Journal Assignment 5
Somboune Khanchaleunh
St. Petersburg College
CIS - 4776
Prof. Tillman
10/1
Journal Assignment 5
Phase 1: Initial Response
We have to go to the Security Operations Center (SOC) because of anomalous behavior at 2:30
AM on Tuesday, the first action we will take is to begin collecting forensic evidence while systems
remain online. This is the appropriate measure because immediately shutting down systems can corrupt
crucial evidence and disrupt energy operations. Leaving the systems active while carefully isolating
systems will let investigators assess the network traffic, collect logs, and entry points of the systems.
Phase 2: Intelligence Gathering
The team discovers evidence of malware with code similarities to previous nation-state attacks,
phishing emails sent to employees 3 days ago, unauthorized remote access tools installed on 15
workstations, and attempts to access SCADA systems controlling power distribution.
Upon seeing the evidence, it can be safe to assume that the attack can be linked to a nation-
state group. From the evidence mentioned above, the attack is likely going to try to take out a portion of
the power grid. Another objective may just to be to sabotage the organization for their own gain. Proof
of this can be seen from the phishing emails and attempts to access the systems, indicating a planned
and coordinated attack.
Phase 3: Crisis Communication messages
1. CEO/leadership team: We have identified coordinated malicious activity that affects internal
networks and limited access attempts of our systems. Our team is actively investigating and containing
the threat but support from executives may be needed for decision making and leadership.
2. Customer Notice: We are investigating a cybersecurity incident that may affect certain areas.
While core operations will remain active, we are taking proactive steps in order to protect customer
data. As the situation continues we will provide more information.
3. Regulatory Report: This will be the initial report of a confirmed cybersecurity incident
involving internal networks and attempts to access control systems. Containment measures and
investigations are underway, as the situation continues to develop we will provide more details.
Phase 4: Containment Strategy (In order of importance)
1. Isolating affected SCADA systems is crucial so that core operations will remain active and
prevents attackers from causing real-world physical disruption.
2. Blocking suspicious IP addresses at the firewall will cut off active connections and stop further
intrusion attempts, limiting what the attackers can do.
3. Preserving forensic evidence such as disk images, memory captures, and logs can be critical in
understanding the attacker’s behavior. It will also be crucial when taking steps to restore systems
correctly and preparing legal action.
4. Resetting all employee passwords comes next because it stops the attackers from using stolen
credentials.
5. Coordinating with an external cybersecurity firm provides additional analytical and specialized
detection capabilities.
6. Implementing emergency communication protocols is also important but the immediate need
to protect operations and collect evidence comes first. Communication can be crucial to keep teams in
check and customers informed.
A real-world example that is similar to the case mentioned above can be seen from a
cybersecurity attack on Ukraine in 2015. Ukrainian power companies experienced unscheduled power
outages that impacted a large number of customers in Ukraine. It was clear that the attack was
synchronized and coordinated, with each company falling victim to the attackers within 30 minutes of
each other. There are also reports of malware found in their systems delivered via spear phishing. An
interagency team comprised of professional cybersecurity teams worked together with the Ukrainian
government to gain more insight on the situation and prevent future cyber-attacks.
References
[Link]