Incident management
Page 6 of 7
Maintain: Build and upkeep of your capability

Every organisation is different. Questions of scale, physical distribution and business type will all play a part in determining your approach to building an incident response capability.
This section provides a high level overview of the most important considerations.
- 1
Gain support from senior management:
Review previous incidents you've experienced, drawing out issues and impacts that a more enhanced IR capacity would have helped with.
Review online sources to understand other organisations' incidents, issues, and the associated costs. Run briefings and exercises at Board level to increase the understanding of the potential impact a major incident can have.
- 2
Understand threats and risks to the business:
This is critical to understanding the appropriate level capability to build. Consider the specific threats to your sector and business, as well as the general 'threat landscape'.
Ensure that all aspects of the business are considered, as different areas may have different risks.
- 3
Understand the current capability baseline:
Build a clear picture of your current team's skillsets and experience. Alongside this, you should understand what tools, system capabilities and logging are employed.
Ensure liaison across the wider business takes place. In particular, you should engage with Business Continuity/Disaster Recovery, Legal, HR and other relevant (e.g. control system / operational technology) teams to see what plans and processes are already in place. Ensure this review is extended to key suppliers.
- 4
Understand budget constraints and compare costs:
Explore your options thoroughly, particularly where suppliers are concerned. There are a vast range of capabilities and services related to IR, monitoring and detection. They are not all the same!
What would most enhance and compliment your current baseline? What is your biggest issue? Not having guidance documented? Not having in-house experience? Limited technology? The answers to these questions would inform and prioritise your plan and budget spend.
- 5
Identify key stakeholders and supporting teams:
This is likely to include the IT security team, but will also take in other IT teams, legal, HR and PR, as well as suppliers. There may also be specialist teams or vendors specific to certain aspects of your business or products.
Remember that senior management may need to support critical decisions and elements such as media handling. Consider different incident scenarios and who should be involved.
- 6
Review and exercise to understand key gaps and risks:
Exercising is one of the strongest ways to understand your current capabilities and experience levels. It provides education and experience for staff (including up to Board level) and helps to identify gaps in your provisions.
Review all aspects of your response capacity and learn from previous incidents.
- 7
Consider the level of in-house vs outsourced capability:
There are many benefits to both approaches. In-house capabilities often benefit from specific business knowledge and context. Meanwhile, outsourced capabilities often draw upon much wider experience and knowledge and may often have the capacity to handle bigger incidents.
Costs will vary hugely - and most organisations will go for a combination of in-house and outsourced capabilities.
Maintaining your capability
Once an IR capability has been built, it will need to be maintained.
The threat landscape constantly changes, IR and security technologies evolve, attacker techniques improve. There may also have been turnover in staff and changes to business processes. All of these can affect your IR needs and capability.
How to maintain a capability:
-
Regularly exercise:
Exercises can help you to identify gaps that may have appeared, as well as provide your team with experience and practice.
This could potentially include your suppliers. Exercises can be run in a variety of ways, from 'tabletop' to more in-depth simulations.
Engage specialist support if required to aid in running these sessions, as they can draw upon experience and knowledge from a range of other organisations.
It is vital to run exercises for all levels across the organisation, including Board level. In fact, exercising may also help with gaining Board level support (and funding) for enhanced capabilities.
-
Review and test technical capabilities and technologies:
In addition to exercising, it is a good idea to review and test specific elements of your IR process.
For example, testing the recovery of a folder from a week old backup, or ensuring log files can be extracted for analysis in a timely manner.
Review technology and security suppliers regularly to ensure they still offer the right service and capability for your business.
-
Review processes and guidance:
This may be conducted as part of your exercising, but a full review of any IR plans, playbooks and other guidance should occur at least yearly - it may also occur following major incidents.
Ensure contact details are up to date and that processes and guidance are still appropriate following any changes in business or threats over the year.
Make sure that all relevant people can access material needed for their role.
-
Keep up to date with threat intelligence and business risks:
The threat landscape is constantly changing, and in some cases the business may be too.
Expanding to new parts of the world, bringing in a new service or product, merging or partnering with other businesses and more. These can have an effect on all aspects of cyber security, including incident response.
-
Run post incident reviews:
For incidents of a certain level, always run post incident reviews, ideally as soon as possible after the incident so everything is fresh in people's minds.
This is one of the most valuable ways to identify gaps and issues with the response capability, as well as gaps and issues in security generally.
Ensure that all improvement steps are documented and assigned to be implemented.
-
Train and design career paths for staff:
Retaining IR staff can be difficult as the incident response skillset is very sought-after.
Consider the career paths on offer in order to retain staff and provide them with development opportunities.
Think about what training would be best for new and existing staff - it may be a combination of specific courses and on the job training, with secondments worth considering where possible and practical.