Small and medium businesses rarely call up security consultants asking for help in improving their incident-response program; instead, when the companies do call, they are usually panicked, in the midst of a real security incident.
While incident response preparation has becoming increasingly important, most firms–especially small and medium businesses–will push off the creation of an incident response plan until the future. Playing through an incident-response simulation–a game–can help, security experts say. Creating a plausible scenario for a security threat to the business is much easier than trying to create a policy from whole cloth and helps to educate management on the impact of potential security threats.
SOURCE: darkreading.com
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.