Jump to content

Recommended Posts

Posted

To save me re-inventing the wheel and also save a huge amount of time, does anyone have some examples of a cyber incident response plan they would be willing to share?

 

Many thanks

Posted

I spent the first 3 months of the year working on an IR plan. Phases are.

 

Prepare

 

Detect

 

Contain

 

Eradicate

 

Recover

 

You need leadership buy in and your leadership to give you a list of priorities. E.G

Phones

E-Mail

MIS

 

Then you need to draw up a list of dependencies.

 

E.G

Internet Access

HyperVisor

 

This is just for the containment phase.

 

You have to think about containing ransomware if you can. Having some firewall rules that block all traffic in case you need to. Ideally having all you internal traffic flow through a firewall is best so you can isolate subnets/VLANs.

 

You will need the authority to make the split second decisions to prevent a complete loss.

E.G cut all internet access

 

Each environment is different however.

It’s probably best to audit all your services and what they require to function. You can then work out what can be isolated if need be.

 

Of course you have to work out how your leadership will handle communication internally and externally so it is a whole organisation process.

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...