentials to enterSees the traffic as authorised and allows it
Manual Log ReviewThe attack generates thousands of normal-looking logs; the key evidence is buriedThe signal is lost in the noise

Notice what all of these methods have in common. They often focus on blocking known bad things at the border. A modern breach doesn't look 'bad' at each individual step; it looks like normal user activity strung together in a malicious sequence.

Many common security tools are bypassed because they look for the wrong things or are not configured to see the full attack chain.

Now pay attention, because this is the moment that changes everything. This is the moment where the attacker moves from one compromised machine to the heart of the network.

NIST DE.CM-1 NIST CSF DE.CM-1 requires monitoring networks to detect events. Understanding this attack flow shows why monitoring must look for sequences of behaviour (like lateral movement followed by large data transfers), not just isolated alerts.

NIS2 Article 21 NIS2 Article 21 mandates risk management measures. Effective risk management requires understanding these specific attack techniques to implement the right detective and preventive controls.



Content Section 3: Detection Mechanisms

Marcus's computer knew something was wrong. It just couldn't tell him. Systems generate clues during a breach. The trick is knowing which clues matter.

Network-Level Indicators

Look for connections to suspicious external IP addresses or domains. In a breach like this, the malware on Marcus's computer would 'call home' to a command-and-control server. These domains are often newly registered or have a poor reputation.

Monitor for unusual data flows. A workstation suddenly uploading gigabytes of data to an external cloud storage service, especially at an odd hour, is a major red flag. This is the exfiltration in progress.

Internal lateral movement also leaves a trail. Look for a single machine making SMB or RDP connections to a large number of other internal servers in a short time, which is not part of its normal job.

Endpoint-Level Indicators

Unexpected processes or services running. The malware needs to execute. Security tools can spot processes running from unusual locations (like the Temp folder) or with strange parent-child relationships.

Changes to system configuration. Attackers often disable logging or security software. An alert for 'Antivirus service stopped' or 'Windows Event Log service modified' can be a critical signal.

Identity Provider Signals

Monitor for impossible travel. A login from Marcus's account in London, followed by a login from another country 30 minutes later, is a clear sign of compromised credentials.

Look for privilege escalation. A standard user account suddenly being added to the 'Domain Admins' group is a catastrophic indicator that the attacker is consolidating power for their lateral movement phase.

SOC2 CC7.1 SOC 2 CC7.1 requires using monitoring procedures to identify changes that introduce vulnerabilities. These detection mechanisms are the operational implementation of that control, looking for the active exploitation of vulnerabilities.

GDPR Article 32 GDPR Article 32 requires appropriate technical measures to ensure security. Implementing these detection mechanisms is a key part of demonstrating you have taken steps to protect personal data from unauthorised processing during a breach.


Activity: Data Breach Preparedness Review

This activity will help you assess your organisation's visibility into the key stages of a data breach.

Important Security Note: Important Security Note: Do NOT document or share specific findings about vulnerabilities, security gaps, or configuration details from your organisation's systems. This activity is for personal awareness and to generate questions for your security team.

Instructions

Step 1: Map the Attack Flow: On a blank piece of paper, draw the five stages of a breach (Initial Access, Persistence, Lateral Movement, Data Collection, Exfiltration).

Step 2: For each stage, write down one question you would ask your security or IT team about how your organisation would detect that activity. For example, for 'Lateral Movement': 'How would we know if a user's workstation started trying to connect to every server on the network?'

Step 3: Identify one piece of documentation you would look for that relates to breach response. This could be an Incident Response Plan, a communication policy, or a list of critical data assets.

Step 4: Based on your thoughts from steps 2 and 3, write down one immediate follow-up action, such as 'Schedule a 30-minute conversation with the CISO to discuss detection capabilities.'

Submission

For the course discussion forum, share general learnings only:

  • Which stage of the attack flow (e.g., Lateral Movement) did you find hardest to formulate a detection question for, and why?
  • What was the most valuable question you developed to ask your security team?
  • Did reviewing the attack flow change your perspective on where security resources should be focused?

Do NOT share: Do NOT share your specific questions, the names of internal systems or tools, details of your organisation's security posture, or any identified gaps.

Review and comment on at least two other students' submissions, focusing on the thought process behind their questions.


Content Section 4: Compliance Documentation

Compliance isn't about ticking boxes; it's about building a defensible position. When an auditor or regulator asks 'How do you protect against data breaches?', this lesson provides the substance behind your answer.

Evidence Generation

This lesson provides documentation for multiple compliance frameworks:

For DORA Article 5 auditors... For DORA auditors, you can now demonstrate staff training on specific ICT risks related to data breach attack flows, a key part of your risk management framework.

For ISO A.5.24 auditors... For ISO 27001 assessors, you can evidence that key personnel have been made aware of incident characteristics, supporting your preparedness for incident management.

For NIST DE.CM-1 auditors... For NIST CSF reviewers, you can show that your team understands the network monitoring signals required to detect the lateral movement and exfiltration stages of a breach.

Audit Trail

Document your completion of this lesson:

  • Lesson title and date completed
  • Time invested: approximately 45 minutes
  • Key learnings in your own words
  • Activity submission reference
  • Follow-up actions identified

Conclusion

Let me tell you how Marcus's story ended.

The breach wasn't discovered for six weeks. By then, the attacker had copied three years of board minutes, legal advice on sensitive government contracts, and the entire global counsel team's email archive. Marcus faced a disciplinary hearing. While he kept his job, his reputation for judgement was damaged. The organisation faced multi-million pound GDPR fines from multiple European regulators, lawsuits from partners, and was temporarily suspended from bidding on certain defence contracts.

The organisation eventually hired a new CISO. They implemented stricter email filtering, deployed an Endpoint Detection and Response (EDR) tool to look for the behavioural clues we discussed, and mandated mandatory security training for all staff, starting with the legal team. The changes were expensive and disruptive, but necessary.

But it doesn't have to be your story. That's why we're here.

You should now understand that a data breach is a multi-stage process, not a single event. You understand how traditional defences are often bypassed by these techniques. You know the key technical and behavioural indicators that can signal a breach in progress. And you understand how this knowledge directly supports your compliance obligations.

Next, we'll explore Next, we'll explore Lesson 1.2: The Attacker's Playbook. We'll look at the specific tools and techniques used in the lateral movement phase, and how to hunt for them inside your own network.

See you there.


Key Takeaways

1. Breaches are Processes: A modern data breach follows a defined lifecycle of initial access, persistence, lateral movement, and exfiltration, with detection requiring visibility across all stages.

2. Traditional Defences are Insufficient: Signature-based tools and perimeter defences often fail because attackers use legitimate credentials, encrypted channels, and mimic normal user behaviour.

3. Detection Relies on Behavioural Clues: Effective detection focuses on anomalous sequences of activity, such as a single machine connecting to many internal servers or large, unexpected data transfers to external sites.

4. Compliance is a Byproduct of Understanding: Frameworks like DORA, NIST CSF, and GDPR require specific security measures; understanding the breach attack flow provides the context needed to implement those measures effectively.


Resources

The course materials folder contains downloadable resources for this lesson:

  • Lesson 1.1 Quick Reference Card - Summarise the key detection indicators for data breach stages (Initial Access, Lateral Movement, Exfiltration) and immediate isolation steps for a compromised endpoint on a single page.
  • Compliance Mapping Worksheet - Map your organisation's controls for detecting data breach activity to the specific DORA, ISO 27001, and NIST CSF requirements covered in this lesson.
  • Risk Assessment Template - Assess your organisation's exposure to data breach threats based on the attack vectors (like phishing for initial access) and techniques (like living-off-the-land for lateral movement) covered in this lesson.
  • Further reading - Links to the MITRE ATT&CK framework for detailed breach tactics, and official guidance on incident response from the NCSC (National Cyber Security Centre).

GC Agenda: March 2026 | Practical Law The Journal | Reuters Defence Masterclass | Threat Intelligence | Lesson 1.1
© LimitedView Limited | 2026

This is 1 of 16 lessons included in the full package.

Enrol Now β€” Unlock All Lessons

Want to track your progress? Create a free account

Choose Your Access

All plans include 30-day money-back guarantee

Taster

£ 19

Single course access β€” ideal for trying us out

  • Full course access
  • Completion certificate
  • Try before you commit

Or get everything

Access every course in the catalogue, including all future courses

£ 29 /mo
Monthly All-Access

Every course, cancel anytime

£ 249 /yr
Annual All-Access

Save 28% β€” Β£20.75/month effective

Teams

Transparent pricing, no sales call required

Starter Team

£ 499 /year

Β£99.80/seat effective

Up to 5 learners, all courses included

Growth Team

£ 999 /year

Β£66.60/seat effective

Up to 15 learners, all courses included

Scale Team

£ 1999 /year

Β£39.98/seat effective

Up to 50 learners, all courses included

Need 50+ seats? Contact us for a custom plan.

Fast Checkout

Start Learning in Minutes

Enter your details, choose a tier, and complete secure checkout. Access starts immediately after payment confirmation.

  • Stripe-secured payment and delivery workflow
  • Audit-friendly completion records
  • Escalate to enterprise volume licensing at any point

48-Hour Relevance Guarantee

If this course does not provide at least five actionable controls your team can deploy quickly, request a full refund within 30 days.

Secure checkout

Select pricing tier

By continuing, you agree to the terms and privacy policy.

Not ready to purchase? Create a free account to browse and track progress.

Questions Before You Enrol?

Immediately after successful payment. Your learning link is generated and delivered in the success flow.
Yes. Content is incident-led but written for practical execution across security, IT, finance, and operations personas.
Yes. Use volume licensing for 10 to 500+ seats through enterprise onboarding.