BreachExchange mailing list archives

7 Tips to Bring Order to the Chaos of a Breach


From: Audrey McNeil <audrey () riskbasedsecurity com>
Date: Tue, 12 May 2015 19:53:25 -0600

http://risnews.edgl.com/retail-news/7-Tips-to-Bring-Order-to-the-Chaos-of-a-Breach-100037


Without an executive response plan, any incident can go from bad to worse
very quickly, including losing the trust and confidence of your customers,
partners, and shareholders. It is not simply about detecting an event and
then trying to interpret what happened from limited information; it is
about taking immediate action and engaging the attack directly regardless
of where it occurs.

It takes executive leadership to make sure the resources and plans are in
place to execute well. It is necessary for organizations to proactively
establish the processes and procedures for an optimal end-to-end approach
to breach management. Gaining swift visibility into the incident, you can
respond confidently to the marketplace and your constituents in a way that
maintains trust.

At a high level, there are four stages to the incident management program:

 Stage 1 Contain breach, initial assessment
 Stage 2  Evaluate seriousness/risk level/potential prejudice the breach
represents
 Stage 3  Consider notifications, and implement if appropriate, mitigate
risk
 Stage 4  Remedial steps taken to prevent future breaches

While most organizations have specific organizational readiness plans for
different types of incidents, executives are likely more familiar with the
differences between disaster recovery and business continuity plans, than
the subtle nuances between security incident response, crisis
communication, and incident notification. Here are seven best practices we
have found based on working on a number of strategic incident response
plans:

1.     Keep it simple: Structure key messages on the types of incident
processes and key concepts that exist within your incident management
program

2.     Awareness is key: Develop an education plan for all levels of
management to identify and differentiate the common components included
within incident management processes. Create the elevator pitch and
succinct definition of the key components in your incident management
approach so that all levels of management can describe in simple statements
what processes exist.

3.     Use a lifecycle approach: Effective incident management is based on
an incident lifecycle and requires integration between multiple processes.
A common misperception is that incident response is a straightforward and
sequential process. The reality is that privacy and security incident
management requires three dimensional thinking and close coordination and
communication between all participants in each process.

4.     Conduct lessons learned events: Most organizations conduct periodic
tabletop or testing of their incident response plans. However, sometimes
the best learning is by experience. Either from real-life incidents, or
taking examples that went well and doing the “what if?” comparison if
things had gone differently. By practicing or discussing the linkages
between plans, helps you mature your incident management processes
throughout the incident lifecycle.

5.     Not all assets are created equal: Focus on your crown jewels – know
where your biggest risks are, and focus your planning on the scenarios that
could have the biggest impact.

6.     Follow your data – know where your data is, and who is accountable
for security, operations, and management

7.     Do not forget about social media – PR and communications team need
to be involved in planning and simulation exercises. With the pace at which
news goes public, integrate communications into your test planning so
process and lines of communication of already in place before events occur.

Your response determines success or failure
The difference between success and failure is determined by how your
organization responds—its ability to identify what happened and why; to
rapidly respond and stop the attack; and to communicate with stakeholders.

It is important to be agile while responding to an event/incident.
Survival depends on how effective you were at planning the response whether
it is a natural disaster or a security breach. With so many retail breaches
that have occurred this year, your organization could be next.  News of
data breaches have become commonplace.  We hear so much about data loss,
that at times it might seem ordinary —that is, until it happens to your
organization.

No organization is immune.  Regardless of how breaches occur, preventative
measures offer no guarantees. No matter how advanced the security
technology is or extensive the resources are the threat still remains.
Breaches can also be costly events when you factor in losses such as lost
business, fines and litigation costs, lost shareholder value, and damage to
your reputation.  The single largest cost component is the loss of business
from a tarnished reputation. What distinguishes one breach from another is
the post-breach response.

Like a fire drill, being prepared makes the difference.  When a security
breach hits, you need a response strategy that immediately curtails damage
and prevents further jeopardy to your sensitive data.
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://lists.osvdb.org/mailman/listinfo/dataloss
For inquiries regarding use or licensing of data, e-mail
        sales () riskbasedsecurity com 

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
YourCISO is an affordable SaaS solution that provides a comprehensive information security program that ensures focus 
on the right security.  If you need security help or want to provide real risk reduction for your clients contact us!

Current thread: