With major cyber attacks making headlines and becoming an increasingly serious business risk, Jibba Jabba founder Ash Harris explains why every organisation should have a clear incident response plan in place before the worst happens.

A key question businesses need to ask themselves about cyber security is changing.

It’s no longer simply: What are we doing to prevent an attack? Increasingly, it also needs to be: What are we going to do if one happens?

That distinction is important because there is no such thing as perfect cyber security. You can invest in good technology, train your staff and put sensible protections in place, but every organisation still carries an element of risk.

What matters is whether, if you wake up tomorrow morning to discover you’ve suffered a cyber incident, everybody knows what happens next. IE, do you have a  Cyber Incident Response Plan in place? 

The National Cyber Security Centre recommends organisations have a response plan setting out how an incident will be managed. It should establish who takes responsibility, who needs to be contacted and how the business will contain, remediate and recover from an attack.

The recent cyber attack affecting Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, is a very high-profile reminder of why this matters.

The breach involved customer information connected with services including car parking, airport lounges, FastTrack and airport Wi-Fi registrations. Information affected included email addresses, telephone numbers, postcodes and vehicle registration numbers. No bank or payment details were held within the compromised system.

What particularly stood out to me was that the compromised information included details associated with future bookings.

If somebody has access to information about future travel arrangements alongside names, contact information, postcodes and vehicle details, you have to think about the ways that data could potentially be combined and exploited. With AI making it increasingly quick to analyse large quantities of information, organisations need to consider not only what data has been taken, but what somebody could potentially do with it.

For businesses, the lesson isn’t that every cyber incident will look like MAG’s. It is that you need to be prepared for your own version of one.

SO, WHAT SHOULD YOUR PLAN CONTAIN?

Start with preparation and responsibilities. Somebody senior needs to take ownership of the response, whether that is a director, IT manager or another nominated person. You should also maintain an up-to-date list of key contacts, including your IT provider, cyber insurer and legal adviser.

All of that information needs to be accessible if your usual IT systems aren’t. There isn’t much point having your emergency response plan sitting on a server you suddenly can’t access.

Backups are another essential consideration. Critical business information should be regularly backed up, with appropriate offline or immutable cloud backups separated from the production environment.

The next stage is detection and assessment. Staff need to know that suspected incidents, unusual activity, phishing, compromised accounts and security alerts should be reported immediately. Once something has happened, you need to establish what has been affected, when it started and whether the incident is still ongoing.

Evidence also matters. Logs, emails, security alerts and screenshots can all be important when establishing what happened, so businesses should avoid immediately wiping compromised equipment before appropriate evidence has been preserved.

Then comes containment and remediation. That could involve isolating affected devices, securing compromised accounts, revoking sessions and tokens, removing malware or malicious access, patching vulnerabilities and correcting configuration problems.

But recovery isn’t simply about getting everything switched back on. You need to be confident that the vulnerability has been addressed and that any data being restored comes from a clean backup.

There are regulatory responsibilities to consider too. Where a personal data breach is likely to result in a risk to people’s rights and freedoms, organisations must assess whether it needs reporting to the Information Commissioner’s Office. Qualifying breaches must be reported, where feasible, within 72 hours of becoming aware of them. Depending on the incident, you may also need to notify affected individuals, insurers, customers, suppliers, regulators or law enforcement.

Finally, once the immediate crisis is over, document what happened and learn from it. Record the decisions made, actions taken, identify the root cause and update the response plan accordingly.

A PERSONAL NOTE

This is an area where my own job has changed massively. IT used to be something that largely happened in the server room, but cyber is now very much a boardroom issue. In fact, I’d now estimate 80 to 90 per cent of my time with clients is focused on compliance, governance and demonstrating that appropriate controls are actually in place.

We’re seeing those expectations coming from regulators, insurers, customers and supply chains. It isn’t enough anymore to say, “Yes, we do that.” Businesses increasingly need documentation showing what they do, when it was reviewed and evidence that the required actions have actually taken place. That can mean maintaining version-controlled policies, recording regular reviews and retaining evidence of checks being completed.

A Cyber Incident Response Plan shouldn’t therefore be a document somebody writes once and forgets about. It needs to be accessible, understood, reviewed and tested.

Because the worst possible time to decide who is responsible, who needs calling and what you should do next is after the attack has already happened.

Need expert IT & cyber security support? Call 0114 303 7130 or head to jibbajabba.co.uk for more information on keeping your business protected.

You May Also Like