Information Technology (IT) Incident Response Plan
It is best for every business to plan for the unexpected. This includes planning for a data breach, that is, the potential loss, theft or corruption of company and customer data from your business. A data breach can hurt your brand, customer confidence, reputation and, ultimately, your business. Knowing what data security regulations affect your business and assessing your company data security gaps can help provide a foundation or starting point for building a data breach/incident response plan.
Early detection of a data breach is a key benefit of an effective incident response plan. Without an incident response plan, an organization may not be in the best position to minimize or contain a data breach/incident, the damage it may cause, eradicate the attacker’s presence and recover in a secure fashion. In fact, without an effective plan, the attacker may have a far greater impact than the initial breach/incident, causing more damage, infecting more company systems and networks, and compromising or stealing more data than would otherwise have been possible had an effective incident response plan been in place.
An effective plan also can help companies comply with state and federal laws and regulations for data breach reporting, response and notification requirements and make it easier to launch a rapid and coordinated response aligned with legal requirements in the event of any loss or theft of data.
Before a breach – strategic planning
Establish a framework for incident response
An effective incident response plan can provide a framework for action so that key decisions are in place ahead of a data breach incident and are not made when everyone is under pressure and the situation is changing rapidly. Determine if your organization has the skills, resources and time to investigate to quantify and recover from an incident. An important part of your incident response plan is to consider in advance which types of incidents you can handle yourself and which types you cannot. Your framework should include incident response procedures, identification of the phases of incident handling, and roles and responsibilities of personnel for handling incidents. Framework considerations include, but are not limited to:
- Designating an incident team who will participate in the incident response. Consider including representatives from management, information technology (IT), legal, public affairs/media relations, risk management, finance, and audit departments (and possibly Human Resources, for internal incidents). The team may include:
- A senior level manager, such as the Chief Information Security Officer, or a designee, to serve as the incident team leader to help coordinate multiple organizational units and the overall incident response.
-
-
An external “breach coach” or attorney experienced in security and privacy compliance issues to assist in managing a data breach/incident. The “breach coach” can assist with gathering facts to develop the communication strategy surrounding the incident. In addition, the "breach coach" can assist with documenting expenses such as time spent recovering and estimates for overall cost of remediation. These details may be important to help re-secure a company's data network, refine the internal and external communication plan, identify the full extent and nature of damages, and serve as evidence if the data breach results in a legal battle. Your insurance agent may be able to connect your business with an experienced breach coach to help your company recover from an event.
-
Individuals who will support the incident handling process and key decision-making role of the team leader and/or “breach coach.” Typically, these individuals have IT or network technical knowledge and business operations knowledge.
-
The proper handling of digital evidence can be an important facet of an incident response. Lack of knowledge in this area can interfere with law enforcement or compliance investigations down the road. It also can destroy critical evidence that could have been used in understanding the incident or against the attacker.
-
Designate and authorize a crisis management/communication spokesperson, generally the incident team lead or someone who handles public affairs/media relations, to represent the company and communicate breach details to others, including law enforcement. This should be done in concert with executive leadership and legal counsel.
-
-
Assemble and maintain third-party contact information. Develop procedures that specify when you will require outside assistance from third parties such as, service providers, local or federal law enforcement, regulators or a private consulting firm specializing in forensic investigation.
- An important part of your incident response plan should be to define which types of incidents you can handle yourself and which types you cannot. Although IT personnel are skilled in data security, unless they are specifically trained to conduct forensic investigations of data compromises, it may be necessary to contract with a third party that specializes in digital forensic and data breach to help quantify what information has been breached and to secure the digital evidence.
- Develop incident handling procedures, a strategy for deciding on the course of action in a given situation, and procedures for communicating with organizational leadership and outside parties/law enforcement/regulators.
- Incidents classified as a low priority rating may be handled directly with the affected device and may not require any further escalation.
- Incidents classified as a high priority (such as a suspected loss of sensitive information) will initiate the implementation of your breach response plan and third-party assistance.
- Test and update breach response procedures periodically in conjunction with other business continuity and disaster recovery procedures to confirm their effectiveness and identify areas for improvement.
Post incident notification procedures
Post incident notification procedures for all personnel, including employees and contractors, which provide guidance and instructions on how to identify and report computer anomalies and incidents to the incident handling team. Such information should be included in new hire orientation and routine employee awareness activities. All employees and contractors should be aware of your incident notification procedures and understand their role in immediately reporting any loss or theft of information. Because data privacy and breach laws can be very broad and strict, any unaccounted data loss may constitute a data breach, even a loss where an employee simply does not remember where he left a backup tape. Any such data loss or misplacement could constitute a data breach and you should act accordingly.
When a breach occurs – incident response
Once your company becomes aware that an incident or a breach has occurred, technical personnel and business decision makers should work together to decide on the most practical and effective containment plan. Containment plans will vary from one set of circumstances to the next. They may quickly become intensive in terms of time and resources from both the technological and business impact perspectives. In any case, the containment of data breaches should be focused on determining the extent of the compromise and preserving the confidentiality and integrity of sensitive data that has not yet been stolen or disclosed. Activities and decisions made during this time are not necessarily linear. Some response activities may happen concurrently. Considerations should be adapted to meet security needs and legal requirements specific to your company. Seek legal counsel when planning for and responding to a data breach to help ensure compliance with applicable federal, state and local laws and regulations. Risk management considerations include, but are not limited to:
Validate the data breach
Begin by validating the data breach. Do not assume that every identified incident is actually a breach of sensitive information. Examine the initial information and available logs to confirm that a breach has occurred. If possible, identify the type of information disclosed and estimate the method of disclosure (internal/external disclosure, malicious attack or accidental).
Assemble the incident team and begin the investigation
Once a breach has been validated, the incident lead should assemble the incident response team, including the communications spokesperson. Decide how to investigate the data breach to ensure that the investigative evidence is appropriately handled and preserved.
- Determine the status of the breach (on-going, active, or post breach). If the breach is active or on-going, take action to prevent further data loss by securing and blocking unauthorized access to systems/data and preserve evidence for investigation.
- Determine the scope and composition of the breach. Identify the types of compromised data and affected parties.
Decide on outside help
Data breach investigations can be made using in-house resources or an outside service provider. The decision to involve outside entities, including law enforcement, is generally situation dependent and should be made in consultation with executive leadership and legal counsel.
Consult legal counsel to determine compliance with applicable federal, state, and local breach reporting and breach notification requirements and which additional authorities or entities, including law enforcement, must be notified in order to satisfy compliance requirements. If there is reason to believe or suspect that a crime has been committed, you may involve law enforcement in the investigation. If law enforcement is involved, collaborate with them to help ensure that in-house investigations do not interfere with law enforcement activities.
Take action to help mitigate the impact
Identify, quarantine and secure all affected data, machines, devices and systems. Disconnect the affected devices from the network, but do not move the data or try to remove the malware yet. The data and malware will be mirrored to a sandboxed device so a forensic analysis can be conducted. After the copy is made, recovery can begin.
Keep all logs for the affected system and network.
Disable access privileges, if needed. Change encryption keys and passwords immediately.
Address and/or mitigate the cause(s) of the data breach. Consider all alternatives to replacing or clearing compromised resources and machines, including the cost of remediation or rebuilding of the assets to an acceptable security level.
Clean the network of malicious code. Cleaning a network or system of all traces of malicious code can often entail having to completely wipe all storage media and perform a “clean install.” Recovery from such a breach may be resource intensive and require careful restoration of data from backups.
Record the measures taken to ensure against future exposure.
Coordinate the flow of information and manage public message about the breach.
Notify affected individuals
In the event of exposure of customer information, determine when and how to provide notification of the breach. Notify affected individuals as required by applicable federal, state and local laws. Consult with legal counsel when developing your approach for notification to ensure legal sufficiency.
Work closely with public affairs or media relations staff to craft the appropriate media notification.
Foster a cooperative relationship between the incident response team and data owners to help secure sensitive data, mitigate the damage that may arise from the breach, and determine the root cause(s) of the breach to devise mitigating strategies and prevent future occurrences.
If the breach represents a threat to affected individuals’ identity security, credit monitoring or identity theft protection services to mitigate the risk of negative consequences for those affected may be required.
Manage the evidence
Document all investigation and mitigation efforts for later analysis. Conduct interviews with key personnel and document facts.
Preserve (when possible) all evidence (backups, images, hardware, written and electronic logs and records) applicable to the breach for examination for later forensic examination. Safely store and record all evidence. Seek advice from your legal counsel on the approved methods for protecting digital evidence, so that you are prepared to properly preserve and document all evidence for use in a court of law, if necessary. Protecting digital evidence may require detailed collection, handling, storage, custody documentation, and destruction procedures (if applicable).
Conduct “lessons learned” and tests for continuous improvement
Maintain a breach report in accordance with regulatory standards and any other response documentation. Review breach reports, response activities and feedback from involved parties to help determine probable causes and response effectiveness.
A “lessons learned” meeting after the recovery phase to identify, document and refine the incident handling process is a good opportunity to assess your data security program and breach response strategy and to make enhancements and modifications to improve your ability to protect against and respond to cyber attacks and data compromise. Integrate lessons learned to avoid reoccurance of past breaches.
Throughout the year, assess gaps and evaluate the effectiveness of plans, procedures and staff training. Make improvements to help close gaps identified. Conduct periodic incident tests and scenario sessions for personnel associated with the incident handling team to ensure that they understand current threats and risks, as well as their responsibilities in supporting the incident handling team. Adjust plans as needed.
Incidents of data breaches, theft and compromise are reported every day throughout the globe. Hackers continually find ways to attack individual, company and government data. New tools and strategies to tighten data security continue to evolve. Stay current, test your plan often and stay aware of changing threats, loss and new tools and strategies to defend your company against data compromise and crime.