Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

3/22/2019
02:30 PM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail

Inside Incident Response: 6 Key Tips to Keep in Mind

Experts share the prime window for detecting intruders, when to contact law enforcement, and what they wish they did differently after a breach.
3 of 7

Communication Control: Have a Plan in Place
The desire to be less transparent following a breach can backfire, said Code42 CISO Jadee Hanson, who was working in a security role at Target when it was hit with a massive breach in 2013. A lack of prepared communication is a common problem with incident response.
'The biggest thing I feel is very much overlooked is controlling communication and having a set communication in place if something terrible happens,' she explained. Target was hesitant to be fully transparent following the 2013 breach; as a result, people filled in the gaps on their own.
'There was a lot of speculation that wasn't real that ended up swirling out of control, to the point where we couldn't get back the story,' Hanson said. Companies are now much more transparent in disclosing security incidents and updating customers as they have more info. It's still a tricky process to navigate, though, especially in the immediate aftermath of a breach.
'Often when you're working with a breach, you're dealing with partial information,' Hanson noted. Getting a C-level executive to say 'I don't know' and maintain credibility is a delicate balance.
(Image: Rawpixel.com - stock.adobe.com)

Communication Control: Have a Plan in Place

The desire to be less transparent following a breach can backfire, said Code42 CISO Jadee Hanson, who was working in a security role at Target when it was hit with a massive breach in 2013. A lack of prepared communication is a common problem with incident response.

"The biggest thing I feel is very much overlooked is controlling communication and having a set communication in place if something terrible happens," she explained. Target was hesitant to be fully transparent following the 2013 breach; as a result, people filled in the gaps on their own.

"There was a lot of speculation that wasn't real that ended up swirling out of control, to the point where we couldn't get back the story," Hanson said. Companies are now much more transparent in disclosing security incidents and updating customers as they have more info. It's still a tricky process to navigate, though, especially in the immediate aftermath of a breach.

"Often when you're working with a breach, you're dealing with partial information," Hanson noted. Getting a C-level executive to say "I don't know" and maintain credibility is a delicate balance.

(Image: Rawpixel.com stock.adobe.com)

3 of 7
Comment  | 
Print  | 
Comments
Threaded  |  Newest First  |  Oldest First
CharlieDoesThings
50%
50%
CharlieDoesThings,
User Rank: Apprentice
3/25/2019 | 10:22:21 AM
6 more tips I could use
Well done with the post, I really enjoyed the tips.
StephenGiderson
50%
50%
StephenGiderson,
User Rank: Strategist
4/26/2019 | 1:16:33 AM
Who should we help?
OF course bigger businesses are going to be better prepared when it comes to disaster and external attacks. But they are also more than capable of affording the ramifications of such a situation whereas the smaller guys will struggle. So who really needs the help?
AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14540
PUBLISHED: 2019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
CVE-2019-16332
PUBLISHED: 2019-09-15
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
CVE-2019-16333
PUBLISHED: 2019-09-15
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
CVE-2019-16334
PUBLISHED: 2019-09-15
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.
CVE-2019-16335
PUBLISHED: 2019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.