0% found this document useful (0 votes)
5 views5 pages

Cybersecurity Incident Response Plan

The document outlines a response plan for a cybersecurity incident involving anomalous behavior detected at a Security Operations Center. It details phases of response including evidence collection, intelligence gathering linking the attack to a nation-state group, crisis communication strategies for stakeholders, and a containment strategy prioritizing system isolation and forensic evidence preservation. A real-world comparison is made to the 2015 cyberattack on Ukraine's power grid, highlighting the coordinated nature of such threats.

Uploaded by

slkhanchaleunh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views5 pages

Cybersecurity Incident Response Plan

The document outlines a response plan for a cybersecurity incident involving anomalous behavior detected at a Security Operations Center. It details phases of response including evidence collection, intelligence gathering linking the attack to a nation-state group, crisis communication strategies for stakeholders, and a containment strategy prioritizing system isolation and forensic evidence preservation. A real-world comparison is made to the 2015 cyberattack on Ukraine's power grid, highlighting the coordinated nature of such threats.

Uploaded by

slkhanchaleunh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Journal Assignment 5

Somboune Khanchaleunh

St. Petersburg College

CIS - 4776

Prof. Tillman

10/1
Journal Assignment 5

Phase 1: Initial Response

We have to go to the Security Operations Center (SOC) because of anomalous behavior at 2:30

AM on Tuesday, the first action we will take is to begin collecting forensic evidence while systems

remain online. This is the appropriate measure because immediately shutting down systems can corrupt

crucial evidence and disrupt energy operations. Leaving the systems active while carefully isolating

systems will let investigators assess the network traffic, collect logs, and entry points of the systems.

Phase 2: Intelligence Gathering

The team discovers evidence of malware with code similarities to previous nation-state attacks,

phishing emails sent to employees 3 days ago, unauthorized remote access tools installed on 15

workstations, and attempts to access SCADA systems controlling power distribution.

Upon seeing the evidence, it can be safe to assume that the attack can be linked to a nation-

state group. From the evidence mentioned above, the attack is likely going to try to take out a portion of

the power grid. Another objective may just to be to sabotage the organization for their own gain. Proof

of this can be seen from the phishing emails and attempts to access the systems, indicating a planned

and coordinated attack.

Phase 3: Crisis Communication messages

1. CEO/leadership team: We have identified coordinated malicious activity that affects internal

networks and limited access attempts of our systems. Our team is actively investigating and containing

the threat but support from executives may be needed for decision making and leadership.
2. Customer Notice: We are investigating a cybersecurity incident that may affect certain areas.

While core operations will remain active, we are taking proactive steps in order to protect customer

data. As the situation continues we will provide more information.

3. Regulatory Report: This will be the initial report of a confirmed cybersecurity incident

involving internal networks and attempts to access control systems. Containment measures and

investigations are underway, as the situation continues to develop we will provide more details.

Phase 4: Containment Strategy (In order of importance)

1. Isolating affected SCADA systems is crucial so that core operations will remain active and

prevents attackers from causing real-world physical disruption.

2. Blocking suspicious IP addresses at the firewall will cut off active connections and stop further

intrusion attempts, limiting what the attackers can do.

3. Preserving forensic evidence such as disk images, memory captures, and logs can be critical in

understanding the attacker’s behavior. It will also be crucial when taking steps to restore systems

correctly and preparing legal action.

4. Resetting all employee passwords comes next because it stops the attackers from using stolen

credentials.

5. Coordinating with an external cybersecurity firm provides additional analytical and specialized

detection capabilities.

6. Implementing emergency communication protocols is also important but the immediate need

to protect operations and collect evidence comes first. Communication can be crucial to keep teams in

check and customers informed.


A real-world example that is similar to the case mentioned above can be seen from a

cybersecurity attack on Ukraine in 2015. Ukrainian power companies experienced unscheduled power

outages that impacted a large number of customers in Ukraine. It was clear that the attack was

synchronized and coordinated, with each company falling victim to the attackers within 30 minutes of

each other. There are also reports of malware found in their systems delivered via spear phishing. An

interagency team comprised of professional cybersecurity teams worked together with the Ukrainian

government to gain more insight on the situation and prevent future cyber-attacks.
References

[Link]

You might also like