Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Incident Response: Your Last Line of Cybersecurity Defence
Articles

Incident Response: Your Last Line of Cybersecurity Defence

Stuart ReedBy Stuart ReedDecember 21, 2017Updated:December 30, 20215 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In 2018, no executive that reads the papers can be unaware of the cybersecurity risks facing their organisation. With the size and frequency of data breaches increasing, companies should be prepared to handle one when it happens.

The best way to cope with a security incident is to hit the ground running. A well-structured, efficient incident response plan helps to contain a breach and limit the damage. It’s a playbook that tells you what to do, who will do it, when, and how.

Unfortunately, these playbooks are scarcer than you might think, NTT Security has found. We surveyed 1350 non-IT business decision makers when preparing our 2017 Global Risk:Value report on companies’ attitudes to cybersecurity and saw some concerning results.

We found that only 48 per cent of respondents had an incident response plan. 31per cent companies were in the process of implementing one, and 10per cent were still writing it. One in ten companies either didn’t plan to implement one or didn’t know whether they had a plan or not (which is as bad as not having one at all).

Designing incident response

What does such a plan look like? At a high level, GCHQ’s National Cybersecurity Centre provides a guide to incident management as part of its ‘10 Steps to Cyber Security’ guidance.

It discusses the need to establish an incident response capability and provide specialist training across a range of technical and non-technical skills. This will be especially important when detecting and containing a cybersecurity threat, stopping it from spreading further.

The government’s guidance also makes a point of defining the required roles and responsibilities, which is one of the most important components of all. A team is only as good as its players.

To be truly effective, an incident response plan must be multi-disciplinary. When a breach occurs, a company must mobilise not only its technical staff to contain the problem, but also its legal team to assess corporate liability and potentially advise on forensic data gathering.

Other parties must be involved, too. Compliance experts must ensure that the organisation covers its regulatory bases, which will be an even more important component in 2018 when GDPR’s strict data protection and data breach notification measures come into play.

Marketing communications executives must handle crisis management and notify other key stakeholders outside the company. Human resources must explore how staff followed policies in the breach (or didn’t), and refine those policies while potentially applying disciplinary measures. Financial staff must assess the monetary impact, and let’s not forget customer service executives who must handle irate customer queries at the ‘sharp end’ of the problem.

Other aspects of a robust incident response plan according to UK government guidance include establishing a data recovery capability, which can be especially important in ransomware cases.

All eyes on the issue

To marshal all these departments and more, an organisation needs C-suite support. Board-level executives must appreciate and buy into the need for cybersecurity preparedness, and allocate the appropriate financial and human resources to support them. Here, at least, the organisations in NTT Security’s report seemed to be giving the matter executive attention. They allocated responsibility to executing the incident response plan evenly between the CEO (23 per cent), CIO (21 per cent), CISO (22 per cent) and COO (21 per cent).

Your incident response plan will help you to get ahead of a breach should it occur, but it isn’t the only part of your cybersecurity toolbox. If you can prevent security incidents with a broader information security policy, then you hopefully never need to pull that incident response team together for active duty.

The security policy is a range of preventative measures that employees can take to minimise the risk of data loss. Components of this plan should cover everything from acceptable use of computing resources through to proper data encryption procedures, and everything in between.

Executives should communicate the broader security policy to everyone, because all employees play a part in supporting it. Your incident response plan may be your blueprint for responding, but your security policy defines how you act to protect yourself, each minute of each day.

This, too, is something that companies could do better at. 79 per cent of those with a documented security policy communicated it to everyone in the organisation. That sounds promising, until you realise that just 56 per cent of companies had created such a policy in 2017. This leaves many companies with untrained, unaware employees who become potential weak links in the infosecurity chain.

Now is the time to get ahead of this issue by drawing together key executives and ensuring that both these policies are locked and loaded. Then, drive your security policy throughout your business culture, getting all employees on board. In this security climate, they are two of the most important documents in your business.

[su_box title=”About Stuart Reed” style=”noise” box_color=”#336588″][short_info id=’104049′ desc=”true” all=”false”][/su_box]

Stuart Reed

UK Director

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Visual data is the blind spot in enterprise security: that’s about to change

    May 4, 20267 Mins Read

    Making stolen data worthless: why security must start with the data

    March 30, 20265 Mins Read

    Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

    March 10, 20264 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}