Skip to main content
Guidance

Incident management

How to effectively detect, respond to and resolve cyber incidents.

Page 5 of 7

Develop: Technical response capabilities

iStock.com/filo
This section explores the technology, logs and evidence required to manage a cyber incident. We also examine the types of technical actions and analysis that you may need to undertake during an incident.

A successful technical response requires experienced and skilled individuals, as well as tools, specific network settings and access to data.


GDPR - supplying data to third parties

If data is provided to suppliers, GDPR requires that data controller ownership must be considered, as well as their capabilities.



Systems or data in the cloud:

Cloud / hosting providers may not turn on, or allow admin access to all logging by default.

Work with cloud providers to ensure you have access to relevant data, when required (either directly or via their staff).

Evidential data capture

When the incident is likely to lead to court action, it may be necessary to capture data evidentially. It is worth at least having evidence bags available and some basic guidance for local IT staff on how to capture a system and store it securely.

Log testing

It's essential that you review and test log availability and extraction.

Many investigations have been hindered due to lack of log data. Often, this is data that the organisation believed they had, but hadn't verified.


To be successful, actions often need to be synchronised across the entire IT estate, so that infections can be eradicated in a single pass.



Don't overreact

During containment it is important to think through the potential repercussions of any actions you might take to deal with the incident.

Overreacting can cause more damage than the incident itself. And in the case of targeted attacks, the attacker could react or bury themselves more deeply in your network.

In some cases, it may be better to monitor and analyse further before you take action. You will need to assess this on a case-by-case basis.

The key to knowing the right action to take is to create your own organisation-specific guidance and exercise different scenarios. This will help you determine the best actions for your organisation and IT set-up, as well as to building staff experience. When the moment comes, you will thus be better prepared and more likely to take the most appropriate action.



More advanced capabilities include:

  • The ability to carry out actions in a timely manner, including out of hours (consider supplier SLAs and staff availability / on call if required)
  • Synchronisation of a range of actions across the estate, including different timezones and countries (particularly for remediation)
  • More complex actions such as:
    • Resetting domain admin and service accounts, and estate wide resets
    • Remotely isolate or quarantine machines or parts of the network
    • Remotely block or remove malicious files and/or processes
    • Block or alert on specific patterns (e.g. traffic patterns)
  • Monitoring of network and host activity to confirm actions have been successful.

Confirm remediation success

You should always confirm that remediation has been successful before moving to recovery.

It is vital that staff are available who can authorise critical decisions, such as taking a customer database or website offline.

The people required to actually perform the action must be aware of who they need to contact, how to contact them, and when. This applies to suppliers as well as in-house staff.

Continuity planning should take into account outages and down times as part of cyber incident and response. This should be linked to disaster recovery planning.

There may also be non-technical actions to deal with at this stage. This could include the likes of media handling, customer support and regulatory or legal duties. For more detail, see the process page.

Backups must be confirmed as clean

Only clean data should be copied back onto clean systems and networks.

Tip:  Backing up just 'data' (i.e. work documents rather than system files) will help prevent executable files (and therefore infections) hiding in your back ups.


Reviewed

Version

1.0