CHS Networks

Finding yourself in the middle of a cyber-attacks is probably not the right time to be working out what actions your business needs to take, as you can probably imagine. In this blog, we explain what you need in place to better defend your company, systems, data, and staff from a cyber-attack.

Should your business be a victim of cybercrime, of which there are many kinds, you’ll need to act fast, and you’ll need to act appropriately. We’re going to be looking at a ransomware attack in this blog, and the actions your business should be prepared, in advance, to take.

Cyber security solutions can be expensive for some small businesses. That’s why many decide to take the risk of not being a victim, rather than investing in solutions that may never be called upon. Taking a gamble that you won’t be a target for cyber criminals is a very risky business. And with the threat landscape evolving, chances are high that you fall victim to a cyberattack. Having an incident response plan is good practice to prevent your business from suffering the effects of an attack.

So, what does such a plan look like?

Plan, plan then plan some more

Every company has a business plan, but may not have an incidence response plan. However, for businesses today, it’s imperative that ALL businesses of ANY size, have an incident response plan for a cyberattack. Your cybersecurity incident-response plan needs to convey the right actions to help those responding to a cybersecurity event.

In this article, we’re going to assume that you’ve just realised, you’re a victim of a cyberattack!

Let’s look at the steps you should take following the discovery of a cyber incident.

Hour 1: Take decisive action

Once a threat has been discovered, it needs to be contained, that may mean unplugging a device, shutting down a server, blocking access to cloud services or even shutting everything down and going offline. Once that’s actioned, you need to trace any damage, define what’s been compromised, what’s been targeted, and what data has been compromised.

For many companies, the knowledge needed to undertake these actions internally isn’t available, as they simply don’t have a team member with that experience or training. In that instance, working with an external cyber security expert is key. You’ll need someone who’s familiar with your company’s digital infrastructure and business assets. If you do have a partner, ensure their contact information is readily available and all staff know how and who to contact, should they notice any suspicious activity. Ensure they’re the first people you contact in order to contain any further infection.

Should your cyber-attack be ransomware, it’s advised not to pay. There is NO guarantee that your data hasn’t already been sold on the Dark Web, and there’s also NO guarantee your data will be provided back to you following payment. Even if it is provided back, again there’s no guarantee that it’s not been encoded with some back-door encryption to allow further/continuous access…

Another good reason not to pay, is that once you’ve initiated a payment to a cybercriminal, you’ve set the precedence, and, once tagged as an easy target and a ’soft touch’ you may well be a victim again.

Day 1: Recover and Document

Unfortunately, a breach doesn’t just ‘end’. Cyber criminals tend to leave ‘backdoors’ within the systems of their victim, paving the way for their return. With this in mind, it’s important that you can pinpoint the attack vector, and vulnerability that was used to start the attack, and ensure that gap is closed. Then, look for others – and be thorough.

Within the first 24 hours of any cybersecurity incident, your business and IT staff should assemble to ensure:

All known traces of the attack are removed, and that a system-wide examination for other weaknesses related to the cyberattack is undertaken.

Involve and update pertinent internal parties (marketing, legal and PR teams) and external parties (law-enforcement and governmental agencies).

You’ll also need to ensure that you’ve met required government regulations following a cyber incident.
Once your required parties have been informed, you will need to notify customers, and potentially suppliers. You should have defined these communications within your initial strategy, as damage control needs to be front of mind. It’s also important that you handle these communications with honesty, explain the attack and the potential ramifications, should they concern customers and clients.

Your teams need to ensure that the entire attack and following actions are documented. Define any undertakings that were effective and those that were not. This breakdown should be used to correct and improve your subsequent, updated incident-response plan.

Following Actions

When your business has recovered, is back trading and effective systems are back working, a thorough audit should be completed. Ensure that a comprehensive penetration test is completed, deliver regular, and updated cyber security staff training and testing, and confirm incremental backups and thorough documentation are in place. Ensuring better best-practice for a cyber-incident, costs far less than the cost of a successful cyber-attack. Define and regularly update your detailed incident response plan and do ensure that you also investigate other solutions to better protect your business from cyber criminals.

Don’t forget that it’s very important to routinely test your incident-response plan. Digital infrastructure and processes change regularly, and testing will highlight any weaknesses in your data, solutions, and your plan.

Cyber criminals never stop finding new attack vectors, so you need keep up, and ensure you’re always improving your cyber security measures. If you have any concerns or would like a review of your cyber security processes and solutions, we’re happy to help.

If you’d like to talk to us about your cyber security provisions, do get in touch.

Get in Touch