A Goal Without A Plan Is Just A Wish

We can all agree that if two buildings are on fire, the building that has taken steps to reduce the ability of the fire to spread, has fire marshalls, evacuation plans and a sprinkler system which are all regularly tested is likely to be less damaged than the one without any of these.

Additionally, we can also agree that the longer the fire is burning, the more damage it causes.

The same can be said in the realm of cyber security (and now we have research to back it up). IBM’s 2023 Cost of a Data Breach Report tells us that investing in a robust incident response (IR) strategy is key to limiting damage from a breach and can reduce costs by up to a third. The report also found that the most effective IR strategy for reducing the period that the ‘cyber fire’ is burning was to combine formation and testing. This led to a decrease of 19.4% in the time taken to identify and contain a breach, saving organisations, on average, over $1m.

So we should know (both through IBM’s cyber research and common sense) the importance of not only having a well-baked IR plan, but one that is tested thoroughly and regularly. Yet do we actually do this? 

Plans Need To Be Tested

On the subject of whether a goal without an IR plan is just a wish, the common sense and wisdom of Antoine de Saint-Exupéry can teach us a lot (in life as well as cyber security). 

“A goal without a plan is just a wish,” whilst originating from a children's book author (and pilot), is very solid advice. So how do we move from wishes, to plans, to goals? It is very easy in our industry to develop something akin to “IR-plan envy.” We look around and see other people’s advanced IR plans and their incredible level of management buy-in and funding. 

However, for organisations without an IR plan or reviewing an existing one, there is plenty of useful guidance included in the ISO/IEC Standard 27035. What makes IR plans and processes special is their cyclical nature. Rather than being a linear process that is completed, they are a feedback loop of continuous improvement.

This is why starting can appear to be the hardest part but is also the most essential. It is also why testing them is so vital. 

Only by going through drills will organisations discover whether there are any opportunities for improvement in their execution of the plan and, in a more fundamental sense, if it is even likely to work. Things like communication gaps, outdated procedures, team members unsure of their responsibilities and technology issues can all be identified in a safe environment of testing. 

Testing can not only highlight unclear roles within the IR team and wider organisation but also provides an opportunity to build trust and understanding between areas of the business that may not regularly interact. 

Implementing and regularly testing a cyclical incident response plan can also serve to combat the toxic elements of finger pointing and blame. Where organisations can leave behind notions of “passing”, “failing” or “blaming” and move towards a culture of improving processes, culture and security can improve dramatically. 

A Final Word On Regulations & Compliance 

It is at this point that some authors may throw in the scary Boogie Man of ‘Regulations’ and ‘Compliance’ to ensure that you agree with and participate in the points made so far. A “Now go ‘do brilliant incident response’ or the regulator will get you” approach. 

Whilst regulator interaction is beyond the scope of this article it is worth noting that a well-defined IR plan with evidence of regular testing and improvement forms a fantastic vehicle for communicating the security posture of an organisation to regulators and stakeholders alike. 

In its simplest sense it says, “we care enough about our stakeholders to take this seriously that we operate from a position of realism as opposed to blind optimism.” We have plans for if things fail rather than just failing to have plans. 
 
Introduction of new regulations, such as those introduced by the Securities and Exchange Commission (SEC) in December 2023, are often presented in the media as introducing an unwelcome level of scrutiny when they could equally as easily be viewed as an opportunity to promote openness and trust between stakeholders, regulators and organisations. 

Through the practice of implementing and maintaining an IR plan, communication with regulators can become more refined (and ironically less likely to be required).

If your goal is a robust information security programme and you don’t have an incident response plan that you are regularly testing, what you actually have is an “information security wish.” If this is your organisation, now is the time to take that first step. It does not need to be perfect but it does need to be. 

Chris Denbigh-White is CSO at Next DLP 

Image: cottonbro studio 

You Might Aso Read: 

The Duality of Cybersecurity:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« Managed Security Services In The Age of Advanced Threat Intelligence 
US Navy Will Use Data Analytics For Maritime Security »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

CyTech Services

CyTech Services

CyTech provides unique services and solutions complemented with professional subject matter experts to both the Federal and Commercial sectors.

XenArmor

XenArmor

XenArmor products include NetCertScanner, an enterprise software to scan & manage expired SSL Certificates on your local network or internet.

Assuria

Assuria

Assuria Cyber Security solutions provide protective monitoring of systems and user activity across the whole IT infrastructure.

QOMPLX

QOMPLX

QOMPLX integrate, contextualize, and analyze data from virtually any source to help you identify operational risk and inefficiencies throughout the enterprise.

ECOMPLY

ECOMPLY

ECOMPLY is an all-in-one GDPR Compliance Solution. Efficient data protection management system for businesses and DPOsomply.

RapidScale

RapidScale

RapidScale’s managed cloud solutions provide reliable, innovative, and secure services, all complete with white-glove service and full management options.

Orbus Software

Orbus Software

Orbus develops, markets and sells enterprise software which helps large, blue chip and government organisations across the globe to achieve digital transformation outcomes.

Firmus

Firmus

As the leading penetration testing services provider in Malaysia, Firmus evaluates the ability of your internal or external information assets to withstand attacks.

MainNerve

MainNerve

MainNerve helps secure networks, applications, people, and facilities… enabling businesses to reduce risk and increase their cybersecurity posture.

Topsec Cloud Solutions

Topsec Cloud Solutions

The Topsec Managed Email Security Platform eliminates Spam, Viruses, Malware, and Phishing.

Paubox

Paubox

Paubox offers secure, HIPAA compliant email and marketing solutions to fit the needs of modern healthcare organizations of every size.

Quartz Network

Quartz Network

Quartz Network is a curated community for change-makers, up-and-comers, and professionals who are ready to grow, adapt, and thrive.

Global Market Innovators (GMI)

Global Market Innovators (GMI)

Global Market Innovators (GMI) delivers secure technology solutions to organizations in need.

Teal Technology Consulting

Teal Technology Consulting

TEAL Technology Consulting is your trusted advisor for all your information security needs.

SureStack

SureStack

SureStack is an AI-native cybersecurity platform that provides organizations with continuous validation, optimization, and real-time security of their cybersecurity stacks.

Blue Networks & Infrastructure (BNI)

Blue Networks & Infrastructure (BNI)

Blue Networks and Infrastructure (BNI) is an innovative systems integrator and managed services provider.