Skip to main content
CYB-0350ExpertCurrent Intake
XCIR

XCIR: Xcademia Cyber Incident Response Practitioner

6-Day Instructor-Led Programme

The XCIR Certification Programme is the practitioner standard for incident responders who contain, eradicate, and recover from cyber incidents across enterprise environments while meeting NIS2, DORA, and UK GDPR regulatory notification obligations. Assessed on Day 6 through a supervised live incident response scenario. No MCQs. No exam. No certprep guide.

Duration

6 Days

Price

$4,995

XCIR: Xcademia Cyber Incident Response Practitioner
Duration
6 Days
Complete in 6 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

A cyber incident does not wait. When the call comes, the incident responder who has only passed a multiple choice test is dangerous. XCIR is built for professionals who need to perform under pressure: containing the attacker, preserving evidence, communicating with leadership, and meeting the regulatory notification timelines that NIS2 and DORA now mandate.

Across six instructor-led days, participants build capability across the complete IR lifecycle: preparation and planning, detection and scoping, containment strategy, evidence preservation, eradication, recovery, and post-incident activities. Sessions cover Windows and Linux IR, active directory compromise response, cloud IR across AWS and Azure, ransomware playbooks, insider threat response, and regulatory notification workflows aligned to NIS2 Article 23, DORA Article 17, and UK GDPR Article 33.

On Day 6, participants manage a live simulated incident from initial detection through containment, eradication, recovery, and final incident report. The senior practitioner observes decision-making, technical execution, communication, and regulatory compliance throughout. XCIR certificate and Practitioner Assessment Report issued together. Aligned with NIST SP 800-61, ISO 27035, CISA IR Playbooks, NIS2, DORA, UK GDPR, and NHS DSPT.

Hands-On Learning

Live IR scenario exercises covering Windows triage, active directory compromise response, cloud IR across AWS and Azure, ransomware containment, evidence preservation, and regulatory notification decision making under time pressure.

Mentor-Led Sessions

Mentor-led sessions covering real incident decision-making at key junctures: isolate or monitor, notify or investigate further, pay ransom or restore from backup. Drawn from real-world incident case studies.

Career-Ready Skills

Lead structured incident response engagements from detection through recovery, maintain regulatory notification compliance under time pressure, and produce professional post-incident reports.

Learning Outcomes

Lead structured incident response engagements from initial detection through containment, eradication, recovery, and post-incident review

Execute Windows and Linux live response, active directory compromise triage, and cloud incident response across AWS and Azure

Manage ransomware response scenarios including blast radius scoping, backup integrity, regulatory notification, and recovery sequencing

Meet regulatory notification obligations under NIS2 Article 23, DORA Article 17, and UK GDPR Article 33 during live incidents

Preserve legally sound evidence during active IR while balancing speed of containment with forensic integrity requirements

Produce professional post-incident reports with root cause analysis, timeline reconstruction, and actionable recommendations

Prerequisites

1

Minimum 12 months in a SOC, security operations, or IT infrastructure role with exposure to security incidents

2

Basic understanding of Windows and Linux operating systems, networking, and Active Directory

3

Familiarity with at least one security monitoring tool: SIEM, EDR, or log analysis

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • NIST SP 800-61 IR lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned
  • ISO 27035 phases: plan and prepare, detect and report, assess and decide, respond, and lessons learned
  • IR team structure: RACI design, MLRO and legal interface, and communication tree construction
  • IR plan development: scope, escalation criteria, authority levels, and communication templates
  • Tabletop exercise design: scenario construction, facilitation methodology, and improvement tracking
Stage 5Final Capstone

XCIR: Xcademia Cyber Incident Response Practitioner — Capstone Project

On Day 6, participants receive a simulated enterprise environment experiencing an active incident. They must triage, scope, contain, eradicate, and initiate recovery while meeting simulated regulatory notification deadlines and communicating with simulated leadership. The senior practitioner observes decision quality, regulatory compliance, and technical execution throughout. The XCIR certificate and Practitioner Assessment Report are issued together on passing standard.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • NIST SP 800-61

    Global

    Computer Security Incident Handling Guide: primary IR lifecycle methodology throughout all domains

  • ISO 27035

    Global

    Information Security Incident Management: phased incident management process alignment

  • CISA IR Playbooks

    Global

    US CISA incident response playbook methodology: ransomware and phishing playbooks referenced throughout

  • NIS2 Article 23

    Global

    Mandatory early warning (24h), incident notification (72h), and final report (monthly) obligations for essential and important entities

  • DORA Article 17 to 23

    Global

    ICT-related incident classification, notification thresholds, and reporting obligations for EU financial entities

  • UK GDPR Article 33

    Global

    72-hour personal data breach notification obligation to the ICO: covered in regulatory notification module

  • NHS DSPT

    Global

    NHS Data Security and Protection Toolkit mandatory incident reporting and classification requirements

  • NCSC IR Guidance

    Global

    UK NCSC incident management guidance: breach response principles and stakeholder communication

Skills You'll Gain

Master these in-demand skills through hands-on practice

Incident response lifecycle (NIST 800-61)Windows and Linux IR triageActive directory compromise responseCloud IRRansomware ResponseEvidence PreservationRegulatory NotificationContainment strategyEradication and persistence huntingRecovery planningPost-incident reportingIR playbook development

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Incident ResponderIR Team LeadSOC L3 AnalystSecurity Operations ManagerCyber Insurance IR SpecialistDFIR Consultant
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

6 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$4,995+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised XCIR: Xcademia Cyber Incident Response Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of XCIR: Xcademia Cyber Incident Response Practitioner, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

GCIH is a 6-day course followed by a 5-hour open-book exam. Total cost is approximately $9,779. XCIR is 6 instructor-led days ending in a supervised live incident response scenario on Day 6: not an open-book exam but an observed real-time response engagement. The Practitioner Assessment Report documents your incident management decisions, regulatory compliance, and technical execution. Less than half the GCIH price.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options