Skip to main content
Language Translation
  Close Menu

Respond is the fourth function of NIST. Respond deals with responding in the likely event, 29.6% chance (“Cost of a Data Breach Report 2019”, IBM Security/Ponemon) of a cyberattack. The two questions dealing with this category are based on knowing that the protections you have in place for your organization will never be perfect. Therefore, when a cyberattack does happen, know that how you handle the response can make or break the outcome for your organization, both financially and public perception. It is very important to remember that a timely response is imperative in case of a cybersecurity incident. Any delay can create additional opportunities for cyber criminals to continue inflicting harm to your organization. The articles that we have can help you “level up” the plan you already have. They can also serve as templates so that you can create a plan unique to your organization.

Low – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Low to Medium will be to 1) Develop a cyber incident response plan that includes key company stakeholder input and the who, what, when, where, why, and how your organization will execute your response, 2) Develop both internal communication flows during the response, and multiple external public relations (PR) statements for multiple scenarios, 3) Analyze the attack to determine how it affected the business, assess the damage, understand the scope of the attack to know how to stop it, and begin cyber forensics measures, and 4) Determine which internal team or external service provider has the ability to remove all traces of the threat from your entire organization.

The following are additional resources to help you level up your game from Low to Medium:

Medium – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Medium to High will be to 1) Develop a cyber incident response plan that includes key company stakeholder input, local law enforcement, legal, and the who, what, when, where, why, and how your organization will execute your response, 2) Develop both internal communication flows during the response, and multiple external public relations (PR) statements that takes into consideration multiple types of cyberattacks, 3) Analyze the attack to determine how it affected the business, assess the damage, spending sufficient time and expertise on understanding the root cause of the attack to know how to stop it & not cause re-infection, and begin cyber forensics measures, and 4) Determine which internal team or external service provider has the ability to remove all traces of the threat from your entire organization.

The following are additional resources to help you level up your game from Medium to High:

High – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score and keep it at High will be to 1) Conduct and keep current a complete risk assessment of your organization to ensure you are refining the cyber incident response plan to include new risks to critical areas and refine your response execution to ensure you are following best practices such as NIST Guide for Cybersecurity Event Recovery (Special Publication 800-184), 2) Refine internal communication flows during the response, including both plans detailing how the entire organization assists with response efforts utilizing out-of-band communications, and a prepared incident log book, 3) Refine your attack analysis to include new business threats, that will determine how it affected the business, assess the damage, spending sufficient time and expertise on understanding the root cause of the attack to know how to stop it & not cause re-infection, and begin cyber forensics measures, and 4) Ensure you include all Service Level Agreement(s) that can be added to your internal team or external service provider that will remove all traces of the threat from your entire organization.

The following are additional resources to help you level up your game and keep it at High: