Cybersecurity Incident Response Plan Guide
Cybersecurity Incident Response Plan Guide
up a cybersecurity
incident response plan
Contents
1. What is a cybersecurity incident plan?
2. The cost of a data breach
3. Why do you need a cybersecurity incident plan?
4. 6 phases of a cyberysecurity incident plan
5. Creating an incident response team
6. Cybersecurity training exercises
7. Cybersecurity incident response plan best practices
8. Examples and templates
9. How Kaspersky can help
1
h
ttps://[Link]/content/dam/
digitalmarketing/vmware/en/pdf/docs/
vmwcb-report-the-state-of-incident-
[Link] 2
The cost of a security breach
2
[Link]
security/eighth-annual-cost-cybercrime-study
3
[Link]
cybersecurity-almanac-2022/
4
[Link]
5
[Link]
Study-More-Than-Half-of-Organizations-with-
Cybersecurity-Incident-Response-Plans-Fail-
to-Test-Them
6
[Link]
centre/talktalk-cyber-attack-how-the-ico-
investigation-unfolded/
7
[Link]
articles/2021-06-04/hackers-breached-
colonial-pipeline-using-compromised-password 3
Why do you need a cybersecurity incident response plan?
Keep costs Regulatory fines, compensating customers, and investigating and recovering
from incidents make breaches potentially very costly. A solid CSIRP will reduce
down all of these costs, making it a sound investment.
If you experience a data breach, you might be legally required to take certain
Don’t miss steps and notify the relevant authorities such as government agencies, as well
anything as the affected parties. Without a CSIRP in place, you’re likely to miss crucial
steps or overlook such details, which will put you at risk of additional fines and
legal action.
Rapid A good CSIRP includes detailed procedures for securing backups, ensuring
response secure identity and access management, and responding quickly to
and data vulnerabilities and threats. Having these procedures already in place ensures
your ability to rapidly resolve any incidents, protecting your data and systems.
protection
4
6 phases of a solid CSIRP Preparation Identification
1. Preparation
The preparation phase is in many ways the most important section, as it
provides the foundation for the rest of the plan. Technically, you should always
be in the preparation phase: prepared for any emerging incident, and keeping
your plan constantly up-to-date and operational. The key elements that should
be included in the preparation phase are:
• Ensuring that all your employees are properly educated regarding data
security and responding to cyber threats and emergencies.
• Conduct a risk assessment to prioritize security issues, identify the most
sensitive assets and the most critical security incidents your team should
focus on.
• Conduct regular training and drills so that everybody is ready to act
appropriately in case of an incident. Check out page 10 for more on common
incident plan drills.
• Assign the relevant roles and responsibilities for your cyber security incident
team, and ensure they have access to the necessary systems and tools. For
more information on team responsibilities, see page 9.
• Clarify the processes and lines of communication in the event of an incident.
Who needs to be contacted, and when? Not having clear, established
communications in an emergency can cause a lot of mess and inefficiency.
• Make sure that every aspect of your plan (training, execution, resources
etc.) is approved, funded and available in advance. In short, is your plan
operational?
2. Identification
This phase of the plan is triggered when an incident has just occurred, and you
need to diagnose it and decide the appropriate course of action. You can’t
prepare specifically for all possible incident sources because there are too
many, but your team should be able to effectively detect the type and severity
of the threat and determine the response.
5
6 phases of a solid CSIRP Identification Containment
There are two types of sign that your security systems are under attack:
precursors (detected before an attack happens) or indicators (detected
during or after an attack).
• An example of a precursor would be a high number of failed login attempts,
suggesting that an attacker is trying to penetrate your network by guessing
a username and password.
• An example of an indicator would be an antivirus software alerting you that
someone on your network has clicked on a malware link and their computer is
infected.
This phase also includes documentation: your team should record everything
that happens, including the nature of the attack, any evidence, and their
actions taken to respond. This will be useful in the post-incident activities
phase, in court and when facing the auditors.
Finally, this phase should also include notification: making sure that all relevant
parties (law enforcement, federal agencies, customers, shareholders and
affected businesses) are made aware that an attack has taken place. Timely
notification ensures you stay on the right side of the law, protects your
reputation and reduces your liability in the long-run. Your plan should include
clear instructions on who should be notified and the steps in the notification
procedure
3. Containment
When you first discover a breach, you might be tempted to just delete all
the contaminated data as soon as possible to remove the threat. However,
this would also remove all the valuable evidence you can use in post-incident
audits, and to help you determine how the breach started and how to prevent it
happening again.
Instead, it’s better to contain the breach by disconnecting affected devices
from the Internet, preventing any further damage to your business. It’s also a
good idea to have a redundant system back-up at the ready to help restore
operations and not lose compromised data forever.
Containment can take two forms:
• Short-term containment: temporary solutions such as isolating the
affected network segment, taking down any servers that have been
compromised, and redirecting traffic to backup servers.
• Long-term containment: continuing operations using temporary solutions
while rebuilding clean systems, preparing to bring them back online in the
recovery stage.
During this phase you can also update and patch your systems, check
your remote access protocols, change all system access credentials, and
strengthen your passwords.
6
6 phases of a solid CSIRP Containment Eradication
There are a number of factors you should take into consideration when
deciding on a containment procedure. The NIST lists them as follows:
Prevention is better • Potential damage to and theft of resources
than cure • Need for evidence preservation
It takes an average of 287 • Service availability (e.g., network connectivity, services provided to external
parties)
days for a security team
to identify and contain a • Time and resources needed to implement the strategy
data breach, according to
• Effectiveness of the strategy (e.g., partial containment, full containment)
IBM’s Cost of a Data Breach
report 2021.9 That’s why • Duration of the solution (e.g., an emergency workaround to be removed in
the preparation phase is so four hours, a temporary workaround to be removed in two weeks, permanent
solution).
important—to prevent any
incidents occurring in the
first place. Questions to ask at the containment phase:
1. What are you doing to contain the breach in the short- and
long-term?
2. Have you quarantined all affected areas?
3. What backups do you have in place?
4. Have all access credentials been changed and strengthened?
5. Have you applied all the latest security patches and updates?
4. Eradication
The exact steps in the eradication phase will depend on the type of attack
you are experiencing. For example, you could be deleting malware, disabling
any compromised accounts, closing vulnerabilities in the network, etc.
Fundamentally, eradication means finding the root cause of the attack and
getting rid of it!
Your team could be eliminating the threat themselves, or you could get a
third-party to do it; either way, there’s one important point to remember: the
eradication must be complete. If even a trace of malware or affected areas
remain in your systems, you could still be suffering from compromised data and
increased liability.
The US Federal Trade Commission gives a list of steps you can take to secure
your systems during and after an attack, including consulting a third party data
forensics team, securing any physical systems that have been compromised,
sorting out any inappropriate material that’s been posted on your networks,
and talking to the people who found the breach.
Having a sound CSIRP in place is crucial for this phase because following its
instructions will ensure that your eradication and security procedures are deep
and meticulous, leaving no stone unturned.
7
6 phases of a solid CSIRP Recovery Post-incident activities
5. Recovery
The recovery phase involves restoring and returning the affected systems back
into business operations. This should be done carefully to ensure that another
incident doesn’t take place.
This process can take days, weeks, or months, depending on the severity of
the breach. The NIST recommends starting by immediately strengthening your
overall security, and then focusing on long-term, ongoing changes to keep your
systems as secure as possible.
Important things to take into consideration during this phase are when to fully
restore operations, how you will verify that everything is functioning normally,
and how long you will continue to monitor the situation until you’re really sure
that everything is back to normal.
6. Post-incident activities
This phase essentially consists of a post-incident debrief meeting with all
involved parties. The meeting should ideally be held a few days after the
incident has been successfully resolved, and no longer than two weeks after,
so that everything is fresh in people’s minds. It’s a way to get closure after the
incident.
Key elements of this phase include:
• A complete review of the incident, from discovery to recovery. The review
should focus on questions like these: Did everyone follow the procedures
in the CSIRP? Was it effective? Were there any weak points or things that
could be improved? What could be done differently next time? How could
similar incidents be prevented in the future?
• An evaluation and update of your incident plan according to any conclusions
drawn from the review.
• The creation of a follow-up report for reference when handling similar
incidents. Having a formal chronology of events (with timestamped
information like data logs) is also useful for legal procedures like audits.
• An assessment of the total damage caused by the breach, including a
monetary estimate. This is also useful for legal reasons such as prosecution
activities.
• Tying up all loose ends that you didn’t have time for during the incident,
such as completing related documentation and making sure that all relevant
parties are notified.
8
Setting up an incident response team
• Central — a central body that handles all incidents for the entire organization.
• Distributed — multiple response teams, each responsible for a different
physical location, department, or part of the IT infrastructure.
• Coordinated — A central team serving as a knowledge center for various
distributed teams, and assisting them with complex, critical or organization-
wide incidents.
Depending on the size of your organization and the criticality and complexity of
possible incidents, you might have a dedicated, full-time incident response team,
or you might train ordinary employees to double as a response team in times of
emergency. Some organizations even outsource their security needs to a third-
party incident response team.
9
Cybersecurity training exercises
Your training plan should include at least one large-scale coordinated annual drill,
which can be one or two days long. Smaller, table-top drills can be conducted
more frequently, according to your organization’s needs.
Discussion-based exercise
– Drawbacks: doesn’t fully test your response plan or your team’s response
actions in real-time.
Simulation exercise
This is a live walk-through that has been highly choreographed and planned.
– Drawbacks: requires more time to plan and coordinate, but still doesn’t
10
ttps://[Link]/why-
h
completely test your plan or team roles in the most realistic way.
isaca/about-us/newsroom/
press-releases/2021/new-isaca-
study-finds-cybersecurity-
workforce-minimally-impacted-by-
pandemic-but-still-grappling 10
Cybersecurity incident response plan best practices
Parallel testing
– Benefits: provides your team with the most realistic simulation and
the best real-time feedback about their actions and roles. This should
definitely help identify any weak points or holes in your plan and team’s role
understanding.
– Drawbacks: requires more planning than any other type of training, and
is also the most expensive because an actual test environment must be
simulated (including segregated systems, networks etc.).
A security breach can affect all areas of the organization, so you need to make
sure that everybody is involved and on board. All key stakeholders should be
given a voice in the preparation of your security plan; these can include senior
management, human resource leaders, legal representatives, compliance
officers, and third-party stakeholders such as technology providers and public
relations.
Your security plan might look just marvelous on paper, but it’s good for nothing
if it doesn’t actually work when it needs to. Regular drills and exercises make
sure that everybody has a clear idea of what they need to do in an emergency,
and they help to identify and remedy any weak spots in the plan. Practice makes
perfect!
4. Keep it simple
Your incident response plan is like a battle strategy manual, so it should be easy
to follow in the heat of war. You don’t want your staff to be losing precious time
trying to understand an overly-complicated document when your organization is
under attack. Yes, it should be detailed, with specific steps and procedures laid
out — but it should also be clear and actionable.
11
How Kaspersky can help
Learn More
12