Creating A Cyber Incident Response Policy

For any type of Cyber security disaster, does your company have an incident response plan for a data breach? 
 
Incident response is an organised approach to addressing and managing the aftermath of a security breach or cyberattack. One of the best ways to gain some peace of mind when it comes to data breaches is to create and regularly test an incident response plan (IRP). Creating an IRP does not have to be a lengthy, intimidating process. 
 
In fact, according to the National Institute of Standards and Technology (NIST), an IRP simply provides the instructions and procedures an organisation can use to identify and respond to the effects of cyberattack. If your organisation is proactive, and in compliance with the growing number of data privacy laws, you should have a policy in place for that worst-case scenario of your files being compromised by a bad actor.
 
Do you also have plans in place if your business suffers another type of cyber incident?
 
What would you do if your e-commerce website was hit with a distributed denial-of-service (DDoS).  This type of attack can take you offline for hours. And if an employee clicked on a phishing email that spread malware throughout the system is disruptive and can be disastrous. Do you have someone monitoring your social media sites, which represent the identity of your company?
 
In her talk to an MPower 2019 audience, Allison Cerra, senior vice president and chief marketing officer of McAfee, said her worst day came one Easter Sunday when she was alerted that one of the company’s social media sites was defaced. The logo was turned into an obscene graphic. The description and other posts were replaced with vile commentary. The company faced a serious cybersecurity crisis without their network or corporate data ever being impacted. Cerra said that, the company wasn’t ready for it.
 
Even though the company took positive steps to address the cyber incident, they kept leadership involved, they had an employee deleting unnecessary administrative access, they realised there were definite mistakes made along the way and during the cleanup phase. The biggest mistake, Cerra said, was that there was no real process in place to handle the attack.
Cybersecurity Conversation
 
Putting an incident response plan in place begins with a conversation.
 
“We can’t have a conversation about security if we don’t start one,” Cerra told the audience. Everyone in the company should be included in that conversation, she added, because cybersecurity is a team sport. Everyone within the organisation has a role, and everyone needs to know what their role is. Its the same thing with different departments within the organisation. Each department has its unique security needs, and its unique duty when it comes to addressing a cyber incident and managing the response.
 
Nor is the conversation a one-and-done speech by the CEO or chief information security officer (CISO). As Cerra noted, “Successful companies communicate early and often.” They hold regular drills to be prepared for the response, because there will be a need to have a response. These conversations need to be holistic.
 
Cyber incidents are more than data breaches and stolen data. They are more than someone infiltrating your network. In McAfee’s case, it was a third-party site, where someone else had controls over security. That complicated McAfee’s ability to respond, too, which is why an incident response plan should include regular audits of 3rd parties. How do they handle cybersecurity incidents on their end? What steps do they require from their partners to mitigate an incident? Who do you talk to if there is an incident involving your reputation and data on their end?
 
Employee’s Responsibility
Response teams are often made up of a select few representatives, usually management and C-level, from different departments. The rest of the organisation is often kept in the dark about cybersecurity response and overall cyber hygiene. That’s because the cybersecurity team is often invisible to the rest of the workforce, until, of course, something bad happens.
Any employee who uses a computer to access the network, whether on premises or remotely, whether on a company-owned device or a personal one, must step up to the plate when it comes to cyber security. 
 
They need to be included in the cybersecurity conversation on a regular basis, but they should also own their own cybersecurity role within the organisation. “Employees are equally responsible in ensuring those patches to laptops, mobile devices and other personal technologies remain current,” Cerra said.
 
It should go beyond patching, too. There are a lot of little things that employees should know and practice. Recognising phishing emails and not opening suspicious links and attachments is something that all employees have (or should have) stressed to them over and over, but what else are your security and response teams doing to make employees part of the cybersecurity solution?
 
One such solution is ensuring employees know how to respond if there is a cyber incident. For instance, the default for many of us when we hear of a data breach is to automatically change passwords.  But when should passwords be changed? In many cases, changing a site’s administrative password should be step one because as soon as an attacker realise they have been discovered, they can also change the password, locking the actual security team out completely.  In other cases, the password should be changed after the incident is mitigated, changing passwords before a vulnerability is patched gives hackers the chance to go in and steal the new ones. In other instances, HR and IT should know to immediately rescind permissions and access when employees leave or shift job responsibilities.
 
Types of security incidents
There are various types of security incidents and ways to classify them. What may be considered an incident for one organization might not be as critical for another.
 
The following are a few examples of common incidents that can have a negative impact on businesses:
 
A distributed denial of service (DDoS) attack against critical cloud services.
• A malware or ransomware infection that has encrypted critical business files across the corporate network.
• A successful phishing attempt that has led to the exposure of personally-identifiable information (PII) of customers.
• An unencrypted laptop known to have sensitive customer records that has gone missing.
 
Security incidents that would typically warrant the execution of formal incident response procedures are considered both urgent and important. That is, they are urgent in nature and must be dealt with immediately and they impact important systems, information or areas of the business.
 
The bottom line is that when a cyber incident hits a company, everyone is impacted in some way, from the CEO and board of directors to the receptionist at the front desk. Your organisation needs a current cyberattack and response plan.
 
If you need help with this process, please Contact Cyber Security Intelligence for advice. 
 
SANS / Kroll:              TechTarget:             Security Intelligence:       
:
You Might Also Read:
 
Top 5 Rules For Laying Out An Employee Cybersecurity Policy:
 

 

 

« Beware Phishing Emails
Darktrace Wins Lloyds Award »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Vanguard Integrity Professionals

Vanguard Integrity Professionals

Vanguard Integrity Professionals is an independent provider of enterprise security software solutions that address complex security and regulatory compliance challenges.

France Cybersecurity

France Cybersecurity

France Cybersecurity represents the French cybersecurity industry to raise international awareness of French cybersecurity capabilities and solutions.

NetFort

NetFort

NetFort provides software products to monitor activity on virtual and physical networks.

Zettaset

Zettaset

Zettaset’s XCrypt Data Encryption Platform delivers proven protection for Object, Relational/SQL, NoSQL, and Hadoop data stores…in the cloud and on-premises.

Cyxtera Technologies

Cyxtera Technologies

Cyxtera offers powerful, secure IT infrastructure capabilities paired with agile, dynamic software-defined security.

Highland Capital Partners

Highland Capital Partners

Highland Capital Partners is an early stage venture capital firm focused on category-defining businesses in consumer and enterprise technology, including cybersecurity.

Citalid

Citalid

The Citalid cyber risk management platform combines threat and business intelligence to identify the risks scenarios you face.

Censys

Censys

Our customers rely on Censys data to get the global visibility they need of their attack surfaces in order to proactively prevent nation-state attacks and emerging threats.

SecSign Technologies

SecSign Technologies

SecSign Technologies delivers user authentication, messaging, file sharing, and file storage with next generation security for company networks, websites, platforms, and devices.

BriskInfosec Technology & Consulting

BriskInfosec Technology & Consulting

BriskInfosec provides information security services, products and compliance solutions to our customers.

Nine23

Nine23

Nine23 are a highly focused cyber security solutions company that defines, builds and manages innovative services, enabling end-users to use technology securely in today’s workplace.

Cyber7

Cyber7

CYBER7 is a National Cyber Security Innovation community initiated by Israel National Cyber Directorate, Ministry of Economy and Israel Innovation Authority led by Tech7 – Venture Studio.

Third Point Ventures

Third Point Ventures

Third Point brings deep technical expertise, a strong network of relationships, and decades of investing experience to add value to our partners throughout their journey from idea to IPO and beyond.

Anonos

Anonos

Anonos is a global software company that provides the only technology capable of protecting data in use with 100% accuracy, even in untrusted environments.

OccamSec

OccamSec

OccamSec is a leading provider in the world of cybersecurity. We provide accurate, actionable information to reduce risk and enable better informed decisions.

SecureKloud Technologies

SecureKloud Technologies

SecureKloud is a global leader in the Cloud services arena. Our experience in cloud consulting and servicing for highly regulated industries extends more than a decade.