Cyber Security Incident Response Planning (CSIRP): Minimizing Business Impact And Being Prepared

Enterprise Investment In Incident Response And Containment Climbing

Add bookmark
Incident Response

Security practitioners live in a world of hacker sophistication – including automated reconnaissance and payload efforts. These same professionals are often charged with defending the network with the same or comparable resources as years past.

Giving her assessment of the space, Security Executive and Information Systems Security Association (ISSA) Member, Candy Alexander, said, “Responding to an incident has become commonplace. IT and security teams used to have to exercise their IRPs, but today, they exercise them for real.”

Security practitioner Keith Hollender, formerly the Vice President of Information Security at Synchrony Financial, piggybacked off that sentiment, saying: “Incident response has become more of a focus in the industry. The mindset has shifted from ‘not if, but when’ we will deal with a major incident.”

The security professional said that incident response platforms and cyber fusion centers are now focused on minimizing impact and being prepared. Comparatively, he said that just a few years ago, only select, large companies had IR teams – and the capabilities were limited.

“Today, more and more companies are investing in incident response and containing an incident once it occurs,” Hollender said. At the enterprise level, continued cyber-spend means more awareness around cyber-threats, but it does not always equate to scores of security staffers holed up at the data center searching for indicators of compromise (IoC).

Instead, oftentimes it comes down to the same number of analysts to identify, verify and contain threats. The challenges behind this structure will be touched upon in this report, but it’s certainly worth noting in a section documenting a CSIRP background. For folks entrenched in the SOC, proper security information and event management (SIEM) software, and tactics, are the best weapon against threat actors.

See Related: Market Report - A Centralized Point Of View: SIEM For Better Efficiency And Compliance

A Technical Touch

It bears repeating that successful CSIRPs – which involve threat intelligence, forensic analysis, post-breach containment controls, etc. – are both established and repeatable. But successful incident management also revolves around a few technical components.

For one, analysts are always on the lookout for IoCs, which ultimately need triaging and individual attention. While that can get lost in a queue with busy analysts, there are certain methods that allow for streamlined attention and care.

Numerous enterprises today employ threat intelligence platforms – many of which are sophisticated tools that overlay the “requisite” security functionalities – and these tools feed security teams with scores of notifications.

See Related: Cyber Security Hub Digital Summit Prepares InfoSec Leaders For Resiliency

Of course, in an age of automation, early-stage machine learning may provide a high number of false positives (pulling security teams away from potentially devastating incidents, elsewhere). But they may also delve so far into numerical detail that they offer CISOs and the like actionable intelligence. Some of which can be active threats, others might be vulnerabilities, aka “open windows.”

Elsewhere, useful intelligence may come from third parties or internal audits. Nevertheless, an IoC could pull an analyst in for a ride – from detection, to (data-based verification) to containment.

IR Challenges And Best Practices

No matter the technical acumen of the security teams, sometimes adequate incident response comes down to sustainability and executive decisions of the wider business. Read the full market report “Diagnosing Disaster: How To Recover From An Attack” to learn about the notable IR challenges, best practices and the outlook for automating CSIRP.

See Related: Cyber Security Hub Market Reports Archive


info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":0,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[],"featured_content_portal_embedded":null}" >