Data Loss Incident Response Playbook
Data Loss Incident Response Playbook
1.2. Purpose
The purpose of the Cyber Incident Response: Data Loss Playbook is to define activities that should be considered when detecting, analysing and
remediating a Data Loss incident. The playbook also identifies the key stakeholders that may be required to undertake these specific activities.
Scope
This document has been designed for the sole use of the first responders such as the Service Desk team when responding to a cyber-incidents.
It is not standalone and must be used alongside your CIRP.
There are similar play books available as part of this project including but not limited to: Phishing, Malware and Ransomware. The appropriate
playbook should be used for the appropriate incident type.
Review recent cyber incidents and the outputs. • Information Security Manager
Identify and obtain the services of a 3rd party Cyber Forensic • Information Security Manager
provider.
Define Threat and Risk Indicators and Alerting pattern within the
organisation’s security information and event management (SIEM) • Information Security Manager
solution.
Where linked to extortion demand and ransomware attack pre • Information Security Manager
define general parameters of a Data Leak and Recovery Plan • Senior/ Gold Command Team
Conduct exercising against this scenario at Tactical, Operational • Conduct exercising against this scenario at Tactical,
and Strategic levels. Consider use of the NCSC Exercise in a Box Operational and Strategic levels. Consider use of the
Toolkit and or access to NCSC Exercising Assured Service NCSC Exercise in a Box Toolkit and or access to
NCSC Exercising Assured Service
3. Detect
Detection Phase
Monitor detection channels, both automatic and manual, customer and staff
channels and social media for indications of a Data Breach or compromise, these
can include but are not limited to:
• Customers, employee or confidential data published online;
• Clients or their customers being contacted by an unauthorised third party with
access to personal or confidential information; • Information Security Manager
• Targeted emails to clients or employees containing personal or confidential • Core IT CIRT
information;
• Data loss prevention logs or alerts;
Detect and report • Lost or stolen devices containing confidential information;
the incident • Lost or stolen paperwork or hardcopies of data;
• Other incidents that suggest data has been extracted outside of the network
perimeter.
Report the cyber incidents via the Service Desk. If a ticket does not exist already,
raise a ticket containing minimum information. • Information Security Manager
To report an incident, follow the process defined in the CIRP (Insert link to CIRP • Core IT CIRT
here).
Classify the cyber incidents, based upon available information related to the Data • Information Security Manager#
Loss and the incident types (see CIRP). • Core IT CIRT
Secure artefacts, including copies of the data, via secure download and • Information Security Manager
screenshot. • Core IT CIRT
Review critical systems and assess for any indicators of similar data sets being • Information Security Manager
compromised. • Core IT CIRT
Preliminary review of data involved to determine if personal data has been • Information Security Manager
compromised. • Core IT CIRT
Research Threat Intelligence sources and consider Cyber Security Information • Information Security Manager
Sharing Partnership (CiSP) submission to gain further intelligence and support • Core IT CIRT
mitigation by others.
• Head of IT
Immediately report Data Breaches that have occurred to the relevant Data
• Information Security Manager
Protection Officer.
• CIRT
Consider whether reporting suspected or confirmed unauthorised access to any • Head of Information Governance
personal data to the authority is appropriate at this stage. • Data Protection Officer
Incident reporting Where appropriate consider reporting requirements to Information Commissioner’s • Head of IT
Office (ICO), relevant Regulator and or Competent Authority (NISD), National • Information Security Manager
Cyber Security Centre (NCSC), Police Scotland and Scottish Cyber Coordination • CIRT
Centre (SC3) • Head of Information Governance
• Data Protection Officer
Analyse the data types and quantities to determine if there has been a privacy • Information Security Manager
breach (i.e. involving personal data). • Core IT CIRT
Analyse the data types and quantities to determine if there has been a breach of • Information Security Manager
financial data (e.g. organisational financial reports, customer or employee credit • Core IT CIRT
card details, bank details etc.).
Analyse the data types and quantities to determine if the data is only found in the • Information Security Manager
organisation’s environments, or shared with third party systems. • Core IT CIRT
In line with the GDPR (Article 33) the ICO must be informed within 72 hours of the
organisation becoming aware of an incident resulting in a “risk to the rights and • Information Security Manager
freedoms of those involved”. • CIRT
Determine whether the Data Breach needs to be reported to the ICO further • Data Protection Officer
guidance can be found at [Link]
Where a decision to notify the ICO has been made the following must be included
as a minimum:
• Describe the nature of the personal Data Breach including where possible, the
categories and approximate number of data subjects and personal data records
concerned. • Information Security Manager
• Communicate the name and contact details of the contact point where more • CIRT
information can be obtained. • Data Protection Officer
• Describe the likely consequences of the personal Data Breach.
Describe the measures taken or proposed to be taken to address the personal Data
Breach, including, where appropriate, measures to mitigate its possible adverse
effects.
Isolate all affected systems or accounts from the infrastructure through removal
• Information Security Manager
from the network or application of strict access controls, to prevent further data
• Core IT CIRT
exfiltration.
Reverse engineer malware to identify the indicators of compromise that will assist • Information Security Manager
with eradication phase. • Core IT CIRT
Reset passwords of legitimate user accounts and reduce permissions where • Information Security Manager
possible. • Core IT CIRT
Eradication
• Information Security Manager
Remove any malware identified during the analysis phase using appropriate tools.
• Core IT CIRT
Disable system and user accounts that have been used as a platform to conduct • Information Security Manager
the attack. • Core IT CIRT
Complete an automated or manual removal process of the malware using • Information Security Manager
appropriate tools. • Core IT CIRT
Re-install any standalone systems from a clean OS back-up before updating with • Information Security Manager
trusted data back-ups. • Core IT CIRT
Co-ordinate the implementation of any necessary patches or vulnerability • Information Security Manager
remediation activities. • Core IT CIRT
Establish a Data Leak and Recovery Plan. This plan should state the • Information Security Manager
Data Recovery • Senior/ Gold Command Team
circumstances in which the organisation would engage with any Threat Actor
and Analysis
claiming to have exfiltrated data and define the general process for monitoring,
• Consider monitor Data Leak sites ( likely requiring a Dark Web capability)
• potentially seek proof of exfiltration
• consider engage Threat Actor as a delaying tactic with support of Law
Enforcement and or CIR
• identifying who and how often leak sites are monitored for publication
• identifying who, how and when leaked data will be recovered
• identifying who, how, where and when recovered data will be assessed on
the basis of sensitivity
• consider the notification process to data owners and individuals impacted
directly in the data leaks /compromise
• liaising with Police Scotland on preventative advice for data loss victims
• consider media handling
Draft a post-incident report that includes the following details as a minimum: • Senior Stakeholders
• Head of Information
• Details of the cause, impact and actions taken to mitigate the cyber incidents, Governance
and including, timings, type and location of incident as well as the effect on
• Head of IT
users;
• Audit Committee
Incident reporting • Activities that were undertaken by relevant resolver groups, service providers
• Information Security Manager
and business stakeholders that enabled normal business operations to be
resumed; • Resilience Lead
• Recommendations where any aspects of people, process or technology could • Business Continuity Lead
be improved across the organisation to help prevent a similar cyber incidents • Police Lead
from reoccurring, as part of a formalised lessons identified process.
Complete the formal lessons identified process to feedback into future preparation • Information Security Manager
activities. • CIRT
Lessons
Identified & • Information Security Manager
Problem Conduct root cause analysis to identify and remediate underlying vulnerabilities. • Core IT CIRT
Management • CIRT
Consider sharing lessons identified with the wider stakeholders. • Information Security Manager
Review staff welfare; working hours, over time, time off in lieu (TOIL) and • Information Security Manager
Human • HR
Resources expenses.
• Head of IT
Communications • Information Security Manager
Publish external communications, if appropriate, in line with the communications
strategy to provide advice to customers, engage with the market, and inform press • Communications Team
of the cyber incidents. • Resilience Lead
• Business Continuity Lead
These communications should provide key information of the cyber incidents
• Policy Lead
without leaving the organisation vulnerable or inciting further Data Loss attacks.
Notification through:
Reports of Data • Reports of customer or personal Collate initial
Detect
or compromised data?
• Current to determine if has been a breach of financial Consider engaging
Engage technical • What is the impact to the
• Originates from the there has been a data (e.g. organisational financial the DPO and
staff organisation?
organisation or privacy breach (i.e. reports, customer or employee reporting to the ICO
• Are customers affected?
customer involving personal credit card details, bank details
• What legal and regulatory
data). etc.).
requirements have been violated?
Remediation
Contain systems
Consider Deploy latest
that have been Contain business effects Re-image systems
disconnecting malware definitions Restore serviced to
affected to prevent of the cyber security and scan for
infected systems to anti-malware BAU
further data incident malware
from the network solutions
exfiltration
Post Incident