After the investigation.
WHAT TO ADDRESS FIRST
Anything still exposed.
WHAT THAT INCLUDES
Access not yet removed Vulnerabilities not yet closed Credentials not yet changed Systems not yet cleaned
WHAT TO ESTABLISH
That every route identified has been closed.
WHAT TO DO ABOUT COMPROMISED SYSTEMS
Rebuild rather than clean, where the compromise was significant.
WHY
Establishing that everything has been removed is difficult and uncertain.
WHAT TO RESTORE FROM
Backups from before the compromise began.
WHY BEFORE
Later backups contain it.
WHAT THAT REQUIRES
Knowing when it began.
WHAT TO ADDRESS ABOUT CAUSE
Why it was possible Why it was not detected sooner What would have prevented it
WHY THE DETECTION QUESTION
The time between occurrence and discovery is usually the largest failure.
WHAT TO CHANGE
The conditions that allowed it, rather than only the instance.
WHAT TO DO ABOUT PEOPLE
Follow a proper process, on the evidence.
WHAT TO AVOID
Action based on suspicion rather than findings Action without the person having responded
WHAT TO ESTABLISH ABOUT NOTIFICATION
Whether people affected must be told.
WHAT TO CONSIDER
Customers whose data was involved Staff Regulators Insurers Partners with connected systems
WHY PARTNERS
Compromise spreads through connections.
WHAT TO RETAIN
Evidence and records, for the period the matter may continue.
WHAT TO REVIEW
Whether the changes made were actually effective.