2. Who’s Watching After Business Hours?
Cybersecurity is a 24/7 operation. Attackers work around the clock, and defenders must be available to respond quickly, even outside of normal business hours. If you don’t already have a 24/7 security operations center, consider standing one up or contracting with a managed detection and response provider to handle incidents during off hours. You should also have an on-call rotation of senior cybersecurity experts who can step in if a situation escalates.
3. How Will We Know How Far the Attack Has Spread?
Determining the scope of a security incident is one of the most difficult and most important activities during breach response. Once you’ve contained the damage, you need to identify which systems and data were compromised so you can conduct a proper response. This is only possible if you’ve logged security data and retained it for a sufficient period. Now is a good time to verify that you’re tracking all of the information that you’ll eventually need.
4. Does Everyone Know Their Role?
Incident response plans are only effective if responders know about them and understand their individual roles. Conduct regular training and exercises to ensure that teams remain current, even if they don’t respond to incidents on a regular basis. Gathering everyone around a table (physical or virtual) and walking through a scenario is a great way to refresh everyone on their responsibilities and ensure that the team is ready to respond to the next cyberattack.
LEARN MORE: Find out why detection and response are the new security baseline.
5. What Does Success Look Like?
Your cybersecurity incident response plan is designed to guide your efforts in the immediate aftermath of a cybersecurity incident. A successful plan provides you with the procedures, tools and human resources necessary to respond to that incident. At the conclusion of each incident, you should take time to conduct a lessons-learned session with your team and assess how well the response unfolded. This is a great opportunity to learn about how the plan worked under fire and make updates to improve the organization’s response to the next incident.
