Skip to content
0800 374 775

Incident response starts well before the incident

During a serious incident nobody reads a forty page plan. What gets used is a single page of phone numbers and the first four decisions, agreed while everyone was calm.

Most businesses that have an incident response plan have a document. Fewer have something anyone could act on at 11pm with the finance system encrypted and the director on a plane.

The gap is not effort. It is that plans get written to satisfy a requirement, and the requirement rewards completeness rather than usability.

What actually gets used

One page. On paper, and somewhere reachable that is not the network that is currently compromised.

Who to call, in order, with numbers. Internal decision-maker, IT provider, insurer’s notification line, legal, bank if money is involved. The insurer line matters more than people expect: many policies require notification within a defined window and some require using their appointed responders, and doing the wrong thing in the first hour can affect cover.

Who can authorise disruption. Someone has to be able to say “take it offline”, knowing that stops production. If that authority is unclear, the first hour is spent finding out who is allowed to decide, and the first hour is the one that matters.

How to communicate when email is untrusted. If the mail system is compromised or down, the response cannot be coordinated over it. Agree the alternative in advance, even if it is a group chat on personal phones.

The first four technical actions. Usually: isolate rather than power off, preserve logs, revoke sessions and credentials, and identify what the affected system holds. “Isolate rather than power off” is worth being explicit about, because instinct says pull the plug and that destroys memory-resident evidence you may need.

The decisions to make while it is quiet

These are the ones that are agonising under pressure and straightforward over a coffee.

When do we notify? If personal information is involved, the Privacy Act 2020 sets an obligation to notify the Privacy Commissioner and affected people where there is serious harm. The assessment is a judgement call and it should not be made for the first time at midnight by whoever is awake. Decide who makes it and what input they need.

What is our position on paying? Whatever it is, having thought about it in advance is worth more than the answer itself, because the alternative is deciding under duress with a countdown running.

What do we tell customers, and who says it? Silence is read badly and improvised statements are read worse.

What does “recovered” mean? Restoring service and being confident the intruder is gone are two different milestones, and rushing the second causes the second incident.

Practise the small version

A full exercise is a big ask. A thirty minute tabletop is not, and it finds most of what a large one would.

Sit the relevant people down and describe one specific scenario: the ERP is encrypted on the Friday of a peak week. Then work through the first two hours out loud. Who is called, who decides, what gets switched off, what customers are told.

Every time we have seen this done, it surfaces something concrete: nobody has the insurer’s after-hours number, the only person who can authorise a shutdown is the one who is always travelling, or the recovery plan depends on a system that would also be encrypted.

Those findings are cheap on a Wednesday afternoon and expensive at 11pm.

Where we sit

We do incident response and digital forensics on call-out, including business email compromise investigation. But the honest position is that the value of a responder is much higher when the first hour was handled well, and the first hour is decided by a page somebody wrote when nothing was wrong.

If you do not have that page, it is an afternoon’s work and it is the highest-return security task available to most businesses.

Next step

Recognise any of this? Let's talk.

We respond within one business day.