{"id":1672,"date":"2019-02-20T10:50:04","date_gmt":"2019-02-20T16:50:04","guid":{"rendered":"https:\/\/media-moon.com\/blog\/?p=1672"},"modified":"2019-12-05T09:33:53","modified_gmt":"2019-12-05T15:33:53","slug":"the-need-for-an-incident-response-plan-part-1","status":"publish","type":"post","link":"https:\/\/media-moon.com\/blog\/the-need-for-an-incident-response-plan-part-1\/","title":{"rendered":"The Need for An Incident Response Plan \u2013 Part 1"},"content":{"rendered":"<h3><em>Why Is It So Important for Your Business to Have One?<\/em><\/h3>\n<p>In today\u2019s world, Cyber threats and attacks are becoming the norm.\u00a0 There is not one single business or corporation that is immune to these threats.\u00a0 It seems like no matter how much an entity does to fortify its defense perimeters, the Cyber attacker will find a way to circumvent it and inflict whatever possible damage that they can.<\/p>\n<p>Such attacks can range from the theft of confidential information and data about your customers to launching extremely sophisticated Ransomware attacks &#8211; with these, Bitcoin is the only acceptable form of \u201cransom payment.\u201d\u00a0 Consider some of these statistics:<\/p>\n<p>*Over 70% of business entities have reported that they have been a victim of a major Cyber-attack in just the past 12 months;<\/p>\n<p>*The automotive industry reported a 32% increase in detected incidents;<\/p>\n<p>*There was a 60% increase in Security breaches in the healthcare sector alone;<\/p>\n<p>*There was also an astounding 527% increase in Cyber related incidents in the power and utility industry.<\/p>\n<p>These statistics further substantiate the fact that Cyber-attacks can occur in any industry.\u00a0 Now, consider, the financial losses that are associated with this:<\/p>\n<p>*The average cost of a single corporate data breach reached $3.5 million, an increase of 15%;<\/p>\n<p>*Each record that is hijacked or stolen from a database costs a business on average $145.10.<\/p>\n<p>The unfortunate truth is that many Cyber-attacks are so covert and stealthy that they can often go unnoticed for a long period time.\u00a0 Thus, this is where Incident Response becomes absolutely critical.\u00a0 It can be specifically defined as follows:<\/p>\n<blockquote><p>&#8220;The process by which an organization handles a data breach or Cyber-attack, including the way the organization attempts to manage the consequences of the attack or the breach.\u00a0 The goal is to effectively manage the incident so that the damage is limited in recovery time, costs, and brand reputation.&#8221;<\/p>\n<p><span style=\"font-size: inherit;\">&#8211;<\/span><a style=\"font-size: inherit;\" href=\"http:\/\/www.digitalguardian.com\"> www.digitalguardian.com<\/a><\/p><\/blockquote>\n<p>However, it is important to note that responding to an incident as soon as it has been discovered becomes absolutely critical.\u00a0 The above definition states that a process must be used, but it must be a defined and orderly one.<\/p>\n<p>For example, there must be a clear line of communication, specific roles and duties must be assigned to each team member of the IR team, but most importantly, there must be a mechanism put into place which allows the IR team members to report back as to what they have discovered.\u00a0 From here, then the next action items can be quickly determined and enacted upon.<\/p>\n<p>In other words, the IR process must detail how to handle just about any type or kind of Cyber-attack.\u00a0 This process must be viewed as literally an emergency plan (such as a step by step policy) in order to increase the chances that a business entity will be able to resume back to normal operations in a quick and efficient manner.\u00a0 A brief outline of the process is as follows:<\/p>\n<ul>\n<li>Identify the incident<\/li>\n<li>Respond to the incident in a timely manner<\/li>\n<li>Assess \/ Analyze the severity of the incident<\/li>\n<li>Notify the relevant parties about the incident<\/li>\n<li>Take appropriate measures to protect sensitive data<\/li>\n<li>Prepare for quick business recovery in the wake of the damage caused<\/li>\n<\/ul>\n<h3><em>Conclusions<\/em><\/h3>\n<p>In <a href=\"https:\/\/media-moon.com\/blog\/the-need-for-an-incident-response-plan-part-2\/\">our next blog post of the series<\/a>, we examine the benefits versus the risks of taking any part of your IT Infrastructure offline in case it has been hit by a Cyber-attack.<\/p>\n<hr \/>\n","protected":false},"excerpt":{"rendered":"<p>Why Is It So Important for Your Business to Have One? In today\u2019s world, Cyber threats and attacks are becoming the norm.\u00a0 There is not one single business or corporation that is immune to these threats.\u00a0 It seems like no matter how much an entity does to fortify its defense perimeters, the Cyber attacker will [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":1676,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[146,156],"tags":[316,315,313,314],"class_list":["post-1672","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-continuity","category-cyber-security","tag-data-security-breach-notification-act","tag-external-stakeholders","tag-security-incident","tag-security-incident-report"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/posts\/1672","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/comments?post=1672"}],"version-history":[{"count":0,"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/posts\/1672\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/media\/1676"}],"wp:attachment":[{"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/media?parent=1672"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/categories?post=1672"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/media-moon.com\/blog\/wp-json\/wp\/v2\/tags?post=1672"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}