Digital Risk & Security Institute DRSI
Department of Information Security Cybersecurity
& Digital Risk Division
INCIDENT RESPONSE PLAN
Platform: Twitter (X)
Focus: Cybersecurity Incident Management
Framework: Based on NIST SP 800-61 Rev. 2
Prepared by:
Emmanuel Felix
God'slife
Christ'sfullness
Ani Nnamdi
Daniel
Osabuohien
Precious Uzor
Christian
Date: August 2025
1
INTRODUCTION
In today's interconnected digital landscape, cybersecurity incidents pose
substantial threats to organizations' operations, data integrity, and overall
security posture. Effective management of these incidents is crucial for
minimizing damage, reducing downtime, and ensuring swift recovery. The
National Institute of Standards and Technology (NIST) provide guidelines
for handling cybersecurity incidents through its Special Publication (SP) 800-
61 Rev. 2, Computer Security Incident Handling Guide. This publication
outlines a structured approach to incident response, emphasizing
preparation, detection and analysis, containment, eradication, recovery, and
post-incident activities.
FOCUS OF THE PROJECT
The focus of this project is to explore and apply the guidelines from NIST SP
800-61 Rev. 2 for effective cybersecurity incident management. Specifically,
the project will delve into:
- Incident Response Lifecycle: Understanding and implementing the four
phases of incident response as outlined in NIST SP 800-61 Rev. 2.
- Application of Guidelines: Applying the technology-agnostic guidelines
2
to manage cybersecurity incidents in a manner that minimizes impact
and enhances organizational resilience.
GOALS OF THE PROJECT
The goals of this project are to:
1. Understand Incident Management Principles: Gain a
comprehensive understanding of cybersecurity incident
management principles based on NIST SP 800-61 Rev. 2.
2. Apply Incident Response Guidelines: Apply the incident
response lifecycle to effectively manage cybersecurity incidents.
3. Enhance Organizational Resilience: Contribute to enhancing
an organization's resilience against cybersecurity threats through
effective incident management practices.
CONTEXT AND RELEVANCE
Cybersecurity incident management is a critical component of an
organization's overall cybersecurity strategy. By following established
guidelines like those in NIST SP 800-61 Rev. 2, organizations can improve
their ability to handle incidents, thereby protecting their assets and reducing
risks.
3
2. Main Content
1. Preparation
1.1. Incident Response Policy
Develop and enforce a comprehensive incident response policy emphasizing:
Protection of user data and platform integrity
Compliance with global regulatory bodies (e.g., GDPR, SEC, NDPR)
Executive-level support for rapid escalation and decision-making
1.2. Incident Response Team (IRT)
Establish a 24/7 Computer Security Incident Response Team (CSIRT) with
defined roles:
Role Responsibility
Incident Commander Leads coordination and
decision-making
Security Analysts Perform technical triage,
forensics, and remediation
IT Operations Assist with containment
and system-level access
Legal/Compliance Ensure regulatory
compliance and
4
documentation
Communications/PR Handle internal/external
updates, including
@TwitterSupport
HR/People Ops Support insider threat
investigations if applicable
Backup personnel must be assigned for shift-based coverage
1.3. Security Infrastructure
Deploy and configure essential tools:
SIEM platforms (e.g., Splunk, Sentinel)
Endpoint Detection and Response (EDR)
Multi-Factor Authentication (MFA/2FA)
Role-based Access Controls (RBAC)
Admin tool access logging and restrictions
Designate hardened, isolated workstations for social account access.
1.4. Training and Simulations
Conduct quarterly phishing simulations and social engineering tests
5
Run tabletop incident response exercises using past scenarios
Provide targeted security awareness training for high-risk users
1.5. Communication Protocols
Pre-approve notification templates for user alerts, regulatory
disclosures, and public statements
Establish secure, out-of-band channels for internal coordination
during breaches
Maintain contact lists for regulators, third-party vendors, and law
enforcement
2. Identification
2.1. Monitoring and Detection
Continuously monitor using SIEM and anomaly detection systems
Watch for Indicators of Compromise (IOCs) such as unusual login
times, IP mismatches, or mass DMs
Integrate threat intelligence feeds for proactive identification
2.2. Triage and Verification
Initiate incident triage through the Security Operations Centre (SOC)
Cross-reference alerts with logs and threat Intel
6
2.3. Scoping the Incident
Identify impacted assets:
Accounts (especially verified or high-following)
Internal tools or admin dashboards
Data repositories (e.g., DMs, emails, API usage)
Evaluate potential lateral movement and privilege escalation
3. Containment
3.1. Short-Term Containment
Temporarily suspend affected accounts or admin tools
Disable sensitive functions (e.g., tweeting, password resets)
Block malicious IPs and command/control (C2) traffic
3.2. Long-Term Containment
Revoke access to compromised credentials or developer tokens
Implement segmented network access for internal tools
Strengthen MFA enforcement and session timeout configurations
3.3. Evidence Preservation
Snapshot systems, logs, and artifacts for forensic analysis
7
Avoid system reboots or file deletions unless cleared by forensic
analysts
4. Eradication
4.1. Root Cause Analysis
Determine exploit path (e.g., phishing, insider threat, 0-day)
4.2. System Hardening
Patch known vulnerabilities and misconfigurations
Audit and tighten access control lists (ACLs)
Review OAuth apps and integrations for compromise
4.3. Credential and API Key Reset
Rotate credentials for affected accounts
Enforce post-incident MFA setup
Reset access tokens for third-party applications
5. Recovery
5.1. Restoration
Restore services in phases, starting with unaffected user groups
Use clean backups and validated configurations
8
Monitor closely for recurring or delayed threats
5.2. Communication
Publish incident updates via official handles
(@TwitterSupport/@XSupport)
Clearly communicate recovery steps to users
5.3. Regulatory Notifications
Report to SEC, EU DPA, NYDFS, or other applicable regulators
Log all disclosures with timestamps and content for audit
6. Lessons Learned
6.1. Incident Review
Conduct a post-incident “blameless” retrospective with all
stakeholders
Document findings in the IRP Improvement Log
9
6.2. Plan Update
Revise the IRP to reflect new risks and operational changes
6.3. Threat Intelligence Integration
Update IOCs, TTPs, and playbooks based on the incident
Share findings with industry partners via ISACs or CERTs
10
7. Twitter-Specific Risk Considerations
Category Risk Response
Strategy
Verified Accounts High-value social Limit admin tool
engineering targets access, enable MFA,
monitor anomalies
Public Perception Brand damage during Use pre-drafted PR
downtime messages, be
transparent
Crypto Account Abuse Regulatory and financial Escalate
implications immediately,
coordinate with
NYDFS/SEC
Third-Party Services OAuth apps, integrations Vet and restrict
integrations, audit
regularly
Internal Tool Abuse Insider risk or weak Audit access,
controls implement Just-In-
Time provisioning
11
8. Annexes
Annex A: Severity Classification Matrix
Low Minor disruption, no Spam tweet from low-
data loss risk account
Medium Limited impact, no Unauthorized access to a
sensitive data tool
High User data compromised, Verified account takeover
regulatory risk
Critical Major breach, platform- Social engineering breach
wide impact of admin tools
Annex B: Pre-approved Public Communications
Initial Statement:
“We are aware of a security incident affecting a subset of user accounts. Our security
team is actively investigating and taking measures to address the issue. We will
provide timely updates here.”
12
Follow-up Statement:
“The issue has been identified and contained. Impacted users will receive
notifications with recovery steps. We thank you for your patience and
understanding.”
Annex C: Regulatory Disclosure Checklist
☑ Notify the Data Protection Authority (EU DPA, NDPR, etc.)
☑ File a report with the U.S. SEC if applicable
☑ Submit breach notification to affected users
☑ Document all disclosure events with timestamps and recipients
13