Cyber Security
CISO Podcast: Manipulator or Listener
Navigating Emotional Intelligence in Cyber Security
Editorial
Until it leads you to the point of getting a punch in the face : Guest Author, Stuart Seymour
So here are the times in incident and crisis management when I have had a punch to the face and, of course, what I learned.
But before that, an analogy. Whenever I keynote on crisis management, I compare the event to a hydra. As the event progresses, new heads of the hydra form due to unforeseen circumstances such as what the company says in the media, what employees say on social media, how the executive might react and so on. This is over and above the main head itself, which is of course the incident. As the incident lead, it is critical that you are mindful of all of these potential hydra heads and that they are cut before they outgrow the incident itself.
At the very root of Tysonian philosophy is that, in essence, plans change; indeed. In the Army, we used to say that no plan survives contact, and so it is critical to be adaptable. In the majority of the major cybersecurity incidents I have been involved in, our original (nailed-on and certain) hypothesis never ended up being what we thought as more data became available.
Adaptability is critical, as is language and temperament. Your job is to prove or disprove. To deal only in fact. There should be no adjectives in any report writing. Any hypothesis dressed in categorical terms (and which inevitably changes) will lead to a loss of trust and even create another crisis of its own. Or another head to the Hydra.
The first building block to incident management has to be tried and tested processes and plans. That are rehearsed. And rehearsed. At all levels of the organisation, including senior management. It was not raining when Noah built the Ark. Cyber Crisis Management exercises have to be achievable and realistic.
The first hours of the incident are critical. Sadly, in my experience, a lot of time is often wasted in trying to apportion blame (or trying to) rabbit holes, “why didn’t we…..” The answer, simply put, is we didn’t. And now we have a fire. And we need to put it out. Leave the why to the lessons learned. And if the Director of hindsight manages to make their way into the room – get rid of them.
I learned the following from a friend in SEAL Team Six. When confronted with a problem, they would often say: “Good (acknowledges the problem positively), what’s next (forward-looking to problem-solve)”
Once this mindset is established and the right teams are where they need to be, incident management can begin.
From experience, during an incident you should focus on the kill chain and its stages. There are two specific aspects which I always try and look out for (and which, once blocked and mitigated, will mitigate most of the attack). Lateral movement and Command and Control (C2).
Once detected, the focus has to be on containment and eradication, but be careful – there is a punch to the face coming. You must understand your systems, what part of the business they serve and their level of criticality. In shutting down a server or blocking x DNS, you might inadvertently do more harm than the attack itself.
After containment and eradication, you are into the recovery phase. Again, testing here is critical. Business Impact Analyses are not the same as business continuity plans, and these are no good if they have not been tested or put through a disaster recovery process.
Now all of this is all well and good and contained with the singular – though rather sizable original head of the hydra – but there are others, and this is where cyber incident management dovetails into Crisis Management. This is where the rehearsed crisis management plan with its clear escalation criteria comes into play.
Once you are in crisis management territory, the focus shifts away from the technical incident to legal risk management and communications. And here comes another punch to the face. In terms of legal risk management, it is critical to bring your legal team in as early as possible. The incident must now be driven at their direction. The problem must be understood in lay terms and not communicated in IT speak.
In terms of communications, internal should, as a rule, be the same as external. And must be limited to facts. Without conjecture or supposition, or as I mentioned above, adjectives. The relevant executives must be briefed so that they are on the same page. Further, there must be a singular source of truth that all are party to. There are many incidents I recall where the CEO was getting 11:00 hrs news at 11:00 but then also 0930Hrs news at 11:00 as folk cannot resist their moment in the sun. A lot of this can of course, be ironed out via exercising.
And finally, lessons learned from an incident must be held – in a psychologically safe place. And definitely without the aforementioned Director of Hindsight and their pal, the Director of Well, We Should Have. Learnings must lead to a concrete action and remediation plan, and of course feed into the incident and crisis management plans themselves.
Coming back to Iron Mike, being in an incident is not too dissimilar to being in the ring. Look after your team. Ensure that alternates are planned well in advance. That families are looked after and that different aspects are considered (childcare, food, accommodation, rest, logistics, to name a few).
And if you get punched in the face, learn from it and share the experience with others so that they are not knocked out in the first round.
1. Plan and rehearse
2. No plan survives contact, and very few hypotheses stay as true at the start as at the end of the
incident.
3. Deal only in facts
4. Don’t look back – look forward positively, ready to solve
5. Think kill chain to prove or disprove. Focus on C2 and Lateral movement
6. Think of the other Hydra's heads
7. Learn – without judgement, nor as the Director of Hindsight
8. Look after your team
Cyber Security
Navigating Emotional Intelligence in Cyber Security
Cyber Security
Mind the Gap... Between Cybersecurity and Regulation
Cyber Security
Sovereignty and Resilience on a Geopolitical Scale
Cyber Security
What great PR can do at times of crisis
Cyber Security
AI in security - hype cycle or real-time game changer?
Cyber Security
What will it take to tackle AI-Driven threats?
Cyber Security
Considering culture change and perspective from Guest Author, James Moncrieff
Cyber Security
Why we overlook its importance in the security puzzle: Guest Author Malcolm Portelli