What You Should Include in a Cyber Incident Response Plan

Introduction

Data breaches or ransomware attacks are a scary reality for any small to medium enterprise. If you operate on the grid (or store your information on the cloud), your whole company could be at risk of a cyber incident.

Statistics estimate that the average company could be affected by a virtual attack on its systems every 5 seconds. This figure might even be an underestimation of the true danger. The importance of a cyber incident response plan protects your company, your employees and your customers in the event of an attack.

Here are 5 things to do in the event that your company is affected by a ransomware attack or data breach.

1. Escalate the Issue

The first thing anyone in the company should do in the event of a ransomware attack or data breach is to escalate the issue to the correct department. Stop using linked, active systems immediately, and inform the appropriate company sector that you suspect there has been an attack or breach on the system.

This allows for quick damage control and immediate action in the event of an attack or breach.

2. Inform Everyone Connected

The second step is to inform everyone connected of the breach or attack.

People who don’t know that there’s been an attack on the system can, through the lack of knowledge, put the system at an even greater risk.

  • Any employee who is connected to the system should disconnect immediately.
  • Advise employees to change their passwords with immediate effect.
  • Impose a no USB rule throughout the company in the event of a breach; this makes further cyber incidents less likely, and stops the current one from spreading even further.
  • Advise employees to disconnect smartphones from any associated company files or accounts. Like less flash drives in company computers, it stops potential ransomware from spreading.

3. Secure All Systems

Secure all systems, including servers, email servers and computer systems immediately.

Do not submit to ransomware attacks. Advise employees to never agree with an attacker’s demands, but to focus on heightened device security both at home and work. Company systems can be secured with a professional cybersecurity team, and this is strongly advised.

4. Find Professional Help

All companies, especially small ones, should have a third-party online security provider. Discuss the cyber incident response plan with your security provider ahead of time – and make sure they know what to do in the event of an attack.

Larger companies are advised to allocate a cybersecurity department that is constantly assessing and negating the company’s risk.

5. Inform the Authorities

A company should always inform the authorities in the event of a data breach or attack. Law enforcement is far from powerless in finding and prosecuting ransomware attackers. Law enforcement action can allow a faster, safer resolution.

Get in touch with us

Secutor Cybersecurity is a trusted partner comprised of industry leading experts in the fields of Cybersecurity and Governance, Risk and Compliance. We partner with our clients to deliver on-demand solutions tailored to expertly navigate the regulatory demands of their specific industries.

Our proven track record of successfully exceeding client expectations is achieved through the combination of our methodical approach, advanced technologies, subject matter experts, and synergy with client team members.

Secutor is your team of world-class problem solvers with vast expertise and experience delivering complete solutions keeping your organization protected, audit-ready, and running smoothly.

Scroll to Top

Introducing:
Secutor Insider Direct

Discover a new era in cybersecurity purchasing. No markups, no hidden fees. Just the right tools at the right price, tailored to your needs, with expert advice from our seasoned cybersecurity professionals.

Ready to Find Your Solution?

Use the form to schedule a consultation, and we’ll reach out within 48 hours to confirm the appointment.

Considering this delay, please only select meeting dates 48 hours or more in advance. Your information will only be used to facilitate a meeting.