Rapid Cyberattack Assessment Workshop (Remote) — Ransomware Risk Assessment & Security Roadmap
Rapid Cyberattack Assessment Workshop (Remote) is a 2-day remote training workshop for Office 365 and Microsoft 365 customers. It helps identify potential cybersecurity risks related to rapidly spreading attacks, such as ransomware, and provides guidance on Microsoft technologies that can help mitigate those risks. SKU: ITPWW170TRNOT. Price: $990. Duration: 2 days. Manager: Mike Mackey.
What this engagement is
This remote workshop helps customers assess potential vulnerability to rapid cyberattacks, including situations where the customer may already have been affected by an attack, is unsure about the status of defensive measures, or wants a risk assessment related to rapid cyberattacks. The objective is to help customers identify potential cybersecurity risks and gain knowledge about technologies that can help mitigate those risks. An onsite form of the workshop is also available at https://o365hq.com/license/ITPWW155TRNOT. Published date: 2019-03-14.
Success criteria
What you receive
How the work unfolds
Kickoff meeting; introduction to the engagement: objectives, flow, responsibilities, and governance; provide and explain preassessment questionnaire to the customer.
Ensure availability of necessary resources; review RCA tool results; begin road map planning; confirmation on the completeness of the questionnaire or RCA tool output; definition of rapid cyberattacks; review, explain, and discuss questionnaire and tool findings; identify opportunities to leverage already deployed entitlements; perform gap analysis; finalize road map.
Road map delivery workshop; solution(s) briefing and Technical Readiness presentations; engagement close-out.
Prerequisites
Who does what
IT Partner
- Understand the customer's status vs cyberattacks. Help the customer identify elements in their IT environment that might make it prone to rapidly spreading and potentially destructive cyberattacks (e.g., ransomware attacks).
- Cyberattacks technical security readiness. Provide guidance, recommendations, and best practices on how to successfully use Microsoft technologies to mitigate security threats that are associated with rapid cyberattacks.
- Create rapid cyberattack road map. Provide prioritized and actionable road map for the customer, containing proposed actions based on discovered gaps, considering user impact and implementation cost.
- Map Microsoft technology capabilities and Partner services to assessment findings, taking into account the customer's objectives and requirements.
Your team
- Information: This includes accurate, timely (within three business days or as mutually agreed upon), and complete information
- Access to people. This includes access to knowledgeable customer personnel, including business user representatives, and access to funding if additional budget is needed to deliver project scope
- RCA tools should be installed and configured
What's not included
Limitations & technical notes
Frequently asked questions
What is the Rapid Cyberattack Assessment Workshop (Remote)?
The Rapid Cyberattack Assessment Workshop (Remote) is a 2-day remote training and assessment workshop for Office 365 and Microsoft 365 customers. It helps identify cybersecurity risks related to rapidly spreading attacks such as ransomware and provides guidance on Microsoft technologies that can help mitigate those risks. The service SKU is ITPWW170TRNOT.
Who is this workshop designed for?
This workshop is designed for Office 365 and Microsoft 365 customers who want to assess their exposure to rapid cyberattacks. It is relevant if an organization may already have been affected by an attack, is unsure whether its current defenses are adequate, or wants a structured risk assessment focused on threats such as ransomware.
How long does the Rapid Cyberattack Assessment Workshop take?
The Rapid Cyberattack Assessment Workshop (Remote) is delivered over 2 days. The engagement is structured around remote webinar sessions that include kickoff, assessment review, road map planning, and final road map delivery.
How much does the Rapid Cyberattack Assessment Workshop cost?
The listed price for the Rapid Cyberattack Assessment Workshop (Remote) is $990. Any taxes, procurement requirements, implementation work, or additional services are not specified in the service description, so they should be confirmed with IT Partner before purchase.
What is included in the workshop?
The workshop includes a kickoff presentation, a preassessment questionnaire, review and discussion of Rapid Cyberattack Assessment tool reports, and a rapid cyberattack road map. The road map is intended to be prioritized and actionable, with proposed actions based on discovered gaps and consideration of user impact and implementation cost.
What deliverables will we receive?
Customers receive a kickoff presentation, an organizational questionnaire covering exploit mitigation, attack surface reduction, privileged access, and business continuity practices, Rapid Cyberattack Assessment tool reports, and a rapid cyberattack road map. The road map maps Microsoft technology capabilities and Partner services to the assessment findings based on the customer’s objectives and requirements.
What happens during the kickoff webinar?
The kickoff webinar introduces the engagement objectives, flow, responsibilities, and governance. IT Partner also provides and explains the preassessment questionnaire so the customer can supply information needed for the assessment.
What happens during the assessment review and road map planning webinar?
During the second webinar, IT Partner helps ensure required resources are available, reviews Rapid Cyberattack Assessment tool results, confirms questionnaire and tool output completeness, and discusses findings. The session also covers the definition of rapid cyberattacks, gap analysis, opportunities to use already deployed entitlements, and final road map planning.
What happens in the final workshop session?
The final session is a road map delivery workshop. It includes solution briefings, Technical Readiness presentations, delivery of the rapid cyberattack road map, and engagement close-out.
What are the prerequisites for the workshop?
The Rapid Cyberattack Assessment tools should be installed and configured before the workshop. The customer is also expected to provide accurate and complete information, timely responses, and access to knowledgeable personnel, including business user representatives where needed.
What are the customer’s responsibilities during the engagement?
The customer is responsible for providing accurate, timely, and complete information, generally within three business days or as mutually agreed. The customer must also provide access to knowledgeable personnel and ensure the Rapid Cyberattack Assessment tools are installed and configured.
What is IT Partner responsible for during the engagement?
IT Partner is responsible for helping the customer understand its status against rapid cyberattacks and identifying IT environment elements that may make it prone to destructive attacks such as ransomware. IT Partner also provides Microsoft security guidance and best practices, creates the prioritized road map, and maps Microsoft technology capabilities and Partner services to the assessment findings.
Does the workshop include remediation or implementation of security controls?
The stated scope focuses on assessment, guidance, report review, and road map creation. Implementation of Microsoft security technologies or remediation of discovered gaps is not listed as included, so any hands-on implementation should be confirmed and scoped separately with IT Partner.
Will the workshop stop an active ransomware attack or provide incident response?
The workshop can be relevant when a customer may already have been affected by a rapid cyberattack, because it helps assess risks and identify mitigation opportunities. However, the service description does not state that it provides emergency incident response, containment, forensic investigation, or guaranteed attack recovery, so urgent response needs should be confirmed separately.
Will there be downtime or business disruption during the workshop?
The workshop itself is delivered remotely as a training and assessment engagement, so it is not described as requiring production downtime. Any impact related to installing or configuring the Rapid Cyberattack Assessment tools is not specified in the service description and should be confirmed with IT Partner before the engagement.
What types of risks does the assessment look for?
The assessment focuses on elements of the customer’s IT environment that may increase exposure to rapidly spreading and potentially destructive cyberattacks, including ransomware. It considers areas such as exploit mitigation, attack surface reduction, privileged access security, and business continuity practices as reflected in the questionnaire and assessment tool outputs.
Does the workshop use our existing Microsoft 365 or Office 365 entitlements?
The workshop includes identifying opportunities to leverage already deployed entitlements. IT Partner maps Microsoft technology capabilities to the assessment findings so the customer can understand which Microsoft capabilities may help mitigate identified risks.
What do we get after the workshop is complete?
After completion, the customer receives a rapid cyberattack road map with proposed actions for addressing discovered gaps. The road map is prioritized and actionable, and it considers user impact, implementation cost, customer objectives, and requirements.
Is an onsite version of the workshop available?
Yes, the service description states that an onsite form of the Rapid Cyberattack Assessment Workshop is also available. The remote workshop is SKU ITPWW170TRNOT, and customers should confirm onsite availability, pricing, and logistics with IT Partner.
Are there any exclusions or out-of-scope items?
The source service description does not list specific out-of-scope items or additional-cost exclusions. Because implementation, remediation, incident response, and other follow-on services are not explicitly included, customers should confirm exclusions and any optional services with IT Partner before purchasing.