Cyber Security Incident Management, Response and Recovery Guidance
Yesterday I spoke at the R3 Summit (Resilience, Response and Recovery) in London, on the topic of Cyber Security Incident Management and response. Given the Q & A and the ensuing discussion after my talk, the attendees were particularly interested in my views on incident containment ahead of recovery. Below is a summary of what I said. Step 1: Incident Management Planning and Preparation The most crucial part of incident management is the preparation, it is important to always consider cyber security incidents as a ‘When’ not an ‘If’ as you plan ahead. So here’s my ‘brain dump’ of an incident management planning strategy: A company Cyber Security Incident Management Policy It must define what the company (aka the board) consider as a cyber security incident Cyber Security Incident notification communications channel or even better a reporting application/system Upon identifying an incident who do staff notify (the incident management team) Staff awareness of how to...