2016年-德勤全球_Cyber_crisis_management_14页_5mb
报告摘要
Deloitte: Cyber Crisis Management – Readiness, Response, and Recovery
Core Content
Deloitte provides a comprehensive overview of cyber crisis management, emphasizing the importance of readiness, response, and recovery in mitigating the risks and impacts of cyber incidents. Cyber threats are increasingly common, and while many attacks fail, the likelihood of incidents remains high. Therefore, organizations must prepare for a wide range of potential cyber events and ensure that their response capabilities are robust, flexible, and well-coordinated.
Main Views
1. Readiness
- Readiness involves vigilance and resource preparedness.
- A multifunctional team must be in place and trained to handle all aspects of an incident.
- Crisis simulations and war gaming help test preparedness and identify gaps.
- Threat intelligence and policy development are critical components of maintaining vigilance.
2. Response
- The response phase is crucial to limit damage, contain incidents, and avoid escalation.
- Effective communication across all media, including social media, is essential to maintain stakeholder confidence.
- The organization must be ready to manage legal and regulatory actions, minimize downtime, and address stakeholder concerns.
3. Recovery
- Post-incident recovery includes assessments, lesson learning, and rebuilding trust.
- Clear roles and responsibilities are necessary to ensure a smooth recovery.
- Rapid detection and well-structured recovery plans are key to minimizing impact on stakeholders.
Key Information
The Cyber Incident Response Lifecycle
- While incidents cannot be predicted, the response lifecycle is predictable and involves several phases: detection, containment, communication, legal and regulatory handling, and recovery.
- The goal is to restore affected systems and enhance cybersecurity to prevent future incidents.
The Three Pillars of Cybersecurity
- Secure: Prioritize digital assets based on their value and allocate resources accordingly.
- Vigilant: Ensure all employees are aware of their role in cybersecurity and are trained to recognize and respond to threats.
- Resilient: Focus on quick recovery, restoring operations, and rebuilding credibility.
Cross-Functional Coordination
- Cyber crisis management requires coordination across six key areas: governance, strategy, technology, business operations, risk and compliance, and remediation.
- Each area plays a critical role in ensuring a comprehensive and effective response.
Key Questions for Each Area
- Governance: Do we have the right team in place? Are we testing our plan and training our staff?
- Strategy: When should the C-suite and board be informed? How will we assist affected stakeholders?
- Technology: What technical capabilities do we have? Do we have access to forensic resources?
- Business Operations: Which processes are most critical? How can we return to full operations?
- Risk and Compliance: What are the breach notification requirements? How do we inform law enforcement?
- Remediation: Have we identified root causes? Have we developed and implemented a remediation plan?
Lessons in Crisis Management
Deloitte highlights five key lessons from its experience in crisis management:
- Preparedness is essential – Structured rehearsals and wargaming help ensure a coordinated response.
- Every decision matters – Decisions in a crisis can significantly impact stakeholder value, especially through reputational damage.
- Response times should be in minutes – Rapid, flexible, and clear communication is crucial to managing a crisis.
- Work remains after the crisis – Post-crisis tasks include data capture, financial management, and compliance.
- Crises create opportunities – Organizations can emerge stronger by responding effectively and using the crisis as a chance for improvement.
Final Recommendation
Most organizations lack the resources and expertise to develop and maintain comprehensive cyber response capabilities in-house. An outsourced or co-sourced approach with a managed cybersecurity and response service provider is often the best option.
- Cyber threat intelligence sharing, 24/7 monitoring, and external support in developing monitoring and risk management programs are beneficial.
- Crisis simulations and assessments help identify and close gaps in preparedness.
In conclusion, cyber crisis management is not just an IT issue but a cross-functional, strategic, and continuous process that requires investment, coordination, and flexibility to ensure resilience and recovery in the face of evolving cyber threats.
试读结束,高清完整版pdf/doc/ppt,请点下载