The Security Manager’s Incident Checklist
CISO Initial steps
- Review legal and regulatory requirements for breach notification to ensure compliance.
- Ensure compliance with all applicable data breach notification laws, such as GDPR, HIPAA, and CCPA.
- If required, report the incident to the appropriate authorities, such as the FBI or CISA in the U.S., within the required timeframes.
- Work with IR lead to establish clear, consistent, and transparent communication channels for all Stakeholders via your crisis comms plan(s).
- Craft transparent and timely notifications that detail what happened, what data was affected, what the organization is doing, and what actions individuals should take.
- Own the narrative by proactively communicating with the public to protect your organization's reputation.
- Have your public relations team collaborate with security professionals and executive stakeholder to manage content and messaging.
- Communicate with clients and customers who may have been impacted, offering support and transparent updates.
- After recovery, publish a public report or a blog post to share lessons learned, reinforcing your organization's commitment to security and transparency.
IR lead
- Immediately identify all relevant internal stakeholders (management, IT teams, employees) and external stakeholders (clients, suppliers, media, regulators).
- Ensure that all digital evidence is handled using forensically sound methods and that a clear chain of custody is maintained for legal admissibility.
- Post event – Work with crisis communications team to engage in thought leadership by publishing insights about the incident response to rebuild trust.
- Conduct a technical debrief with security and IT teams to review tools and procedures.
- Develop a list of actionable recommendations based on the findings from the post-mortem review.
IT Teams
- Review and update all user access privileges, enforcing the principle of least privilege post-breach.
- Audit all accounts for unusual activity and reset credentials for any that were compromised. (Especially service accounts.) Rotate passwords for all admin and service accounts.
- Review all Active Directory activity to make sure no new credentials were created that are unaccounted for by HR direction.
- Review backup data for anomalies, deletions, modifications, encrypted items, or other IoC.
- Scan backups for any new or anomalous file extensions, deletions, or whether unexpectedly large files were downloaded by new users, service accounts, user credentials that recently changed.
- Apply patches to all affected systems and update all systems enterprise-wide with the latest security updates. (If this step is impossible, notify the CISO that the risk register may need to be updated.)
DevOps or Product Teams
- If the attacker moved laterally, implement network segmentation improvements to prevent similar ease of movement in the future.
- Conduct a final security audit to ensure all vulnerabilities have been addressed and/or patched and the environment is secure.
- Once a confirmed clean backup copy is available, push backups and document any discrepancies in file names or extensions.
CISO Postmortem
- Review your cyber liability insurance policy to understand your coverage for costs associated with the attack, including legal fees, forensic investigations, and any regulatory fines.
- If you have one, use your cyber insurance firm's panel of pre-approved experts for support with legal counsel and forensics.
- Review and update security policies (as appropriate) to reflect the attack and any new policies or recommendations.
- With the IR lead, conduct a blameless post-mortem analysis to identify the root cause of the breach and evaluate the effectiveness of your incident response.
- Enhance monitoring and detection capabilities as needed to prevent similar attacks from going undetected.
- Work with HR to update any onboard/offboarding processes and procedures as needed.
- Work with HR to provide support and resources for employees who may be experiencing stress or burnout from the incident.
- Update emergency contacts in your incident response plan, including internal teams and external stakeholders.
- Update your crisis comms plans with contingencies or lessons learned from the engagement.
- Update security awareness training with specific examples from the attack.
- Reinforce the security culture by celebrating employees who reported suspicious activity, or who put in extra hours to facilitate recover.
CISO post review with CFO or board review
- (If appropriate) Formalize relationships with third-party vendors who assisted during the breach.
- Assess the damage and determine the financial loss caused by the attack.
- Analyze the attack's financial impact to inform future budget requests for security.
- Brief employees on what happened and how to reinforce security best practices, using anonymized scenarios from the incident as a learning story.
- Update your incident response playbook, crisis comms plans, etc. to incorporate lessons learned from the incident.
- Implement a continuous improvement program for your security posture.