{"id":749,"date":"2019-09-27T16:41:02","date_gmt":"2019-09-27T16:41:02","guid":{"rendered":"https:\/\/www.sugarshot.io\/?p=749"},"modified":"2023-05-11T09:33:37","modified_gmt":"2023-05-11T09:33:37","slug":"how-to-build-an-incident-response-team-you-can-depend-on","status":"publish","type":"post","link":"https:\/\/www.sugarshot.io\/how-to-build-an-incident-response-team-you-can-depend-on\/","title":{"rendered":"How to Build an Incident Response Team You Can Depend On"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">If your network hasn\u2019t had a <\/span><a href=\"https:\/\/www.sugarshot.io\/services\/cyber-security-los-angeles\/\"><span style=\"font-weight: 400;\">cybersecurity threat<\/span><\/a><span style=\"font-weight: 400;\"> yet, it\u2019s only a matter of time before disaster strikes. If you\u2019ve had one (or more), you know how a cyber incident can cause complete and utter chaos.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">According to <\/span><span style=\"font-weight: 400;\">the<\/span> <a href=\"https:\/\/cybersecurityventures.com\/cybersecurity-almanac-2019\/\"><span style=\"font-weight: 400;\">Cisco\/Cybersecurity Ventures 2019 Cybersecurity Almanac<\/span><\/a><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">cyber attacks are the fastest growing crime globally, and they are increasing in size, sophistication and cost.<\/span> \u00a0 <span style=\"font-weight: 400;\">An incident response team is responsible for analyzing security breaches and taking reactive measures to minimize risk and damage.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">Putting together a solid incident response team takes careful consideration and planning \u2013 after all, the safety of your business depends on it. In this blog, we\u2019ll teach you how to build a successful incident response team to keep threats at bay.<\/span> \u00a0<\/p>\n<h2><span style=\"font-weight: 400;\">What Does an Incident Response Plan Consist Of?<\/span><\/h2>\n<p>\u00a0 <span style=\"font-weight: 400;\">An incident response plan can help you prepare for all types of events and mitigate risk. Without establishing frameworks, procedures and roles, chaos can ensue in an emergency.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">Time is of the essence when dealing with a cyberattack. As the old saying goes: fail to plan, plan to fail.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">According to the <\/span><a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-61r2.pdf\"><span style=\"font-weight: 400;\">National Institute of Standards and Technology<\/span><\/a><span style=\"font-weight: 400;\"> (NIST), establishing an incident response capability should include the following actions:\u00a0\u00a0<\/span> \u00a0<\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Create an incident response policy and plan\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Develop procedures for performing incident handling and reporting\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Set guidelines for communicating with outside parties regarding incidents\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Select a team structure and staffing model\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Establish relationships and lines of communication between the incident response team and other groups, both internal (e.g., legal department) and external (e.g., law enforcement agencies)\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Determine what services the incident response team should provide\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Staff and train the incident response team<\/span><\/li>\n<\/ul>\n<p>\u00a0 <span style=\"font-weight: 400;\">Whew \u2013 that sounds exhausting. It takes a dedicated group of educated IT professionals to put together an emergency plan for the best chances of success.\u00a0<\/span> \u00a0<\/p>\n<h2><span style=\"font-weight: 400;\">What Does an Incident Response Team Do?<\/span><\/h2>\n<p>\u00a0 <span style=\"font-weight: 400;\">An incident response team is the first line of defense against cyberattacks in an organization. They are the first responders when <\/span><span style=\"font-weight: 400;\">an attack occurs, <\/span><span style=\"font-weight: 400;\">analyzing security breaches and taking reactive measures to minimize risk and damage. <\/span><span style=\"font-weight: 400;\">If a data breach, network virus, system shutdown or other catastrophic IT event hits your business, they mobilize to stop the threat and get you operational \u2014 fast.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">Additionally, response teams stay on top of current trends and continually update and implement new procedures. Communicating with management and other stakeholders keeps everyone informed on changes to the plan and what to expect should a crisis occur.<\/span> \u00a0<\/p>\n<h2><span style=\"font-weight: 400;\">Incident Response Team Roles &amp; Responsibilities<\/span><\/h2>\n<p>\u00a0 <span style=\"font-weight: 400;\">Building a solid incident response team requires careful consideration, planning and resources.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">A strong IR team is composed of several different kinds of employees so that cross-functional support is achieved before, during and after a cyberattack. In other words, cyberattacks <\/span><strong>aren\u2019t <\/strong><span style=\"font-weight: 400;\">\u201cjust an IT problem.\u201d<\/span> \u00a0 <span style=\"font-weight: 400;\">In general, members of the team should have developed critical thinking and problem-solving skills in addition to the technical capabilities required for their role. General skills that are helpful in emergency response situations include programming, network administration, system administration and technical support.<\/span> \u00a0 <span style=\"font-weight: 400;\">In an ideal situation, your incident response team should include the following roles:<\/span> \u00a0<\/p>\n<ul>\n<li><span style=\"font-weight: 400;\"><strong>Team Manager:<\/strong> Team managers should be technically savvy and have excellent communication skills, since they interact with various roles and organization levels. They are responsible for overseeing the work and ensuring that procedures are performed properly during a crisis.<\/span><\/li>\n<li><span style=\"font-weight: 400;\"><strong>Technical Lead:<\/strong> The technical lead possesses strong technical skills and incident response experience. They assume final responsibility for the quality of the team\u2019s work.<\/span><\/li>\n<li><span style=\"font-weight: 400;\"><strong>Incident Lead:<\/strong> The incident lead coordinates activities, gathers information from other team members and ensures team members have the tools they need.<\/span><\/li>\n<li><span style=\"font-weight: 400;\"><strong>HR\/Legal Representative:<\/strong> Should an attack involve a company employee, these representatives provide legal recommendations and take appropriate action steps.<\/span><\/li>\n<li><span style=\"font-weight: 400;\"><strong>Communications Lead:<\/strong> The communications lead provides incident updates to other groups, stockholders, social media and the press as needed.<\/span><\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<h2><span style=\"font-weight: 400;\">Internal Vs. Outsourced Incident Response Teams\u00a0<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Now, we know what you\u2019re thinking \u2013 hiring a team that covers all of the above roles is pretty unattainable for the average business. And finding employees with the necessary expertise, availability and temperament to deal with emergencies isn\u2019t exactly easy.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">But there is another solution. Hiring a managed IT company to provide outsourced incident response services often comes at a fraction of the cost of hiring, training and maintaining a full in-house team.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">Here are some at-a-glance comparisons between internal and external IR teams:<\/span> \u00a0 <strong>24\/7\/365 Service:<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In House: No one wants to work the graveyard shift! You must employ knowledgeable, full-time employees to be available 24\/7, plus replacements.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Outsourced: Outsourced staff specialize in emergency procedures and have multiple team members to cover shifts.\u00a0<\/span><\/li>\n<\/ul>\n<p>\u00a0 <strong>Technical Expertise:<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In House: Team members must be continually trained to stay up-to-date on technology &amp; procedures.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Outsourced: External teams invest heavily in education and have deeper knowledge of intrusion detection, forensics and system vulnerabilities.<\/span><\/li>\n<\/ul>\n<p>\u00a0 <strong>Tools:<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In House: Internal staff can find necessary tools, but the learning curve can be steep and time-consuming in addition to regular IT duties.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Outsourced: Outsourced IR teams have invested in sophisticated tools (like digital forensics software), saving your company money and time by knowing which ones work best.<\/span><\/li>\n<\/ul>\n<p>\u00a0 <strong>Morale\/Stress on Staff:<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In House: You must select team members who can handle emergencies calmly to avoid burnout.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Outsourced: Team members have been chosen precisely for the ability to perform under pressure. Larger staff rotation eliminates burnout.<\/span><\/li>\n<\/ul>\n<p>\u00a0 <strong>Creating an Incident Response Plan (IRP):<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In House: Staff members who aren\u2019t experienced with creating an IRP may take much longer to design and implement one.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Outsourced: Incident response experts know what to do without \u201crecreating the wheel\u201d every time. They know what works and what doesn\u2019t.<\/span><\/li>\n<\/ul>\n<p>\u00a0 <strong>Cost:<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In House: Having a fully-staffed internal team may be prohibitively expensive for smaller organizations.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Outsourced: Outsourcing some or all of your IRT can save money, time and stress for existing IT staff.<\/span><\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<h2><span style=\"font-weight: 400;\">Hire an Incident Response Team You Can Count On<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">A byte of prevention is worth a terabyte of cure. While cyberattacks cannot be eliminated entirely, <\/span><a href=\"https:\/\/www.sugarshot.io\/the-small-business-cyber-security-checklist\/\"><span style=\"font-weight: 400;\">preventive activities<\/span><\/a><span style=\"font-weight: 400;\"> can reduce the number of cyber security incidents you face.\u00a0<\/span> \u00a0 <span style=\"font-weight: 400;\">You need an incident response team to detect incidents quickly, minimize loss, and restore your IT capabilities. Luckily, the burden of creating and maintaining such a team does not have to fall squarely on your shoulders.<\/span> \u00a0 <span style=\"font-weight: 400;\">With our help, you can protect your valuable business assets and data. SugarShot\u2019s <\/span><a href=\"https:\/\/www.sugarshot.io\/services\/incident-response-los-angeles\/\"><span style=\"font-weight: 400;\">incident response<\/span><\/a><span style=\"font-weight: 400;\"> and business continuity services include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Emergency on-site help<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Replacement IT services<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">System restoration<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Backup recovery<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Data loss recovery<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Hacking prevention &amp; response<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Detection Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Process improvement<\/span><\/li>\n<\/ul>\n<p>\u00a0 <span style=\"font-weight: 400;\">Want to learn more about how our incident response services can help put your mind at ease? <\/span><a href=\"https:\/\/www.sugarshot.io\/contact-us\/\"><span style=\"font-weight: 400;\">Contact us<\/span><\/a><span style=\"font-weight: 400;\"> today for a free, no-obligation conversation.\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"If your network hasn\u2019t had a cybersecurity threat yet, it\u2019s only a matter of time before disaster strikes. If you\u2019ve had one (or more), you know how a cyber incident can cause complete and utter chaos.\u00a0 \u00a0 According to the Cisco\/Cybersecurity Ventures 2019 Cybersecurity Almanac, cyber attacks are the fastest growing crime globally, and they [&hellip;]","protected":false},"author":2,"featured_media":751,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"footnotes":""},"categories":[6],"tags":[17,5],"class_list":["post-749","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-business-continuity","tag-cyber-security"],"_links":{"self":[{"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/posts\/749","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/comments?post=749"}],"version-history":[{"count":0,"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/posts\/749\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/media\/751"}],"wp:attachment":[{"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/media?parent=749"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/categories?post=749"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sugarshot.io\/api\/wp\/v2\/tags?post=749"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}