Please do not leave this page until complete. This can take a few moments.
10. Isolate infected systems. Just as we had to quarantine for Covid infections, power down compromised endpoints to avoid spreading the contagion to other parts of the network.
9. System recovery. Create, review, and exercise a system recovery plan to ensure the restoration of services as part of a comprehensive disaster recovery strategy. This may involve using backups, reinstalling software, or patching vulnerabilities. Perform periodic testing and evaluate the backup plan. Test and test again.
8. Forensics. Assess the damage and root cause of the breach. Did a user click a bogus link or download a malware-laden file? Were credentials stolen by a successful phishing or social engineering scam?
7. Notify authorities. The federal government requires reporting of cybercrimes. Contact the local FBI, file a report with CISA (Cybersecurity and Infrastructure Security Agency): CISA exists to protect organizations from cyberattacks and respond to incidents. Report to FinCEN (Financial Crimes Enforcement Network), which receives reports of suspicious financial activity, including ransomware payments.
6. Patch systems. Apply all available software updates immediately. Automate the process as much as possible because threat actors create exploits soon after a patch is released. Use a reliable update service provided directly from the software vendor.
5. Prepare for emotional fallout. Cyber-attacks can cause feelings of distress, anger, guilt and fear among employees.
4. Change passwords. Suggest using a popular password manager to store and generate unique and complex passwords for every online account. Activate multi-factor authentication (MFA) options; these should default to being turned on but are not generally.
3. Train security awareness. Educate employees about the attack. This will help them to be more aware of the risks and to identify and report suspicious activity.
2. Review security policies. This may include deploying new security controls, increasing security monitoring, and conducting regular penetration tests both inside and out. Regularly test your incident response plan (IRP) to avoid chaos and confusion should an attack occur by performing tabletop exercises.
1. Engage experts. A cybersecurity expert can help the organization report and investigate the attack, develop a remediation plan, set up threat detection controls, test systems for weaknesses, set policies and procedures, and implement practical security measures.
Stay connected! Every business day, WBJ Daily Report will be delivered to your inbox by noon. It provides a daily update of the area’s most important business news.
Sign upWorcester Business Journal provides the top coverage of news, trends, data, politics and personalities of the Central Mass business community. Get the news and information you need from the award-winning writers at WBJ. Don’t miss out - subscribe today.
SubscribeWorcester Business Journal presents a special commemorative edition celebrating the 300th anniversary of the city of Worcester. This landmark publication covers the city and region’s rich history of growth and innovation.
See Digital EditionStay connected! Every business day, WBJ Daily Report will be delivered to your inbox by noon. It provides a daily update of the area’s most important business news.
Worcester Business Journal provides the top coverage of news, trends, data, politics and personalities of the Central Mass business community. Get the news and information you need from the award-winning writers at WBJ. Don’t miss out - subscribe today.
Worcester Business Journal presents a special commemorative edition celebrating the 300th anniversary of the city of Worcester. This landmark publication covers the city and region’s rich history of growth and innovation.
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
This website uses cookies to ensure you get the best experience on our website. Our privacy policy
To ensure the best experience on our website, articles cannot be read without allowing cookies. Please allow cookies to continue reading. Our privacy policy
0 Comments