A Comprehensive Guide to Incident Response
A Comprehensive Guide to Incident Response
Building Effective Incident Response in Your Enterprise
Corporations today face an ongoing ambush of cybersecurity and data breach risks. In March 2024 alone, organizations in the U.S. saw over 4.277 billion known records breached. Globally, the number was 5.336 billion for that single month. One can only imagine what the numbers will be for the entire year.
In this data-risk climate, enterprises must act quickly to get ahead of the curve. Fortunately, there are well-developed incident response methods and technologies your organization can explore and adopt.
This guide provides background on risks to your organization’s data and discusses the essentials for building effective incident response strategies and incident response mechanisms.
What is Incident Response?
Incident response is an organization’s holistic approach to managing and mitigating cybersecurity risks and breach impacts. It encompasses preventing, identifying, and planning for intrusions that compromise an enterprise’s data. Incident response strategies include containing the intrusion, restoring operations, minimizing overall negative impacts on the business, and learning from each incident.
Why Incident Response Strategies are Needed
The threats to enterprise data security are many and varied. Let’s explore the types of incidents you may encounter, what malicious actors are after, and some important related terminology.
- Types of Attacks
- Ransomware: Malicious actors might try to gain access to take over your systems and force you to pay ransom to regain access. Such attacks are termed “ransomware” attacks.
- Social Engineering and Phishing: Cybercriminals fish for unsuspecting employees who may click on a link in an email that gives attackers access to your data. This attack is known as “phishing”. Similarly, social engineering attacks try employees to give a bad actor sensitive information, such as a password, by manipulating their behaviour.
- Malware: Malware is malicious software including viruses, ransomware, and trojans adversely affect and disrupt the operation of your networks and systems.
- Unauthorized Access Attempts: Repeated, failed login attempts and any unauthorized access attempts to critical systems are things your IT and InfoSecurity teams should monitor.
- DoS Attacks: Sometimes, bad actors flood a network with false online requests that confuse the system, causing it to crash. The result is that legitimate users can’t access systems like email, websites, or even a bank account. Thus, the name “denial of service” or DoS attacks.
- Data Breaches: Once a bad actor gains access to the data on your network, servers, or devices, you have a data breach. Sensitive company financial, customer, and personal information of all your employees may now be in the hands of a criminal. Also, a breach can give criminals access to intellectual property assets.
- Dark Web: Bad actors use these tactics to gain access to your data. There is an active, lucrative market for stolen data such as social security numbers, phone numbers, and addresses on the dark web. These hidden, unsearchable internet locations facilitate stolen data transactions in secrecy.
- Employee and Third Party Risks
- Insider Threats: Some of your organization’s biggest risks can be employees and business partners. A disgruntled employee might steal company data before they leave. The data could be used to embarrass your organization or valuable intellectual property stolen for use at their next job.Contractors, vendors, or business partners with access to your systems are also insiders who can pose risks to data security.
- Privacy & Regulatory Risks
- Privacy Regulations: If a data breach involves employees’ or customers’ personal information, you’ll have a privacy incident problem. The compromise of personal data stored on your systems will trigger obligations for your organization under global data privacy and data protection laws such as the European Union’s GDPR and a growing number of U.S. state privacy laws.
- Regulatory Compliance: Data breaches or incidents can also affect your status and compliance with other business regulations in general or those specified to your industry.
- Physical Security Risks
- Physical Assets: Incident response also involves managing the theft of physical assets like laptops and mobile phones that contain sensitive information.
- Facility Breaches: Unauthorized access to your organization’s facilities or vandalism are also incidents you’ll want to plan for.
The Incident Response Team
Now that you understand the types of incident response threats you face, let’s zero in on who you’ll want to help your enterprise develop an incident response plan. The incident response team will develop and implement a corporate incident response mechanism.
This dedicated team includes the right expertise and corporate responsibilities to ensure your organization effectively identifies incidents, mitigates damages and impacts, and helps the organization get up and running after an incident. You’ll want representatives from all key incident response stakeholders on the team.
- Enterprise IT
First, you’ll want a strong IT presence on your incident response team. Their expertise is crucial given that most threats stem from penetration of your network. IT teams (or InfoSec) are the ones who use technology to detect intrusions and monitor suspicious activity that can indicate you may have a breach. IT incident response stakeholders also manage the organization’s IT infrastructure and assets that bad actors target. - Information Security (InfoSec)Many large organizations have a dedicated information security team. Smaller organizations may rely primarily on IT for this function. If you have an InfoSec team, include them in your incident response team.These professionals stay on top of all known current cyber threats and remedies. They often take a point for intrusion monitoring, incident response assessment, and incident response strategies.
- In-house LegalThe general counsel’s office is a critical player in incident response. The law department should be part of the incident response team that gets the first rapid notice of an incident.Your company may face legal repercussions from the data breach or theft. The legal team will typically orchestrate the response from a legal and compliance perspective. If sensitive litigation or transaction information is compromised, the law department must act quickly to mitigate impacts on the legal portfolio.
- ComplianceYour organization’s compliance team is also one of the incident response stakeholders. Even though this team may report to the general counsel, you still want the compliance folks because they have important expertise on the regulatory reporting requirements you must meet when you incur a data breach.
- Corporate PR/Communications The compromise of business records, client data, intellectual property, and internal communications like email can ignite a firestorm of public relations and brand problems for your organization. Your PR team will play an important role in managing the impact of the incident on your brand. Assuring customers and the market that the organization is managing the intrusion and complying with all best practices will be priority number one to protect your reputation.If you are a publically traded company, the investor relations team will participate in incident response, often with guidance from legal. After a breach, swift action is necessary to inform investors and the marketplace to manage the effects on your company’s stock price.The internal communications team will coordinate with IT, legal, and executive incident response stakeholders to get appropriate communications to employees, executives, and the board of directors.
Incident Response Plan
A primary responsibility of your incident response team is to develop an incident response strategy and plan. You don’t want to be freewheeling in the chaos of a live data breach.
The team will create a plan that establishes exactly how the organization will respond to a data breach or a physical breach. They will document the incident response plan that describes in detail the protocols, procedures, and communication alerts to be executed in the event of an incident.
Critical Elements of an Incident Response Plan
- Intrusion Monitoring: Intrusion monitoring is fundamental to battling data risks. Your organization must acquire technology and tools for 24/7 monitoring and detecting intrusions and suspicious activity.
- Incident Classification: The plan should set out categories of breach incidents and the specific actions to take for each one.
- Incident Reporting: Provide clear instructions on how employees should inform a subset of the incident response team about a suspected threat or intrusion, and what information they should include. One incident response best practice is to have incident reports go to a group of people rather than one IT contact. This builds-in redundancy to ensure the report is seen and acted on immediately.
- Incident Notification List: Have a comprehensive list of incident response contacts, key employees, and executives who should be notified of incidents. Sort their need-to-know by incident categories. Assign a staff member responsibility for these notifications and backups when they are out of the office. Consider notification automation mentioned below.Keep the communications going – make sure the key people are informed and aware of the situation as it evolves.
- Document the Incident: Document the details of every incident – from a DoS to malware accidentally downloaded on an offline laptop. You’ll need details such as the location, date, and time of the intrusion, type of intrusion, etc.
You may need this information to report to the Board, regulators, or law enforcement. - Incident Response Measures: Establish incident response measures in your plan. Consider metrics such as time-to-verify intrusion, time-to-shut down an intrusion, time to identify affected data, timely regulatory filings, customer notices, etc.List all the data you must collect to allow you to measure your incident response mechanism against the metrics you select. Set up processes to preserve and collect this information. Automate as much of this process as you can.
- Broader Communications: The PR and Communications team should help the incident response team detail the procedures for public relations and any general communications to customers and employees in the plan.Legal or compliance teams must handle all legally mandated notices to customers and affected individuals.
- Regulatory Actions: Identify all the regulatory requirements your organization is subject to concerning data breaches and privacy in your plan. Summarize the key notification requirements your organization may have under:
- Global and State Privacy Laws
- Health Information Portability and Accountability Act (HIPAA)
- Securities and Exchange Commission (public companies)
- State and Federal licensing agencies
- State Departments of InsuranceAlso, identify any notices your cybersecurity or other insurance providers require. Your coverage may be affected by a failure to notify timely.
- Third-party Communications and Collaboration: Detail how and when you will inform vendors, contractors, and other third parties. Specify what categories of incidents require notifying law enforcement and cybersecurity experts and how your organization will collaborate during any investigations.
- Incident Response Assessments: After every incident, make sure you conduct a thorough incident response assessment. You’ll want to evaluate what worked, what didn’t work, and what can be improved. Go back and adjust your incident response strategies and incident response mechanisms based on your takeaways from the assessment.
Immediate Incident Response Steps
There’s been a report of a possible breach. What are the initial, urgent steps to take?
- Assess
a. Verify that an intrusion occurred.
b. If an intrusion is verified, determine the location, scope, and severity.
c. Identify what infrastructure, devices, and data types (financial, customer, personal, etc.) may have been compromised.
d. Classify the incident based on the severity levels established in the incident response plan.
e. Decide how to respond to the specific intrusion based on established protocols for that classification and situational analysis. - Contain
a. Stop the spread and continued operation of the virus or other incidents. Actions may include shutting down the affected systems and disconnecting them from the network.
b. Confiscate any affected devices – laptops, phones, tablets, desktops, etc.
c. In extreme situations, shutting down the entire system or even cutting off internet connectivity may be necessary to stop and contain the attack. - Restore
a. As much as possible, restore business systems so business operations can continue. Consult your business continuity plan.
b. However, see Dos and Don’ts below.
Dos and Don'ts of Incident Response
It’s imperative to preserve the digital evidence of an incident for legal analysis, cybersecurity investigations, regulatory audits, law enforcement actions, and any consumer or shareholder lawsuits that may arise. Here are a few Dos and Don’t for effective incident response.
- DO preserve evidence: It is important to preserve the digital evidence of an incident for investigations and any legal proceedings that may follow a breach.The digital footprint can help counsel, and investigators analyze:
- What data was accessed or stolen
- Whether regulated personal information was compromised.
- How the intrusion happened
- How many files were affected
- What customer data was compromised
- If the organization’s response was reasonable
- DON’T Restore Before Consulting Legal: IT must consult with legal before restoring network connectivity to affected devices or applications. Even with the pressure to restore business operations, there are evidentiary and other obligations a lawyer can help you think through.
- DO Image: Image all devices potentially affected by the incident to preserve the digital evidence on them.
- DON’T Wipe & Erase: If you decide to rebuild your IT infrastructure and devices from scratch after an attack, don’t wipe or erase data before you have imaged or preserved data per legal instructions.
- DO Notify Regulators & Affected Customers: Legal and compliance teams must act quickly to meet stringent, exacting regulatory notification requirements. It’s bad enough to go through a breach experience —you don’t want to compound things with noncompliance hearings and penalties.
- DON’T Assume: Don’t assume an agency or regulator doesn’t require breach notification or that the regulations never change.
- DO Update: Do a periodic thorough review and analysis of all potentially relevant laws and regulations. Update your incident response plan accordingly.
- DO Inform Insurance Carriers: Be sure to notify your providers for both business and cybersecurity insurance when you have a breach. Faillure to notify could affect your coverage.
- DO Educate: The incident response team must continually train and update the organization on the incident response plan. You will also want to conduct regular cybersecurity prevention and data privacy training for employees. Initial prevention and awareness training should be mandatory for all new hires.
- DON’T Make it “Their Job.”: Don’t perpetuate the idea that cybersecurity is only the job of the incident response team.
- DO Build a Shared Responsibility Culture: Build a culture of collective responsibility for cybersecurity prevention. Everybody should be alert to cyber risks. Build a culture where everyone feels responsible for protecting your organization, employees, and customer data.
- DO Contact Law Enforcement: Do enlist the help of law enforcement for severe incidents. The Federal Bureau of Investigation (FBI) may have resources and expertise to help you investigate the incident.
Game Changer Role of AI in Incident Response
Technology solutions for preventing and responding to cyberattacks have reached new levels. Artificial intelligence (AI) figures prominently in the new landscape. Your InfoSec and incident response team will want to explore how AI and other technology can assist your organization in managing these ever-growing risks.
- Intrusion Detection and Incident Response: You’ll want threat detection and incident response technology in your incident response mechanisms. Advanced systems have AI built in to aid security teams in assessing incidents and establishing the response workflow. Some even prioritize risks and remediate the biggest threats using automated response playbooks to keep infosec, IT, users, and other incident response stakeholders aligned during the chaos of an incident.AI and machine learning can rapidly analyze quantities of data to help security teams identify patterns, anomalies, and threats.
- Information Governance (IG): Incident response prevention includes using technology that helps you implement and monitor your organization’s information governance policies. GRC software gives you visibility and control over your data, to unify people, processes, and technology.AI features in IG solutions search and locate where you store data in various locations – the cloud, on-premise, on devices, and in document sharing and collaboration applications — so you can map the location of sensitive and regulated data. In the initial triage of an incident and later during investigations, the data map helps teams quickly locate sensitive data such as legal, health, IP, financial, and customer data.
- Blockchain: Blockchain technology facilitates highly secure, transparent information sharing in a myriad of transaction types. Blockchain use cases run the gamut from complex financial transactions and real estate deals to order tracking and accounts payable. The “blockchain” stores data in blocks linked together in a chain. The data in a blockchain is unalterable without consensus among the transaction parties. Blockchain data immutability, traceability, and encryption can enhance your organization’s intrusion protection and incident response.
- Hybrid Cloud and On-premise Solutions: When it comes to keeping your data safe, employing a balance of cloud and on-premise solutions is advisable.Storing your data in the cloud and using cloud-hosted solutions such as CRM, DMS, and eDiscovery can improve security and help you prevent breaches. The top cloud providers offer extremely secure data and have the latest information on known threats, taking the data off your local servers that bad actors may target.Many companies, however, prefer to use on-premise solutions to retain complete control over their data. With an effective IT team and cutting-edge infrastructure, you can often better safeguard your data.
Conclusion
Don’t wait to start your journey to improve incident response strategies and mechanisms. The intrusion threats are a reality for every organization.
Along the way, keep in mind the importance of
- establishing an incident response team with a cross-section of stakeholders your organization can rely on to plan and lead incident response efforts
- leveraging the role AI now plays in incident response, intrusion detection, and information governance technology
- adopt the best practices listed in this guide
- involve your entire organization in intrusion prevention
Knovos Assistant