Every business wants to believe they’ll never fall victim to a cyber-attack. Unfortunately, many of them are wrong. And for small and mid-size businesses (SMBs) in particular, a breach can have severe, long-term consequences.
It’s not enough to secure your business against threats. You must prepare for the ones that manage to sneak past your defences. That’s exactly what this article will teach you to do.
What Is Incident Response in Cyber Security?
Traditional cyber security is focused on preventing an attack from ever taking place. While this is important, it’s only half the equation. Incident response is designed to deal with the threats your defences can’t stop.
Generally, this will involve:
- Detection: Identifying an attack in action
- Isolation: Containing the threat before it can spread further
- Eradication: Removing the threat from company systems
- Recovery: Healing from any damage that was caused during the attack
- Remediation: Updating security practices to ensure it doesn’t happen again
With a cyber security incident response plan, a breach may take a matter of hours to address. Without it, you could be looking at days of downtime, millions in financial losses, and severe reputational harm.
The Core Components of a Cyber Security Incident Response Plan
Preparation
Preparation is the foundation your entire plan is built upon. Unfortunately, it’s also where Australian SMBs often underinvest. Effective preparation should include:
- Identifying the assets, systems, and data that are most critical to your business
- Documenting your IT environment to define a baseline
- Assigning clear roles and responsibilities for incident response procedures
- Establishing relationships with external support resources, such as a managed security provider or legal counsel, before you need them
- Creating a set of reliable, tested data backups
- Training staff on how to recognise and report potential cyber security incidents
Detection
Next, you’ll need a way to reliably identify cyber incidents. This takes place in two steps. Stage one is discovering suspicious behaviour that might indicate a threat, using tools such as:
- Endpoint detection tools that monitor device activity
- Email security controls that flag phishing attempts and suspicious links
- Log monitoring that uncovers unusual access patterns or system changes
- Clear internal reporting channels so staff know how and where to raise concerns
Stage two is determining which anomalies actually represent a real cyber-attack, and which are false alarms. Typically, this is where human expertise (either in-house or outsourced) becomes necessary.
Isolation
Once a data breach is confirmed, your immediate priority should be to contain it. Upon gaining access, the first thing threat actors will try to do is move laterally across your IT infrastructure. This allows them to evade eradication attempts and cause more damage. If they obtain a password, for example, be prepared for them to try that same password on every account.
If you encounter a confirmed threat, do these things at once:
- Isolate affected systems from the network
- Disable compromised user accounts and reset credentials
- Block malicious traffic at the firewall or network level
- Preserve forensic evidence before taking any remediation steps that might overwrite it
Eradication and Recovery
After the attack has been successfully contained, you’ll need to carefully remove it from your systems. Your goal here is to identify the root cause (for instance, a compromised password), not just address the symptoms.
Unlike the previous step which happens quickly, this must be slow and methodical:
- Determine how the threat breached your systems
- Have your security team remove it (if you don’t have in-house security staff, you will need to outsource this)
- Verify that the threat has been removed from all systems, even those you don’t think were initially breached (remember that the attackers may have moved since the attack began)
- When you can confirm that your IT is safe, begin the process of restoring operations and data as needed
- Continue to monitor in the period immediately following restoration
If at any point you notice signs that the threat may still be present, stop and go back to step one of the eradication process. Do not attempt to restore data or operations if you’re not sure that the threat has been removed. This is where a third-party security expert can be highly valuable, as they have the knowledge and tools needed to properly verify this.
Remediation
Congratulations, you have survived the breach. But you’re not quite finished. The most important step is the post-mortem review. This is when you analyse what went wrong, how it could have been prevented, and what should be done from here on out.
Explore:
- How the attack began
- How the threat actors behaved during the breach (this information can help you close gaps that allow lateral movement to take place)
- How well the incident response plan played out (this is your opportunity to address any problems you noticed)
- How you will prevent this vulnerability from being exploited a second time
Common Mistakes Made by SMBs
Not every lesson needs to be learned the hard way. Here are some very common mistakes that SMBs make when building their incident response plans, so you can avoid them:
- No Plan for After-Hours Attacks: Threat actors don’t keep a 9-5 schedule. You need a strategy to prevent breaches that occur after your employees go home. This might involve partnering with a provider who offers 24/7 monitoring, or implementing software solutions that automatically block suspicious attempts.
- Untested Backups: Backups fail more often than you might expect, and too many businesses discover that this has happened during a real emergency. Regularly test backups to ensure that they were not corrupted and the restoration process works.
- No Security Expertise: Many of these steps can only be carried out correctly by a security expert. If you don’t have any on staff, then you’ll need to either hire them or outsource.
- Poor Staff Awareness: If employees don’t understand how to identify security breaches, you’re losing an important threat detection tool. Awareness training is a worthwhile investment.
Shield Sensitive Data and Preserve Your Financial Future
Strong defences are crucial, but they won’t stop every threat. To truly protect your business from financial losses, data erasure, and reputational damages, you need an incident response plan. Focus on building a strategy that addresses your most important needs first and removes threats effectively, and you’ll be prepared to handle even the worst incidents.
At Platform 24, security and compliance are our areas of expertise. We know what it takes to protect your business from harm, and we’re experienced in helping companies recover from security events. Get in touch if you’d like to learn more about how we can keep you safe.