Skip to main content
Guidance

Incident management

How to effectively detect, respond to and resolve cyber incidents.

Page 6 of 7

Maintain: Build and upkeep of your capability

iStock.com/Nuthawut Somsuk
Choosing, training and equipping the right level and type of Incident Response capability

Every organisation is different. Questions of scale, physical distribution and business type will all play a part in determining your approach to building an incident response capability.

This section provides a high level overview of the most important considerations.

  • 1

    Gain support from senior management:

    Review previous incidents you've experienced, drawing out issues and impacts that a more enhanced IR capacity would have helped with.

    Review online sources to understand other organisations' incidents, issues, and the associated costs. Run briefings and exercises at Board level to increase the understanding of the potential impact a major incident can have.

  • 2

    Understand threats and risks to the business:

    This is critical to understanding the appropriate level capability to build. Consider the specific threats to your sector and business, as well as the general 'threat landscape'.

    Ensure that all aspects of the business are considered, as different areas may have different risks.

  • 3

    Understand the current capability baseline:

    Build a clear picture of your current team's skillsets and experience. Alongside this, you should understand what tools, system capabilities and logging are employed.

    Ensure liaison across the wider business takes place. In particular,  you should engage with Business Continuity/Disaster Recovery, Legal, HR and other relevant (e.g. control system / operational technology) teams to see what plans and processes are already in place. Ensure this review is extended to key suppliers.

  • 4

    Understand budget constraints and compare costs:

    Explore your options thoroughly, particularly where suppliers are concerned. There are a vast range of capabilities and services related to IR, monitoring and detection. They are not all the same!

    What would most enhance and compliment your current baseline? What is your biggest issue? Not having guidance documented? Not having in-house experience? Limited technology? The answers to these questions would inform and prioritise your plan and budget spend.

  • 5

    Identify key stakeholders and supporting teams:

    This is likely to include the IT security team, but will also take in other IT teams, legal, HR and PR, as well as suppliers. There may also be specialist teams or vendors specific to certain aspects of your business or products.

    Remember that senior management may need to support critical decisions and elements such as media handling. Consider different incident scenarios and who should be involved.

  • 6

    Review and exercise to understand key gaps and risks:

    Exercising is one of the strongest ways to understand your current capabilities and experience levels. It provides education and experience for staff (including up to Board level) and helps to identify gaps in your provisions.

    Review all aspects of your response capacity and learn from previous incidents.

  • 7

    Consider the level of in-house vs outsourced capability:

    There are many benefits to both approaches. In-house capabilities often benefit from specific business knowledge and context. Meanwhile, outsourced capabilities often draw upon much wider experience and knowledge and may often have the capacity to handle bigger incidents.

    Costs will vary hugely - and most organisations will go for a combination of in-house and outsourced capabilities.


Reviewed

Version

1.0