Train your team

The Malicious Mindset Workshop.

Teach your security team to think like the adversary.

A full day with your security team: a healthcare ransomware tabletop, the malicious mindset session taught live with heavy Q&A, and a prioritized action plan ranked by attacker impact. No lab setup, no network access, no pre-engagement prep.

The day

Four parts, each building on the last.

Your tools in use, your team in place, and a working operator in the room.

01

Context

An introduction to the malicious mindset framework and why the attacker’s vantage point holds a structural advantage. Your team grasps the core asymmetry that shapes the rest of the day.

02

Tabletop exercise

A realistic healthcare ransomware attack chain from initial access to encryption. Your team responds in real time, uncovering blind spots and testing key assumptions as the scenario unfolds.

03

Malicious mindset session

The intellectual core of the day. A deep dive into persistence, living-off-the-land tradecraft, and adversary evasion—taught live with heavy Q&A focused directly on your security stack.

04

Action plan

A prioritized roadmap ranked by attacker impact, highlighting your highest-value gaps. Your team leaves with clear direction on where to focus their time and existing expertise.

You leave with three written deliverables, built for your environment

Attacker Playbook

How adversaries think and move through environments like yours.

Tooling Recommendations

Product guidance with attacker-perspective rationale. What to buy, what to skip, and what to fix first.

Board-Ready Kit

Executive language and ROI framing. The documentation that gets gaps funded.

Pricing

Choose your format.

A flat rate for the day, quoted on scope, with add-ons to expand it or options to scale it down. Pricing is shared on the introductory call.

One day

Virtual

The full day, delivered over video conference.

  • Healthcare ransomware tabletop
  • The malicious mindset session, live with Q&A
  • Prioritized action plan
  • All three written deliverables, built for your environment

One day

On-site

The full day, in your building.

  • Everything in the virtual format
  • Physical environment observation
  • Extended whiteboarding, far more interactive
  • Informal access to the operator all day
  • Executive / board readout included

Shape the day

Additional seats · tooling deep-dive · 30-day follow-up call · executive readout for virtual engagements. Add-ons are priced on scope and quoted before you commit.

Only want a partial or half a day? Tell us in your request, and we’ll scope the quote accordingly.

The guarantee

Actionable findings, or we come back free.

If your team doesn’t leave the Workshop with actionable findings and new confidence recognizing adversary activity, the founder returns for a second day at no charge to close the gap. Still not satisfied? Full refund. You keep every written deliverable either way.

The bottom line for your board: actionable findings, or you don’t pay.

Questions

What security leaders ask us.

We already run penetration tests. Why this?

A penetration test finds your network vulnerabilities. The Malicious Mindset Workshop answers a different question: would your team recognize someone actively exploiting them, and act in time? Both matter, but most hospitals only ever measure the first. Teams that do both find the Workshop changes how their analysts interpret pentest findings.

Do you need access to our network?

No. The Workshop is advisory and educational: no live exploitation, no access to your production network, no access to patient data. If it helps, you can share architecture diagrams or network maps so the day speaks to your environment, and those are kept free of PHI, so no protected health information ever changes hands. Because of that, the engagement doesn’t require a HIPAA business associate agreement, which makes vendor review unusually fast. A scoped SOW arrives with booking confirmation and can state the no-PHI condition in writing, and if your compliance office wants additional paperwork, we’ll work through it.

How do I get this approved?

The Board-Ready Kit is included in the base price for exactly this reason: board-ready language, ROI framing against the cost of a healthcare ransomware event, and approval materials that work whether you’re the champion taking this upstairs or the CISO taking it to the board. A twenty-minute call with the founder and your leadership is also available at no charge if that would accelerate the conversation. Documented gaps are how security leaders win budget, and the engagement is built to produce that evidence.

What exactly does the price depend on?

Format and scope. Virtual and on-site are the two anchors, and the quote moves from there with team size, a tooling deep-dive, a 30-day follow-up call, or an executive readout for virtual engagements. If you only want part of the day, the tabletop or the mindset session on its own, the menu flexes down too. You’ll have a written quote before any commitment.

Who should attend?

The core security team: SOC analysts, security managers, and IT staff with detection and response responsibility. The champion (security director or manager) should be present for the full day. For on-site engagements, the executive readout at day’s end is designed for leadership who can’t attend the full session.

What if it doesn’t produce what you promised?

The Actionable Findings Guarantee covers this explicitly. If your team doesn’t leave with actionable findings and new confidence recognizing adversary activity, the founder returns for a second day at no charge. Still not satisfied after that second day? Full refund. You keep all written deliverables either way.

Get in touch

Twenty minutes. No slide deck. Bring your hardest questions.

A short call about where your team is today, what they’re working with, and whether the Workshop is the right fit. Adversant runs a small number of engagements each quarter by design, so dates are limited.