enterprisesecuritymag

NOVEMBER 2022ENTERPRISE SECURITY| | 9possible scenarios on where the breach came from and how it is affecting core operational capabilities of the company; keep a log of the events; know your supervisory and statutory obligations in order to prepare a proper communication ­ to authorities, internally to management and employees and external ­ to customers, press and if needed - shareholders;FIRST COMES FIRSTThe first 24 hours is a game of priorities. As mentioned above, the initial surprise should be substitute in timely manner with rational assessment and analysis. In my opinion the first two vectors, that should be inspected, are: is it an outside attack or an inside job and then to determine the scope.If it is the first option then the most important question is: "Is it still ongoing? Are they now in our network/resources?" This is crucial for several reasons - if the illegal access is not over yet, you cannot trust your internal systems, which requires the inclusion of external resources for crisis management and also you may want to shut down parts or the whole system in order to avoid further damage. This can cause chaos within the organization and can heavily deteriorate the operations, which ultimately will lead to loses - so it's kind of a last resort.The internal attack or inside job is more welcome scenario due to the fact that if handled right it is more likely to close the case fast, with relatively low levels of damage and public focus. It is rare for employees to just want to hurt the company - in most cases such actions are justified by monetary incentive a.k.a. blackmail. The next big topic is how the event affects core operational capabilities of the company. If it doesn't - great. But if there is disruption, it is very important to create the necessary organization in order to respond and to strengthen communication channels - for example, if you cannot serve customers in physical offices, it is a good idea to provide additional staff for call centers and to try to compensate for the extra load to digital channels. You may also have to adopt temporary "war-time" customer service procedures because the "peace-time" one could be impossible to follow.Next is the initial game plan ­ high level tasks that aim to manage the crisis and/or to obtain additional information and facts on the origins and root causes. Short deadlines will help to keep the plan operative in nature and will enhanced the information flow among stakeholders, which will lead to coordinated efforts within the different domains of the organization.At this stage you should start preparing for regulatory communication. First of all, the circle of mandatory regulators and supervisors, that need to be notified, should be clear before the data breach. Typically, this includes sector supervisor authority /National bank, financial commission or other regulating legislative body/, law enforcement authorities /preferably cyber-crime units/ and the Data protection authority /DPA/, if you fall under GDPR scope. The latter implies taking additional step, namely a risk assessment on the impact of the breach to the rights and freedoms of natural persons involved, based on which management can take an informed decision on whether there is an obligatory requirement to notify the DPA. Data breach management under GDPR is a universe of its own and this article is not enough to develop the topic in appropriate detail, so I laid down only the basics. Based on the results of the above listed measures and in compliance with management decisions on how to manage the crisis, by the end of the first 24 hours you should be ready with initial PR and communication plan. This is given only if the breach is not already public knowledge - for example data dump on file exchange website. he earlier a plan is prepared and approved, the more time you will have to communicate it internally to managers and employees, conduct training if necessary, evaluate feedback, make changes if needed, arrange media coverage, etc.In conclusion, there is no one-size-fits-all solution for data breach management that you can read in a book or methodology and simply effortlessly apply. In order to be successful and effective in crisis management you need a tailored approach, which takes advantage of organization's strengths, while mitigating the adverse effects of the known weaker links. he possible attack vectors, the specifics of different companies, the various regulatory and supervisory regimes and requirements, the business considerations makes it hard to plan in detail so it is better to create a flexible framework, which takes into account the main domains and considerations and leave the rest to the talent of the team to demonstrate their problem solving capabilities. ESIN ORDER TO BE SUCCESSFUL AND EFFECTIVE IN CRISIS MANAGEMENT YOU NEED A TAILORED APPROACH, WHICH TAKES ADVANTAGE OF ORGANIZATION'S STRENGTHS, WHILE MITIGATING THE ADVERSE EFFECTS OF THE KNOWN WEAKER LINKS
< Page 8 | Page 10 >