Cyber security

profileBfh
Alqethami-Assignment5-IncidentResponse-presubmissionfeedback.pptx

Importance of cyber incident response

Banan Alqathami

1

Cyber Incident Response Process

Incident response Process comprises of following steps;

Preparation: No company can muster an efficient reaction to an issue in a matter of minutes. Our organization needs a similar strategy for anticipating and dealing with crises.

Detection & Analysis: According to the National Institute of Standards and Technology (NIST), the most challenging aspect of incident response for many organizations is frequently the process of accurately detecting and assessing incidents.

Containment Eradication & Recovery: During this phase, the priority is placed on minimizing the effects of the incident and restoring service as quickly as possible.

Post Incident Activity: One of the most crucial yet frequently disregarded aspects of incident response is learning and improving in the wake of an incident. The incident and the subsequent response are examined here. Goals here include reducing recurrence and enhancing our ability to respond to similar situations in the future.

2

Cyber Incident Response Team

It is our responsibility to have a cyber incident Response team in place to protect our organization. We need everyone to pull together and work as a unit if we want to achieve our goal. As a member of this team, it is my duty to create and maintain the relevant plans and documentation. They should have access to the parts of the plan that pertain to their work, and they should be updated on any changes. A feedback loop that adjusts the plan as new information becomes available is essential.

The antecedents and indications of an event are the telltale symptoms that something bad is going to happen, or has already happened. Once found, the team must analyze the uncovered signals to identify whether or not a precursor or indicator is part of an assault or a false positive.

Documentation of the event If the alert turns out to be real, the team will need to start recording information about the incident and keep track of their progress as they work to resolve it. NIST identifies incident priority as the most important decision point. The organization’s staff cannot handle occurrences in a simple "first come, first served" fashion. Instead, they must assign ratings to events based on how much damage they will do to the firm, how sensitive the data is that was compromised, and how easily the data can be recovered.

Once an event has been assessed and prioritized, the team must notify the relevant parties. The exact reporting obligations should already be part of a well-thought-out team’s strategy.

3

Cont.

Strategies for containment, eradication, and recovery must be established utilizing criteria such as:

importance of the damaged property according to the nature and severity of the incidence, the importance of keeping proof, etc. That any compromised systems are significantly vital to key company processes what's required to put the plan into action Evidence should be obtained and documented at all times throughout these operations.

This serves two purposes:

one, to improve the security team's abilities in light of the assault

second, to provide the groundwork for any legal action that may be necessary in the event of an attack.

It is recommended to hold a lessons learned meeting with all relevant stakeholders following any incident, no matter how small, in order to improve security and incident management as a whole. Include as many people as possible from across the company and make an effort to invite those whose participation will be required during future situations. The meeting should focus on the following topics:

4

Cont.

who, what, where, when, whether or not the necessary protocols were followed, whether or not they were suitable, whether or not information was missing when it was needed, and how efficient the team was.

Explanations on why development slowed Where did we go wrong, and how can we prevent this from happening again?

To what extent is it possible to foretell the future, and what indicators should one be on the lookout for?

It's possible that the knowledge gained at such conferences might be quite useful in the process of indoctrinating new staff members.

They can be used to enhance current rules and processes and to develop institutional expertise, as well as to prevent similar accidents in the future.

5

Cyber Insurance Supports Cyber Incident Response

Unfortunately, incidents of cybercrime like data breaches are on the rise. If confidential information were compromised, it could damage your company's standing and put your customers and employees in danger. That's why businesses of all sizes would be wise to purchase cyber insurance.

Cyber liability insurance typically covers data breaches that expose personally identifiable information (PII) such as customer Social Security numbers, credit card numbers, bank account details, driver's license numbers, and medical records.

The process of filing a cyber insurance claim is based on best practices for responding to cyber incidents, and the claims are typically overseen by a third-party data privacy counsel.

This protects the privacy of attorney-client conversations and helps in making decisions. Legal fees for incident management, response, and forensic investigation services contracted by the data privacy attorney on the client's behalf are also covered.

Policyholders can often find consulting firm recommended by their cyber insurers to assist them in dealing with third parties like law enforcement, government agencies, and cybercriminals who demand ransom payments.

image1.png

image2.png

image3.png

image5.png