Saturday, June 25 2022

Fundamentals of every CRP is the CRP life cycle. It is a series of stages that occur with steps needed to be taken in order to make sure every aspect of the cyber incident has been examined and documented. The tricky part comes in where companies need to assess their working nature and determine what aspects of the company are most valuable in order to create the most productive CRP. If you can predict where your company is most likely to be hit, you have more chances of defending against these types of attacks along with customizing a CRP to best suit the company’s environment. Following are the defined series of steps/stages that should be included in every CRP for cyber security:

1. Preparation is the first important stage in the process of responding to a cyber incident. Common sense tells you that there must be some sort of a security system in place in order to be able to identify an incident. In other words, a structure where adequate security staff, security mechanisms/tools and knowledge of the company’s resources is vital for any kind of successful response.

2. The first stage directly connects with the second stage which is identification. Having an adequate setup is paramount to the ability to identify that an incident has occurred. This is usually where alerts from intrusion detection systems come up, web filtering gateways detect a suspicious external connection, SIEM solutions connect the dots of an attacker passing through the internal network or an endpoint solution alerting of a phishing email opened. No matter the case, quick reaction from qualified security staff is needed in order to escalate and respond to the alerts.

3. Containment is the third stage of the CRP life cycle. In order to stop further spreading of malware and damage to the network and data theft, containment of the threat actors is what is needed in order to focus on the next stage of the incident response. A good example in practice would be a complete network containment of the infected machine which means cutting all internet and intranet connections of the machine.

4. Eradication is one of the more complex stages in the incident process as it involves forensic analysis in order to determine the extent of presence of the threat actor. Security staff need to make sure that what they do in the eradication stage eliminates all presence and access of the threat actor to the system. This includes, re-imaging of machines, searching for backdoors, and most importantly, determining the root cause analysis if the incident. Depending on the root cause, eradication stage can be simplified by knowing the vector of attack that took place.

5. Recovery stage comes right after eradication. In this stage, getting the infected systems up and running again is important to decrease any potential monetary loss associated with the downtime of the infected system. In some cases, a single computer infected with a virus is not going to bring down the company, but an office with 100 employees whose computers fell victim to ransomware is a whole other story. In the later case, quick action from the security team will determine how big the loss of revenue will be.

As previously stated, lessons learned is one of the most important stages for a simple fact that it will showcase to everybody how the incident occurred and how to effectively close the attack vector that got exploited. Closing unnecessary open ports and services, implementing dual factor authentication, limiting exposure of internal resources and increasing the segmentation of the network are just some of the things that could be done in order to close the gaps.

Cyber Security Response Plan
Previous

Free preview of the 92nd Academy Award ceremonies on websites? Beware

Next

Cyber attacks in 2020: how they will affect you and how to prevent them.

Check Also

Widget

Don’t Miss

Firmware Supply Chain Company Binarly Raises $3.6 Million

SecureDisruptions

Binarly Inc., a cybersecurity company building technology to address repeatable security failures in the firmware supply chain, today announced $3.6 million in seed funding from WestWave Capital and Acrobator Ventures. Prominent cybersecurity leaders Michael Sutton, Thomas ‘Halvar Flake’ Dullien, Jamie Butler, Ryan Permeh, Bryson Bort, Pedram Amini, Chris Ueland and David Mandel from Emerging Ventures […]

Allied Universal Acquires Three Companies

SecureDisruptions

Allied Universal®, the leading security and facility services company, is continuing its global expansion with the acquisition of three companies located in New York, the Netherlands and Denmark. The largest of the three companies, International Protective Service Agency, is headquartered in New York, NY, and provides comprehensive security and event services for clients located throughout New York and New Jersey. IPSA founder and owner Jerry […]

SEMPRE.ai ACQUIRES NEWSPACE NETWORKS

SecureDisruptions

SEMPRE.ai, the technology company created to secure America’s critical infrastructure, announced the acquisition of NewSpace Networks to further safeguard and expand the availability of terrestrial, maritime, airborne and space-based wireless communications. Integration of the two companies’ technologies has been underway for more than a year, with the first commercial products having been tested domestically with the U.S. Department of […]

Quickpass Cybersecurity Secures $7M in Series A Funding Round

SecureDisruptions

Quickpass Cybersecurity, a leading provider of Privileged Access Management and Helpdesk Security Automation for MSPs (Managed Service Providers), announced a new $3 million round of financing in partnership with Arthur Ventures. This completes their Series A round of financing, totaling $7 million. This round of funding will enable Quickpass to accelerate the company’s efforts to […]

GreyNoise Raises $15 Million in Series A Funding

SecureDisruptions

GreyNoise Intelligence, the cyber security company analyzing internet scanning traffic to separate threats from background noise, today announced that it has raised a $15 Million round of Series A funding led by Radian Capital. With participation from CRV, Inner Loop, Stone Mill Ventures and Paladin Capital, this brings the total of funding raised to date to […]

Immuta Raises $100 Million in Series E Funding

SecureDisruptions

Immuta, the leader in data access and data security, today announced that it has secured $100 million in Series E funding. With this investment, Immuta will meet growing data security and privacy demands by accelerating secure data access across all cloud platforms. Only Immuta can automate access to data by discovering, securing, and monitoring data […]