One: preparation
-
Sit down with the security/IT team
-
List who to inform in case of an incident
-
Write down contact details for anyone who may help you in case of an incident
-
Write down chain of command during incident handling
-
Confirm those handling incidents have the required management approval and budget
Two: identification
-
For larger organizations: run IDS/IPS and SIEM to receive alerts of possible incidents
-
Run centrally managed endpoint security (or consider an MSSP)
-
If applicable, make use of monitoring function of Google Workspace or Office 365
-
Use tools and create a culture to make it easy for staff to report possible incidents
-
Make sure you are approachable for outsiders to report a possible incident
-
Check if there is a legal requirement to report the incident to a regulator
Three: containment
-
Disconnect infected devices from the network
-
Remove access to, and change passwords of, compromised accounts
-
Take forensic images and save logs for further investigation
-
Apply temporary fixes for business continuity
Four: eradication
-
Remove malware from infected devices
-
Remove maliciously created accounts
-
Rebuild infected machines if deemed necessary
Five: recovery
-
Bring affected systems back online
-
Test affected systems and accounts and monitor their activity
-
Provide psychological support for affected staff members
Six: learning
-
What worked and what didn’t? Where did you get lucky?
-
Complete documentation of the incident and its handling
-
Sit down with the security/IT team and update incident response plan where needed