Top 10 Cyber Incident Pain Points
Top 10 Cyber Incident Pain Points
History reveals both the good and bad when it comes to organizations dealing with cyber incidents. Among these revelations is the
overwhelming fact that vulnerabilities will always be present, but its how organizations respond to incidents when these vulnerabilities
are exploited that determines their fate. Regardless of how many security controls are placed on a network and the components that
go into making a network operate, there will always be vulnerabilities in a connected world. So, what do you do in an environment that
allows for such risk of compromise? One of the best methods of protecting organizations is by ensuring that response capabilities are
effective and efficient, and one of the most valuable steps in strengthening a response capability is learning from others experiences.
The following whitepaper discusses the pain points that organizations grapple with when responding to incidents, and how they can
address them.
Delta Risk has gathered this data from our own analysis of real world events, observations, and findings by facilitating many cyberbased exercises and conducting penetration testing in support of various commercial and federal entities. Through our interactions
with these organizations, we have identified 10 trends common to most of them.
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
Limited data classification guidance to help determine severity and guide incident response activities
Ill-defined processes (aka pre-thought use cases) for responding to high impact incidents
Lack of defined checklists or step-by-step procedures, including contact lists for response
Lack of consideration of the business impact when determining courses of action for response
Lack of defined thresholds between events and incidents to aid in decision making
10
Lack of training and exercise of memory muscle for the most likely or high risk incidents
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
10
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
11
Pain Points
LEVEL
Board, Management Team, Mid-level,
Management, Technical Staff
SIZE
Small (less than 50), Medium (more than
500), Large (more than 10,000)
COMPANIES
National, International, Multi-National,
Corporate, Business Unit
SECTORS
Energy, Technology, Finance/Insurance,
Healthcare, Government, Info Technology
EXERCISES
Workshops, Table Top Exercises,
Operational Exercises, National Level
Exercise, Quantum Dawn, Cyber Storm
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
12
Pain Points
2 Hrs
3 Hrs
1/2 Day
Full Day
DEPTH OF SCENARIO
Level of Planning Effort Realism
Off the
Shelf
Client
Specific
Tailored
PARTICIPANTS
Issue Identification
Single
Organization
Cross
Functional
Corporate
& BU
SCENARIO
Level of Issue Identification
Managers
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
Sr. Managers
C-Suite
Board
13
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
14
Summary
When considering the strength of an organizations cyber response capability, a strong focus on preparation is key. The steps to proper
preparation can be developed from the failures and successes of other organizations. With the backing of a wealth of experience from
conducting exercises throughout a wide variety of industries and organization sizes, the list of pain points provided gives insight into
voids that may be present within your organizations current cyber response capability. These and more pain points can be revealed
through a solid cyber security training and discovery program that involves a consistent and thorough exercise component.
2016 Delta Risk | Top 10 Cyber Incident Pain Points: Are You Prepared?
15
sadasd
Delta Risk LLC is a global provider of strategic advice, cybersecurity, and risk
management services to commercial and government clients. We believe that an
organizations approach to cybersecurity should be planned, managed, and executed
within a tailored and organization-specific program. We help guide organizations
to succeed in todays cyber environment by building on the people, processes, and
technology they already have.
http://www.delta-risk.net/
[email protected]