"Preparation is everything" (see reference 1 below). If you have done the proper preparation up front, avoiding or recovering from a cyberattack will be more likely.
The Importance of Preparation
Preparation for when (not if) your organization gets targeted by a cyberattack is one of the most important aspects of cybersecurity defense. As seen in the Critical Insight Cybersecurity as a Service infographic below, from the seven core areas that need to be in any comprehensive cybersecurity strategy, four are activities that are direct preparation to prevent attacks, and another is long-term preparation for regulatory compliance.
As you'd guess, outcomes tend to be better if your response to any given set of circumstances gets shaped by prior training and thinking. In cybersecurity defense, this preparatory work falls into the following core areas.
Risk identification and mitigation
When building a cybersecurity defense strategy, "you can't defend what you don't know" is a frequently used phrase. For most organizations the resources they have available to spend on cybersecurity protection will be finite, and it is vital that they are used in the best way possible to maximize return on investment.
If funds are to get used well, there must be an overall picture of the current cybersecurity situation. The following methods deliver this overall picture:
After the risks are known and a plan put in place to address them, there needs to be additional planning and preparation for when a cyberattack happens.
Response Planning
Every organization should work under the assumption that that will be targeted by cyberattacks and that some of the attacks will breach defenses. For this reason, there needs to be planning so everyone knows what to do when an attack happens.
Note that this planning is separate and different from the improvement plan discussed above. The latter is to fix issues over time and improve the cybersecurity posture. In contrast, the response plan details what needs to be done when an attack happens. Incidentally, 24x7 network monitoring is vital for cybersecurity. It's not part of the preparation except for the initial decision on how you will deliver 24x7 monitoring.
An incident response plan (IRP) that is detailed and that everyone is familiar with so they can react quickly (close to instinctively) can be the difference between a cyber incident being minor or catastrophic. As our response team likes to say, "When you're in the middle of a fire, you don't want to be reading the instructions for the fire extinguisher!"
A comprehensive incident response plan should contain the following elements and associated activities (see ref 3 for more detail):
Regulatory Compliance
A broader aspect of preparation is compliance with regulations that pertain to the industry an organization operates within. Regulations can be from Government (HIPAA or CCPA, for example) or industry-led (like PCI DSS). Coupling requirements for compliance with the general cybersecurity planning makes sense, as there will be considerable overlap between the internal cybersecurity needs and the external regulations. Coupling them saves effort and resources, and each strand feeds into and strengthens the other.
How To Respond After an Attack
While preparation is essential and has to be detailed and ongoing, there is no such thing as 100% protection from cyber criminals. The threat landscape is constantly changing. New vulnerabilities get discovered weekly, and bad guys usually exploit them before organizations can apply fixes to their systems.
Bottom line? Every organization should assume they will be victims of a successful cyberattack.
When an incident is detected (again - you need 24x7 monitoring), all of the planning and tabletop exercises & training outlined above come into their own. When an incident is in progress, the response speed is crucial. The goal of the initial response should be:
Conclusion
Is preparation everything when it comes to cybersecurity defense? No, it's not. As the cybersecurity as a Service wheel shows, a complete strategy also includes 24x7 detection and response capabilities.
But, if you haven't done the prep to support your active monitoring and response efforts, then your outcomes will be worse than you hope.
Critical Insight can help you prepare and defend in real-time and improve your defensive posture over time. Use the form below to discuss enhancing your preparation and defense.
References
Business Insider: David Robinson Letter To My Younger Self - https://www.businessinsider.com/david-robinson-letter-to-my-younger-self-2016-11
Critical Insight Services - https://www.criticalinsight.com/services
Critical Insight: Incident Preparedness https://www.criticalinsight.com/services/incident-preparedness