Incident management
Page 4 of 7
Build: A cyber security incident response team (CSIRT)

The core team will usually be IT or Cyber Security staff. The extended team may include other capabilities, such as PR, HR and legal. A full list is described in the sub-sections below.
The team does not have to be dedicated to IR full time. It is more cost effective to have a 'virtual' CSIRT, pulled together when needed, from people who have other day jobs.
Ad-hoc CSIRT teams
If this approach is to be adopted, it is vitally important that the people critical to the CSIRT are able to prioritise an incident over their day-to-day work, when necessary.
Structure and members
The location of the team will depend on the nature of the organisation. A 'central' or 'distributed' model can be chosen, depending on whether it's possible, or desirable, to have IR staff at more than one key location. Many organisations will have a central IR team (for example at the head/main office location) and distributed support from IT or IR staff at other locations.
Roles and responsibilities
The Cyber Security Incident Response Team (CSIRT) may require a number of roles in order to ensure that incidents are managed and coordinated effectively.
These fall under the headings:
- Government and law enforcement
- Senior / Executive management
- Incident manager
- Technical lead / recovery manager
- Crisis management, business continuity, disaster recovery
- Investigators and analysts, cyber security specialists
- IT and infrastructure
- Other departments including legal, PR, HR and customer services
Roles required during an incident
The diagram below details the core roles which will be needed during an incident.
Some individuals may perform more than one role but the responsibilities must be accounted and available as needed, if an incident is to be handled smoothly.
Optional roles are listed, pulling in external teams and additional business management functions.

Central co-ordination
It is vital that there is a central point of co-ordination. The person with this responsibility need not be a cyber security expert. Their role is to ensure that all actions and findings are managed, tracked and correlated and that the incident is communicated to all relevant stakeholders.
It may be preferable to outsource some aspects of the incident response - from technical to PR and legal support. But it is important that there are people in-house who can oversee, advise, and make decisions which affect the business (based on advice from the specialist suppliers).
Assuring availability
Always provide for 'deputies' - people who will cover if a critical person or persons are unavailable.
This applies to all aspects of the response team and any suppliers if they only have one key individual who can carry out certain tasks.
Hours of coverage and surge support
The hours where incident response cover is required will depend on the nature of your business and risk appetite. The choice will need to balance risk and budget, as working extended hours can have large costs associated.
When determining your coverage, the following should be considered:
- How would you handle an incident that starts in the day and cannot be left overnight?
- Might incidents be detected out of hours that cannot wait until the next working day?
- What coverage is required? Weekdays only, extended business hours, or 24/7?
- What is the risk? Do you need official on-call support, or does the cost of this outweigh the risk?
- Is the use of suppliers appropriate? Is a 'follow the sun' type model possible?
The practicalities of part-time cover
There are practicalities to consider if extended cover is only going to be provided during an urgent incident. For example, if an office building is leased, will that building be available 24/7 in the event of an incident?
Staff are likely to need both food and accommodation, which someone will need to arrange and pay for. There may also need to be a shift pattern arrangement of working devised if the hours are particularly long, or if the incident continues for a protracted period. This means you might need more than one person in-house who is capable of each key role - such as leading/coordinating the response.
Note on suppliers
You should review all suppliers to determine who you may require support from during an incident.
This could be anything from infrastructure and cloud hosting to external PR firms. Work with suppliers to ensure they will be able to support when needed. Even in-hours support may be limited from a supplier, depending on your contract.
Team skills and experience
The skills and experience required by your CSIRT will vary depending on the nature of your business and how much of the IR capability you decide to build in-house.
There are, however, some practices which will benefit any organisation.
Maintaining awareness
Make use of threat feeds along with the latest cyber security news and incident reports. These can improve your general awareness and knowledge, they may also alert you to current threats to your sector and organisation.
Ensure the executive team are aware of the threats and their likely roles during an incident. In particular, you should make clear the critical decisions they may need to make, usually with limited information.
Exercising
One of the best ways to identify gaps and hone your response, is to run exercises based on real-life scenarios.
There is significant benefit to these exercises being facilitated by external specialists, who can offer a fresh set of eyes and provide impartial advice. This will help to maximise the benefits from these events.
Exercises can range from deeply technical / tactical through to strategic and management level response. It is well worth running exercises at all levels in order to ensure all aspects of the business know their roles and responsibilities in the event of an incident.
Key to any exercise, whether run in-house or by an external supplier, is the need to document and assign lessons learned in order to drive improvement across your organisation. The NCSC offers a free online resource, Exercise in a Box, which helps organisations test and practise their response to a cyber attack.
Training
The provision of specific training to key staff can significantly improve an organisation's readiness for a cyber incident. There are specific training courses available in this area. Many providers will be able to offer bespoke training and briefing sessions in line with the needs of your business.
- 1
Basic:
For organisations that are not heavily targeted and most response is outsourced - use cyber incident/awareness briefings to develop understanding
- 2
Improved:
For those who require increased capability in-house, consider general cyber investigation and/or incident management training as a starting point
- 3
Advanced:
For those who intend on building a full IR capability in-house, a range of courses including forensics and intrusion analysis (for host and network), and malware analysis.
Specific training for technical recovery leads or lead investigators will help develop the ability to uncover and handle complex, sophisticated incidents.
Executive awareness
It is just as important to build awareness and experience at executive level, as it is at the technical level, as these roles will be required to make urgent, critical decisions.
It is also important to consider who will be able to take on certain key roles, such as incident manager during the response, and who will be required to make critical decisions.
It's also essential to ensure that deputies are appointed in the event that key staff are unavailable, or need a break during a long incident response.