The Recovery Orange Book

Post Incident Response Checklist

The Security Manager’s Incident Checklist

CISO Initial steps

  • Review legal and regulatory requirements for breach notification to ensure compliance.
    • Ensure compliance with all applicable data breach notification laws, such as GDPR, HIPAA, and CCPA.
  • If required, report the incident to the appropriate authorities, such as the FBI or CISA in the U.S., within the required timeframes.
  • Work with IR lead to establish clear, consistent, and transparent communication channels for all Stakeholders via your crisis comms plan(s).
  • Craft transparent and timely notifications that detail what happened, what data was affected, what the organization is doing, and what actions individuals should take.
  • Own the narrative by proactively communicating with the public to protect your organization's reputation.
  • Have your public relations team collaborate with security professionals and executive stakeholder to manage content and messaging.
  • Communicate with clients and customers who may have been impacted, offering support and transparent updates.
  • After recovery, publish a public report or a blog post to share lessons learned, reinforcing your organization's commitment to security and transparency.

IR lead

  • Immediately identify all relevant internal stakeholders (management, IT teams, employees) and external stakeholders (clients, suppliers, media, regulators).
  • Ensure that all digital evidence is handled using forensically sound methods and that a clear chain of custody is maintained for legal admissibility.
  • Post event – Work with crisis communications team to engage in thought leadership by publishing insights about the incident response to rebuild trust.
  • Conduct a technical debrief with security and IT teams to review tools and procedures.
  • Develop a list of actionable recommendations based on the findings from the post-mortem review.

IT Teams

  • Review and update all user access privileges, enforcing the principle of least privilege post-breach.
  • Audit all accounts for unusual activity and reset credentials for any that were compromised. (Especially service accounts.) Rotate passwords for all admin and service accounts.
  • Review all Active Directory activity to make sure no new credentials were created that are unaccounted for by HR direction.
  • Review backup data for anomalies, deletions, modifications, encrypted items, or other IoC.
  • Scan backups for any new or anomalous file extensions, deletions, or whether unexpectedly large files were downloaded by new users, service accounts, user credentials that recently changed.
  • Apply patches to all affected systems and update all systems enterprise-wide with the latest security updates. (If this step is impossible, notify the CISO that the risk register may need to be updated.)

DevOps or Product Teams

  • If the attacker moved laterally, implement network segmentation improvements to prevent similar ease of movement in the future.
  • Conduct a final security audit to ensure all vulnerabilities have been addressed and/or patched and the environment is secure.
  • Once a confirmed clean backup copy is available, push backups and document any discrepancies in file names or extensions.

CISO Postmortem

  • Review your cyber liability insurance policy to understand your coverage for costs   associated with the attack, including legal fees, forensic investigations, and any regulatory fines.
  • If you have one, use your cyber insurance firm's panel of pre-approved experts for support with legal counsel and forensics.
  • Review and update security policies (as appropriate) to reflect the attack and any new policies or recommendations.
  • With the IR lead, conduct a blameless post-mortem analysis to identify the root cause of the breach and evaluate the effectiveness of your incident response.
  • Enhance monitoring and detection capabilities as needed to prevent similar attacks from going undetected.
  • Work with HR to update any onboard/offboarding processes and procedures as needed.
  • Work with HR to provide support and resources for employees who may be experiencing stress or burnout from the incident.
  • Update emergency contacts in your incident response plan, including internal teams and external stakeholders.
  • Update your crisis comms plans with contingencies or lessons learned from the engagement.
  • Update security awareness training with specific examples from the attack.
  • Reinforce the security culture by celebrating employees who reported suspicious activity, or who put in extra hours to facilitate recover.

CISO post review with CFO or board review

  • (If appropriate) Formalize relationships with third-party vendors who assisted during the breach.
  • Assess the damage and determine the financial loss caused by the attack.
  • Analyze the attack's financial impact to inform future budget requests for security.
  • Brief employees on what happened and how to reinforce security best practices, using anonymized scenarios from the incident as a learning story.
  • Update your incident response playbook, crisis comms plans, etc. to incorporate lessons learned from the incident.
  • Implement a continuous improvement program for your security posture.