BreachExchange mailing list archives
7 Tips to Bring Order to the Chaos of a Breach
From: Audrey McNeil <audrey () riskbasedsecurity com>
Date: Tue, 12 May 2015 19:53:25 -0600
http://risnews.edgl.com/retail-news/7-Tips-to-Bring-Order-to-the-Chaos-of-a-Breach-100037 Without an executive response plan, any incident can go from bad to worse very quickly, including losing the trust and confidence of your customers, partners, and shareholders. It is not simply about detecting an event and then trying to interpret what happened from limited information; it is about taking immediate action and engaging the attack directly regardless of where it occurs. It takes executive leadership to make sure the resources and plans are in place to execute well. It is necessary for organizations to proactively establish the processes and procedures for an optimal end-to-end approach to breach management. Gaining swift visibility into the incident, you can respond confidently to the marketplace and your constituents in a way that maintains trust. At a high level, there are four stages to the incident management program: Stage 1 Contain breach, initial assessment Stage 2 Evaluate seriousness/risk level/potential prejudice the breach represents Stage 3 Consider notifications, and implement if appropriate, mitigate risk Stage 4 Remedial steps taken to prevent future breaches While most organizations have specific organizational readiness plans for different types of incidents, executives are likely more familiar with the differences between disaster recovery and business continuity plans, than the subtle nuances between security incident response, crisis communication, and incident notification. Here are seven best practices we have found based on working on a number of strategic incident response plans: 1. Keep it simple: Structure key messages on the types of incident processes and key concepts that exist within your incident management program 2. Awareness is key: Develop an education plan for all levels of management to identify and differentiate the common components included within incident management processes. Create the elevator pitch and succinct definition of the key components in your incident management approach so that all levels of management can describe in simple statements what processes exist. 3. Use a lifecycle approach: Effective incident management is based on an incident lifecycle and requires integration between multiple processes. A common misperception is that incident response is a straightforward and sequential process. The reality is that privacy and security incident management requires three dimensional thinking and close coordination and communication between all participants in each process. 4. Conduct lessons learned events: Most organizations conduct periodic tabletop or testing of their incident response plans. However, sometimes the best learning is by experience. Either from real-life incidents, or taking examples that went well and doing the “what if?” comparison if things had gone differently. By practicing or discussing the linkages between plans, helps you mature your incident management processes throughout the incident lifecycle. 5. Not all assets are created equal: Focus on your crown jewels – know where your biggest risks are, and focus your planning on the scenarios that could have the biggest impact. 6. Follow your data – know where your data is, and who is accountable for security, operations, and management 7. Do not forget about social media – PR and communications team need to be involved in planning and simulation exercises. With the pace at which news goes public, integrate communications into your test planning so process and lines of communication of already in place before events occur. Your response determines success or failure The difference between success and failure is determined by how your organization responds—its ability to identify what happened and why; to rapidly respond and stop the attack; and to communicate with stakeholders. It is important to be agile while responding to an event/incident. Survival depends on how effective you were at planning the response whether it is a natural disaster or a security breach. With so many retail breaches that have occurred this year, your organization could be next. News of data breaches have become commonplace. We hear so much about data loss, that at times it might seem ordinary —that is, until it happens to your organization. No organization is immune. Regardless of how breaches occur, preventative measures offer no guarantees. No matter how advanced the security technology is or extensive the resources are the threat still remains. Breaches can also be costly events when you factor in losses such as lost business, fines and litigation costs, lost shareholder value, and damage to your reputation. The single largest cost component is the loss of business from a tarnished reputation. What distinguishes one breach from another is the post-breach response. Like a fire drill, being prepared makes the difference. When a security breach hits, you need a response strategy that immediately curtails damage and prevents further jeopardy to your sensitive data.
_______________________________________________ Dataloss Mailing List (dataloss () datalossdb org) Archived at http://seclists.org/dataloss/ Unsubscribe at http://lists.osvdb.org/mailman/listinfo/dataloss For inquiries regarding use or licensing of data, e-mail sales () riskbasedsecurity com Supporters: Risk Based Security (http://www.riskbasedsecurity.com/) YourCISO is an affordable SaaS solution that provides a comprehensive information security program that ensures focus on the right security. If you need security help or want to provide real risk reduction for your clients contact us!
Current thread:
- 7 Tips to Bring Order to the Chaos of a Breach Audrey McNeil (May 19)
