错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

We’ve Had an Incident

  • Dan Weis

摘要

At this stage, you should be fully prepared for a cyber event; you have your documented incident response plan in place, it’s been tested, and you know it works. You have implemented policies and procedures, adopted various security frameworks, and implemented technical controls; you have your due diligence covered, and you have a SOC in place monitoring the environment. But they still got in. It happens; sometimes emails manage to get through, sometimes the user provided the access, maybe it was a malicious insider, or a previously unknown vulnerability was exploited to breach your network. It happens.