When We Call About a Security Incident
Most people picture a cybersecurity incident as a race against the clock.
In reality, by the time we call your organization’s Primary Contact, we’re usually no longer fighting the fire. We’re helping you decide how to reopen the building.
By that point, our team has already investigated the alert, taken steps to contain the threat and worked to stabilize the situation.
Our call isn’t about asking what we should do first. It’s about explaining what happened, what we’ve already done and what decisions still belong to your organization.
Not Every Security Alert Becomes a Leadership Call
Our security systems investigate suspicious activity every day. Most alerts never become security incidents.
For example, if we detect unusual sign-in activity, we may temporarily secure the account and contact the employee directly to verify what happened. If the activity is legitimate, we restore access and everyone gets back to work.
We involve your organization’s Primary Contact when we believe there is a reasonable possibility that someone outside your organization gained access to your systems or data.
That’s the point where the conversation shifts from helping one employee to protecting the business.
What Happens Before We Call
By the time we contact your Primary Contact, we’ve usually already completed the most time-sensitive work.
Every incident is different, but our initial priorities are generally the same:
- Contain the threat and prevent further damage.
- Secure affected accounts or devices.
- Contact the affected employee if needed.
- Determine whether the incident appears contained.
Our goal is to stabilize the situation first so our conversation with your leadership can focus on informed business decisions instead of reacting to an active emergency.
One of the easiest ways to reduce the stress of a security incident is to decide how your organization will respond before one occurs. Who should we call first? Who can make business decisions? Who will notify your cyber insurance provider if needed?
What We’ll Tell You
Our first conversation is intended to bring you up to speed.
We’ll explain:
- What type of incident we’re responding to.
- Which users or devices appear to be affected.
- When the activity appears to have started.
- When we detected it.
- What we’ve already done.
- What we know so far, and what we don’t know yet.
Not every answer is available immediately. It’s common for our understanding of an incident to evolve as we continue investigating. Our goal is to give you enough information to make good business decisions while we continue our work.
Moving From Response to Recovery
Once we’ve contained the immediate threat, the work changes.
Our focus shifts from stopping the incident to helping your organization recover from it. That’s where your business decisions become just as important as our technical ones.
Depending on the situation, we’ll discuss questions such as:
Should your cyber insurance carrier be notified?
Many cyber insurance providers prefer to be notified early, even if the incident doesn’t ultimately result in a claim.
Do you want a deeper investigation?
Containing an incident and restoring operations is different from determining exactly what happened.
Some organizations choose to authorize additional investigation to better understand what was accessed, how the incident occurred and whether any additional action is needed. This is typically where billable incident investigation begins.
Are you ready to restore normal operations?
Once we’re confident the threat has been contained, we’ll discuss restoring access, resetting passwords and getting employees back to work.
Our goal is to make sure your organization understands the situation before moving into recovery.
Don’t Wait Until Your First Incident
One of the easiest ways to reduce the stress of a security incident is to decide how your organization will respond before one occurs.
Who should we call first? Who can make business decisions? Who will notify your cyber insurance provider if needed?
If you’re already a Hungerford Technology client, take a moment to verify that your Primary Contact and backup contact are up to date with us.
If you’re evaluating your organization’s incident response process for the first time, we’d be happy to help you think through those questions before they’re ever needed. Call us at (616) 949-4020 or contact us here.
Stay updated! Get tips and insights delivered to your inbox weekly by subscribing to our newsletter.
