The Cost of Improvising During an Incident
Organizations that experience a significant security incident without an incident response plan consistently report chaotic, poorly-coordinated responses that extend dwell time, increase damage, complicate forensics, and create additional regulatory exposure. The decisions that need to be made in the first hours of a breach are far harder to make well under pressure without a pre-established framework.
Incident Response Plan
An incident response plan (IRP) documents who does what when a security incident occurs. At minimum, it should address:
- Definition of what constitutes a security incident requiring plan activation
- Incident response team composition and contact information
- Escalation and notification procedures — who gets called, in what order, at what thresholds
- Evidence preservation and forensic chain of custody procedures
- Containment, eradication, and recovery procedures for common incident types (ransomware, data breach, account compromise)
- External communication and public relations procedures
- Regulatory and legal notification obligations — breach notification timelines vary by jurisdiction and industry
Retain a Security Incident Response Firm Before You Need One
Trying to hire a forensic incident response firm in the middle of an active breach is difficult and expensive. Retaining an IR firm in advance gives you a pre-negotiated agreement, a team that already understands your environment, and immediate availability when you need them.
Logging and Detection
You cannot respond to what you cannot see. Before an incident, ensure you have comprehensive logging in place — Windows event logs, firewall logs, DNS logs, authentication logs, and endpoint detection and response (EDR) coverage where possible. Logs should be centralized in a SIEM and retained for a sufficient period (90 days minimum; 12 months for regulated environments).
Backup and Recovery
Ransomware is the most common severe incident type affecting mid-market organizations. Effective, tested, offline backup — following the 3-2-1 rule (three copies, two media types, one offsite/offline) — is the single most important control for recovering from ransomware without paying a ransom. Test your backups regularly; untested backups frequently fail when needed.
Are you prepared for an incident?
A penetration test reveals your vulnerabilities before an attacker does. Contact Grid32 to discuss testing and incident preparedness.
Get a Quote →