Home United States USA — software What to do first when hit by a cyber attack

What to do first when hit by a cyber attack

177
0
SHARE

Security consultant Gemma Moore looks at the actions organisations should take if they suspect they have suffered a cyber security incident.
At some point, your business may have to deal with a cyber security incident. But when you are under pressure and your team is stressed, people make mistakes.
Delaying too long in making critical response decisions may exacerbate the impact of the incident but, conversely, making knee-jerk decisions can cause further damage to the business or hinder a complete response.
There are many ways you may suspect that a security incident has happened, from detecting unusual activity through proactive monitoring of critical systems or during audits, to outside notification from law enforcement and compromised data located in the wild.
However, indicators such as unusual CPU ( central processing unit ) and network usage on a server may have multiple potential causes, many of which are not information security incidents. So it is vital to investigate further before jumping to conclusions.
Do you have any corroborating evidence? For example, if the IDS ( intrusion detection system ) detects a brute force attack against the website, do web logs support this having occurred? Or, if a user reports a suspected phishing attack, has this email been received by other users and did the user click on links or open documents?
You also need to think about answering questions about the nature of the incident.

Continue reading...