Acting on What Was Found Print

  • 0

After the investigation.

WHAT TO ADDRESS FIRST

Anything still exposed.

WHAT THAT INCLUDES

Access not yet removed Vulnerabilities not yet closed Credentials not yet changed Systems not yet cleaned

WHAT TO ESTABLISH

That every route identified has been closed.

WHAT TO DO ABOUT COMPROMISED SYSTEMS

Rebuild rather than clean, where the compromise was significant.

WHY

Establishing that everything has been removed is difficult and uncertain.

WHAT TO RESTORE FROM

Backups from before the compromise began.

WHY BEFORE

Later backups contain it.

WHAT THAT REQUIRES

Knowing when it began.

WHAT TO ADDRESS ABOUT CAUSE

Why it was possible Why it was not detected sooner What would have prevented it

WHY THE DETECTION QUESTION

The time between occurrence and discovery is usually the largest failure.

WHAT TO CHANGE

The conditions that allowed it, rather than only the instance.

WHAT TO DO ABOUT PEOPLE

Follow a proper process, on the evidence.

WHAT TO AVOID

Action based on suspicion rather than findings Action without the person having responded

WHAT TO ESTABLISH ABOUT NOTIFICATION

Whether people affected must be told.

WHAT TO CONSIDER

Customers whose data was involved Staff Regulators Insurers Partners with connected systems

WHY PARTNERS

Compromise spreads through connections.

WHAT TO RETAIN

Evidence and records, for the period the matter may continue.

WHAT TO REVIEW

Whether the changes made were actually effective.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot