Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Incident Response – How Late is too Late?
Articles

Incident Response – How Late is too Late?

ISBuzz TeamBy ISBuzz TeamJuly 7, 2015Updated:July 4, 20247 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Incident Response - How late is too late
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cyber threat awareness is not limited to an obscure crowd of coding geeks—and hasn’t been for a long time. In fact, just earlier this year, U.S. intelligence director James Clapper announced that cyber attacks top the list of threats facing the U.S.[1] The sheer number of breaches reported is testimony to the fact that IT teams are struggling to detect and fight off attacks despite increased efforts to keep up with the rising scale and complexity of threats. It appears that no business – regardless of its size and resources – is immune.

Why is it that many victims fail to successfully protect their assets despite a huge host of preventative measures? The answer is that, quite literally, time is of the essence. The following examines why time is critical for successfully fending off an attack, the reality most organizations face and most importantly, what tools and strategies are available to help.

A race against time

It is impossible to generalize how long it takes a cyber-attack to pass the critical stages of compromise and data exfiltration – there are simply too many variables involved. Unfortunately, in most cases, exfiltration begins in a few minutes after the infection has occurred. Ideally, catastrophic consequences are averted because threats are detected, investigated, and stopped as soon as detection occurs.

According to the 2014 Verizon Data Breach Investigations Report, nearly 90 percent of point-of-sale intrusions saw data exfiltration in minutes or seconds after compromise—and more than 90 percent of web app attack incidents required days or longer to contain. Any delay in incident response literally means more lost records, lost revenue, and losses of customer goodwill. It’s clear that rapid response should be a high priority, but often it’s difficult for organizations to address. My conversations with responsible IT managers indicate that the processes carried out by large organisations can take up to 14 days to complete.

Delayed response time is due to the many steps required to move from detection to containment and resolution. Legacy incident response involves manual effort, manual data entry or transfer, and even variable human analysis that often requires double-checking for accuracy. These steps include: security alert notification and centralized collection; data gathering about the targeted user and system; service desk appointment setting and local system data gathering for the targeted endpoint; unified analysis of system and target data; research across domain registration, antivirus detection systems, and intelligence systems; response decision analysis; and finally the enforcement action, which may also involve ticketing, change control, and interdepartmental negotiation for final action.

For global organisations this legacy incident response process can vary depending on time differences across geographically separated locations as well as the availability of staff across different departments, such as infrastructure, messaging, firewall, etc. If large organisations, who can afford the time and resources to put dedicated measures in place, are struggling—smaller businesses fare even worse without the means to actively invest in protection. It’s no coincidence that some of the larger more recent breaches were initiated through smaller partners of the targeted firms, allowing cyber criminals to gain a foothold before moving to attack the larger target. Law enforcement notification is usually how many businesses realize their networks are compromised. Clean-up alone can take more than a month. The Ponemon Institute estimates the time needed to resolve an attack is 45 days.[1]

Leaving networks open and vulnerable for extended periods of time to clean-up is embarrassing at best, crippling at worst. Take the Sony breach for example – even ahead of the big PlayStation Network break, an extra 25 million customer data sets were stolen undetected. The Global Cyber Security Center (GCSEC) states that this due to the fact that both internal incident response plans and security assurance practices proved to be ineffective. Too much time passed between intrusion detection and the acknowledgement that millions of records were stolen.[2]

The Target breach tells a similar story. In this case, the intrusion was detected and security teams alerted – yet the organisation stood by, watching 40 million credit card numbers leave their network before they interfered. The initial alert was missed.

Why do organisations struggle to contain threats?

At the core of the problem is the sheer scale, complexity and sophistication of the evolving threat landscape. The annual rate of new malware is quickly outpacing the ability to keep up with defensive measures and skilled personnel. In addition, most organisations are struggling to find the time and resources required to effectively invest in and operationalise new security technologies.

Once installed, there can be additional hidden challenges and costs. Equally, businesses can unwittingly find themselves left overwhelmed by complex coding and unable to obtain a meaningful output. In short, even if an organisation has spent hundreds of thousands, or even millions on detection techniques, all the information provided confirms that they do have malware – along with the 70-95 percent of other corporate networks across the globe.

This is not to say that prevention and detection aren’t necessary. In fact, tools such as encryption, blocking of known threats and employee training to recognise suspicious patterns (such as phishing emails) all contribute to the reduced likelihood of a successful attack. However, these measures need to be constant, 24/7 and always up-to-date with the latest attack vectors – a task virtually impossible to carry out manually or with limited in-house resources.

Third-parties, such as SIEM and intelligence vendors, have contributed to the identification and monitoring of new and unknown threat vectors. Unfortunately, relying on third-party code for new functions and integration can leave IT teams vulnerable and overwhelmed if they do not have the ability to customize and apply the code to their specific environment. In fact, some companies have revealed writing as many as 500 rules in order to filter out the ‘noise’ of their security processes – and the end result lacks fidelity and actionable output.

Links : 

  • Visit HERE.
  • Visit HERE.

The solution: actionable, automated, integrated intelligence

Even if all detection and prevention systems are working correctly, up-to-date, monitored and acted upon swiftly –it won’t be enough. Numerous reports fundamentally establish that successful attacks will continue to happen – even with the strongest of defences. Yes, a CEO might believe that investing in a number of costly prevention and detection systems should suffice to keep the business out of harm’s way; however, even the most timely alerts are useless if there is no clear path and information helping the IT team start effective counter measures.

For a defence to be successful, actionable insight has to be derived from each of the networks’ multiple, disparate systems. Often, organisations lack the infrastructure and volume of data needed to derive the much needed insight required to determine the appropriate counter-threat measures. Plus, the reality is that solutions requiring custom module development, integration and maintenance can quickly become as costly as building and maintaining existing dedicated solutions. The result may delay or even hamper an organizations’ ability to act immediately against bad actors.

Organizations need threat response technology that takes data from all threat detection tools and narrows down the alerts with enhanced, automated threat intelligence and context. Once threats are prioritized, this same system then confirms infections and helps IT teams focus resources on protecting the organization against threats. The bottom line is that intelligent threat response technology, which combines timely detection, verification and protection, is a necessary security layer for any organization trying to keep up with today’s malicious threats.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}