Monday, September 20 2021

Fundamentals of every CRP is the CRP life cycle. It is a series of stages that occur with steps needed to be taken in order to make sure every aspect of the cyber incident has been examined and documented. The tricky part comes in where companies need to assess their working nature and determine what aspects of the company are most valuable in order to create the most productive CRP. If you can predict where your company is most likely to be hit, you have more chances of defending against these types of attacks along with customizing a CRP to best suit the company’s environment. Following are the defined series of steps/stages that should be included in every CRP for cyber security:

1. Preparation is the first important stage in the process of responding to a cyber incident. Common sense tells you that there must be some sort of a security system in place in order to be able to identify an incident. In other words, a structure where adequate security staff, security mechanisms/tools and knowledge of the company’s resources is vital for any kind of successful response.

2. The first stage directly connects with the second stage which is identification. Having an adequate setup is paramount to the ability to identify that an incident has occurred. This is usually where alerts from intrusion detection systems come up, web filtering gateways detect a suspicious external connection, SIEM solutions connect the dots of an attacker passing through the internal network or an endpoint solution alerting of a phishing email opened. No matter the case, quick reaction from qualified security staff is needed in order to escalate and respond to the alerts.

3. Containment is the third stage of the CRP life cycle. In order to stop further spreading of malware and damage to the network and data theft, containment of the threat actors is what is needed in order to focus on the next stage of the incident response. A good example in practice would be a complete network containment of the infected machine which means cutting all internet and intranet connections of the machine.

4. Eradication is one of the more complex stages in the incident process as it involves forensic analysis in order to determine the extent of presence of the threat actor. Security staff need to make sure that what they do in the eradication stage eliminates all presence and access of the threat actor to the system. This includes, re-imaging of machines, searching for backdoors, and most importantly, determining the root cause analysis if the incident. Depending on the root cause, eradication stage can be simplified by knowing the vector of attack that took place.

5. Recovery stage comes right after eradication. In this stage, getting the infected systems up and running again is important to decrease any potential monetary loss associated with the downtime of the infected system. In some cases, a single computer infected with a virus is not going to bring down the company, but an office with 100 employees whose computers fell victim to ransomware is a whole other story. In the later case, quick action from the security team will determine how big the loss of revenue will be.

As previously stated, lessons learned is one of the most important stages for a simple fact that it will showcase to everybody how the incident occurred and how to effectively close the attack vector that got exploited. Closing unnecessary open ports and services, implementing dual factor authentication, limiting exposure of internal resources and increasing the segmentation of the network are just some of the things that could be done in order to close the gaps.

Cyber Security Response Plan
Previous

Free preview of the 92nd Academy Award ceremonies on websites? Beware

Next

Cyber attacks in 2020: how they will affect you and how to prevent them.

Check Also

Widget

Don’t Miss

Cyber Deal Update: Upstream Security, Hunters, build.security

Khushi Arora

Upstream Security and Hunters complete Series C and Series A funding rounds, respectively. Elastic NV acquires build.security. Funding Upstream Security, an Israeli provider of automotive cybersecurity and a data analytics platform for connected vehicles, has closed a $62 million Series C funding round led by Mitsui Sumitomo Insurance, along with new investors I.D.I. Insurance, NextGen […]

Cyber Deal Update: Loop Secure, Intelligent Automation, Blumira

Khushi Arora

Tesserent acquires Loop Secure to complement its own services, and BlueHalo merges with Intelligent Automation. Blumira completes a Series A funding round. Mergers and Acquisitions Tesserent, an Australian network security company, has announced its intent to acquire Loop Secure, a provider of managed security services, governance risk and compliance, and offensive security services also based […]

Cyber Deal Update: FHIRBlocks, InfoSum

Khushi Arora

Healthcare cybersecurity company ConsenSys Health acquires FHIRBlocks. InfoSum and Monte Carlo close a Series B and Series C funding round, respectively. Mergers and Acquisitions Otava, a Michigan-headquartered cloud solutions provider, has announced its acquisition of NewCloud Networks, a Colorado-based cloud computing services provider. The acquisition provides Otava a product portfolio that includes security services, cloud […]

Cyber Deal Update: Carve Systems, Baffle, Certik

Khushi Arora

iVision acquires Carve Systems, Baffle closes a Series B funding round, and CertiK closes adds to its Series B funding round announced last month. Mergers and Acquisitions iVision, a Georgia-based provider of IT infrastructure and application solutions, has acquired Carve Systems, a New York-based cybersecurity company that provides security testing, security engineering, and security strategy […]

Cyber Executive Moves: Aegon Asset Management, Tego Cyber

Khushi Arora

Aegon Asset Management hires former COO of MN and Tego Cyber gains a new CISO. Aegon Asset Management, based in The Netherlands, has appointed Nicole Grootveld-Sandig as its chief technology officer. Grootveld-Sandig joins Aegon from the Dutch specialist pensions management company MN NV. Tego Cyber, a Nevada-based developer of cyber threat intelligence solutions, has hired […]

Cyber Deal Update: Appriss Insights, Espagon

Khushi Arora

Equifast acquires data analytics company Appriss Insights, while Cisco acquires observability provider Espagon. Mergers and Acquisitions Equifax, an Atlanta-based global data, analytics and technology company, has announced its acquisition of Appriss Insights, a Kentucky-based information technology company providing customized solutions to enhance security and financial processes for businesses, for $1.825 billion. “We are extending the […]