top of page

Essentials for Cyber Incident Response

Phishing - the hackers favourite type of cyber attack

Many cyber incidents involve network infiltration but do not always result in a data breaches or ransomware - they may be exploratory exercises designed to assess the likely value of a target.  Nevertheless, defences have breached and malicious code or files may be left on the the network, waiting for the right moment to attack - which means remedial action must be taken in line with the steps outlined below

1. Identification & Scale

The process begins by understanding the nature and scope of the intrusion. suspicions are often raised by unusual log activity, unauthorised privilege escalations, or unexpected outbound connections. Initial analysis involves log analysis across the network, Intrusion Detection Systems (IDS) alerts, and and other telemetry to confirm the existence of a threat and construct a timeline of  movements and identify compromised assets and accounts

2. Isolate and Contain

Once the infiltration path is confirmed and understood, the immediate priority is to stop further lateral movement and sever any command-and-control communication channels being used by the attacker Security teams, disable compromised user accounts, and terminate active unauthorised sessions. Live system memory and disk images should be captured.to preserve forensic evidence and post-recovery review

Out-of-band communication networks should be iused to prevent the attacker from monitoring and countering remediation efforts

3. Eradication and Environmental Hardening

When the root cause and associated mechanisms are confirmed, eradication efforts can be started. 

  • hunting for and deleting malicious tools, toolkits and backdoors.

  • Enterprise-wide reset of administrative passwords ety. .

  • Vulnerabilities patched

  • Confirm integrity of back-ups

4. Recovery and Operational Verification

Systems can now be safely returned to "business as usual" operation. This phase concentrates on secure system verification rather than long database restorations:

  • If system files were altered, rebuild affected servers and device configurations from known-clean baseline images.

  • Initiate advanced logging and continuous monitoring to watch for any signs of malware persistence or re-entry attempts by the attacker 

  • Maintain vigilance over network operation and traffic

5. Post-Incident Analysis

Conduct a formal lessons-learned evaluation. The incident response team reviews why initial defences failed and schedules changes required for improved  detection. Update documentation  to refine incident response plans, and adjust security controls if required, 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page