๐ง๐ต๐ฒ ๐๐๐บ๐ฎ๐ป ๐๐ผ๐๐ ๐ผ๐ณ ๐๐ฟ๐ถ๐๐ถ๐ ๐ฅ๐ฒ๐๐ฝ๐ผ๐ป๐๐ฒ - Revamp and Revise your Incident Response Plan (pt 1)
- midoriconnolly
- Jan 12, 2024
- 1 min read

A few weeks ago, I participated in a tabletop exercise at the MM-ISAC conference that simulated a major security incident. While the exercise was valuable, it highlighted a crucial gap in many incident response plans (IRPs):ย ๐๐ต๐ฒ ๐ต๐๐บ๐ฎ๐ป ๐ฐ๐ผ๐๐.
We swapped stories about war room experiences, fueled by energy drinks and chips, with people sleeping on office floors and missing family time. Sadly, one participant mentioned a recent incident triggering an attempted employee suicide.
This is unacceptable. ๐๐ฟ๐ถ๐๐ถ๐ ๐ฐ๐ผ๐๐ป๐๐ฒ๐น๐ผ๐ฟ๐ ๐๐ต๐ผ๐๐น๐ฑ ๐ฏ๐ฒ ๐ฟ๐ฒ๐ฎ๐ฑ๐ถ๐น๐ ๐ฎ๐๐ฎ๐ถ๐น๐ฎ๐ฏ๐น๐ฒ ๐๐ผ ๐๐๐ฝ๐ฝ๐ผ๐ฟ๐ ๐๐ต๐ฒ ๐๐ฟ๐ถ๐๐ถ๐ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐บ๐ฒ๐ป๐ ๐ง๐ฒ๐ฎ๐บ (๐๐ ๐ง) ๐ฎ๐ป๐ฑ ๐ฎ๐น๐น ๐ฎ๐ณ๐ณ๐ฒ๐ฐ๐๐ฒ๐ฑ ๐ฒ๐บ๐ฝ๐น๐ผ๐๐ฒ๐ฒ๐, ๐ฏ๐ผ๐๐ต ๐ฑ๐๐ฟ๐ถ๐ป๐ด ๐ฎ๐ป๐ฑ ๐ฎ๐ณ๐๐ฒ๐ฟ ๐๐ต๐ฒ ๐ถ๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐. IRPs must also include clear scheduling guidelines with mandatory breaks and rest periods for CMT members.
๐๐บ๐ฒ๐ฟ๐ด๐ฒ๐ป๐ฐ๐ ๐ฟ๐ฒ๐๐ฝ๐ผ๐ป๐๐ฒ ๐๐ฒ๐ฎ๐บ๐ ๐ฎ๐น๐ฟ๐ฒ๐ฎ๐ฑ๐ ๐ฝ๐ฟ๐ถ๐ผ๐ฟ๐ถ๐๐ถ๐๐ฒ ๐๐ต๐ฒ ๐๐ฒ๐น๐น-๐ฏ๐ฒ๐ถ๐ป๐ด ๐ผ๐ณ ๐๐ต๐ฒ๐ถ๐ฟ ๐ผ๐ฝ๐ฒ๐ฟ๐ฎ๐๐ผ๐ฟ๐.ย As the security industry matures, we need to extend this respect to our front-line cybersecurity defenders. In a climate where anxiety disorders are rising among young workers (63% increase*), IRPs must prioritize the mental health of the CMT and all impacted employees.
Let's build a more resilient and humane security industry. Let's ensure IRPs acknowledge and address the human cost of crisis response.
*๐๐บ๐ฅ๐ฆ, ๐. ๐. ๐. &. ๐. (2023, ๐๐ค๐ต๐ฐ๐ฃ๐ฆ๐ณ 30). ๐๐ฉ๐ฆ ๐๐ช๐ด๐ฆ ๐ฐ๐ง ๐๐ฏ๐น๐ช๐ฆ๐ต๐บ ๐ข๐ฏ๐ฅ ๐๐ฆ๐ฑ๐ณ๐ฆ๐ด๐ด๐ช๐ฐ๐ฏ ๐ข๐ฎ๐ฐ๐ฏ๐จ ๐ ๐ฐ๐ถ๐ฏ๐จ ๐๐ฅ๐ถ๐ญ๐ต๐ด ๐ช๐ฏ ๐ต๐ฉ๐ฆ ๐๐ฏ๐ช๐ต๐ฆ๐ฅ ๐๐ต๐ข๐ต๐ฆ๐ด - ๐๐ข๐ญ๐ญ๐ข๐ณ๐ฅ ๐๐ณ๐ช๐ฆ๐ง. ๐๐ข๐ญ๐ญ๐ข๐ณ๐ฅ ๐๐ณ๐ช๐ฆ๐ง. ๐ฉ๐ต๐ต๐ฑ๐ด://๐ฃ๐ข๐ญ๐ญ๐ข๐ณ๐ฅ๐ฃ๐ณ๐ช๐ฆ๐ง.๐ฃ๐บ๐ถ.๐ฆ๐ฅ๐ถ/๐ช๐ด๐ด๐ถ๐ฆ-๐ฃ๐ณ๐ช๐ฆ๐ง๐ด/๐ต๐ฉ๐ฆ-๐ณ๐ช๐ด๐ฆ-๐ฐ๐ง-๐ข๐ฏ๐น๐ช๐ฆ๐ต๐บ-๐ข๐ฏ๐ฅ-๐ฅ๐ฆ๐ฑ๐ณ๐ฆ๐ด๐ด๐ช๐ฐ๐ฏ-๐ข๐ฎ๐ฐ๐ฏ๐จ-๐บ๐ฐ๐ถ๐ฏ๐จ-๐ข๐ฅ๐ถ๐ญ๐ต๐ด-๐ช๐ฏ-๐ต๐ฉ๐ฆ-๐ถ๐ฏ๐ช๐ต๐ฆ๐ฅ-๐ด๐ต๐ข๐ต๐ฆ๐ด
Comments