Learning lessons from a cyber incident can reduce the likelihood of it happening again.
After the incident, it’s important to:
review what has happened
learn from any mistakes
take action to try and reduce the likelihood of it happening again.
Not only is it important to review your technical controls after the incident, it is also a great opportunity to review and implement staff awareness or training measures to help develop your staff’s security culture.
Review actions taken during response
Collate and review the actions you documented throughout the response to the incident. Make a list of things that went well and things that could be improved from the response stage.
Review and update your incident plan
Where necessary, make changes to the incident plan you created in Step 1, to reflect the lessons learnt .
Strengthen your defences
Reassess your risk and make any necessary changes. For example, if you were a victim of a password attack you may need to create a new password policy, provide new training, provide physical secure storage for passwords (or password manager apps) for your staff.
Consider the terms of your contracts
Depending on how successful the incident response was, you may need to make a strategic decision on your third party contracts. You might want to consider the following:
Does this incident mean the way that you do business has to change?
If you currently outsource, did their response meet your needs?
If they didn’t meet your needs consider renegotiating the terms of the contract or cancel, changing to a new company.
Did you have the skills in-house to do it yourself, negating the need to outsource in the future?