How NOT to f-up your security incident response
ID: de7cf78d-6732-5343-b47e-136f60d83926
STIX ID: report--de7cf78d-6732-5343-b47e-136f60d83926
Feed Name: The Register (Security)
This feature article outlines common incident response failures—such as confirmation bias, narrow scoping, rushing remediation, and poor evidence preservation—highlighted by an anonymized Fortune 1000 breach where initial access via SQL injection and directory traversal was misattributed. Experts from Microsoft, Mandiant, and CrowdStrike recommend disciplined scoping, creating timelines, preserving volatile data and logs, coordinating across vendors, maintaining a rehearsed IR plan and retainer, modernizing legacy systems, and rebuilding compromised hosts to prevent reinfection, with specific emphasis on the added complexity of ransomware and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
