Recover is the fifth and last function of NIST. As we have emphasized a proactive approach is very important, organizations must prepare for the possibility a cyberattack happens. Detecting and Responding is not enough, you will have to get everything impacted by the attack operating normally. All though there are many types of cyber attacks, the costliest cyberthreat is when a data breach occurs. If your organization stores any kind of personal information from users, clients, or employees, the organization is responsible to safeguard the data. Therefore, you need to plan both how you will Recover after different forms of cyberattacks, data breaches, etc…, and how your organization will use the lessons learned, throughout the incident, to improve your overall cybersecurity processes.
Low – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Low to Medium will be to 1) Utilize your physical and digital asset inventory developed in the Identify function to complete a cyber risk assessment (CRA) and business impact analysis (BIA) for your organization, to identify the critical data, services, and systems and their cyber interdependencies, which allows you to determine the order you recover critical services, 2) Determine how your organization will be cyber resilient during times of reduced capacity or when recovering over a period of time because only the most critical systems are available at the beginning, 3) Document the specific personnel, their emergency communications information, the steps involved during a restore from backups, and a comprehensive communications plan that will coordinate the entire effort.
The following are additional resources to help you level up your game from Low to Medium:
- Data Breach Response: A Guide for Business
- 20 Questions to Ask During a Real (or Manufactured) Security Crisis
Medium – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Medium to High will be to 1) Update your physical and digital asset inventory developed in the Identify function so you can update both the cyber risk assessment (CRA) and business impact analysis (BIA) for your organization, to ensure all critical data, services, systems, and their latest cyber interdependencies drive the order you recover critical services, 2) Determine how your organization will be cyber resilient during times of reduced capacity, alternate workspaces, replacement of physical assets are required, or when recovering over a period of time because only the most critical systems are available at the beginning, 3) Document the specific personnel, their roles and responsibilities during recovery, storage of backups offsite, sensitive data encryption and management, emergency communications information, the steps involved during a restore from backups, and a comprehensive communications plan that will coordinate the entire effort.
The following are additional resources to help you level up your game from Medium to High:
- Data Breach Response: A Guide for Business
- 20 Questions to Ask During a Real (or Manufactured) Security Crisis
High – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score and keep it at High will be to 1) Review documentation with not only those involved in the hands-on recovery, but also those in secondary roles to uncover gaps in skills, technology, or restoration capabilities to determine what needs improved, 2) Develop a plan that will test processes, procedures, skills, and real-world restoration abilities, 3) Test the organizations recovery plan to ensure all critical data, services, systems, and their latest cyber interdependencies, are brought back into proper operation, and 4) Document how the organization will better itself through lessons learned from cyberattacks with stronger protections, improved processes, and increased cyber resiliency throughout the entire organization.
The following are additional resources to help you level up your game and keep it at High: