Hello. My name is David Visor. And welcome to post incident response.
Often times sad to say, we'd be caught up in the technical environment and we overlook, I guess what you could call soft skills. Um, however, the soft skills and the technical skills do
comfy. Mm. In a way that can't be overlooked. And if it is overlooked, then you're not going to be well rounded, holistic response annals. So hopefully, uh, we're learning as we go where Module five. Already talking about some boost
One of riches incident, recovery that is falling there. The end of our is their response process preparation We talked about briefly but
scattered throughout all of our time together. So far, preparation, as you've seen, is a key element in making sure that you can completely and adequately performed detection in analysis, containment eradication in recovery and then also your post is that activity.
So as we move over to first incident,
um, we are gonna kind of cover an element in that third step, which is containment eradication in recovery because it falls.
Yeah, I guess you could say it's fluid, so it's going to happen there early as the incident response process
moves along, but it also is going to be part of your post incident activity as well. Andi. It's important to track these issues because if you don't, you could very easily lose track of what's going on now. Recovery is simplest. Definition is to return to normal activity. That's
true. Weather is
surgery. As you can see, my extra hardware X ray there on that's attached to my spine. Now you're pretty big screws, actually, but I went through that surgery a couple years ago.
Ah, and I had to recover from that back surgery s So it was
you could say a long and tortuous word, and it has to be handled correctly. It's not. You could actually create and cause
more problems than what you you seek to solve by having the surgery. And when it comes into the response to see thing holds very, very true.
As you move into the recovery phase after you've declared your incident after you've done evidence gathering in your analysis and throughout the process of the analysis you developing in daycares compromise which has been passed out to other teams on the incident response team
like your firewall, an image that work and you'd your system advance
so that they can update their tools. Ruby in the containment now and as that. Those indicators are added to your tool sets and and systems are identified that were affected in her forensically captured and imaged and examined. And they are re imaged and brought back into service.
As you can see, that containment issue is almost now moving directly into recovery.
And whereas it may be a long road and hard room, it has to be beautiful correctly or you won't recover completely, and you could expose yourself to future incidents based on the lack of proper recovery. Now, this stage of the I. R process
does not resign with the cyber security, Um,
as it's strictly defined in the incident process, you will be dealing with a wide variety of other teams. Expect Ventured Exchange advance or Ravan's ate a vase. Adnan's. I can help this people in users management. Legal resource is
any time there's an incident, uh, any scope,
then you're going to see a lot of different people brought in. So as we move over into recovery, you are actually going to be dealing now instead more with administrators, database admits and others who are responsible for various segments of network in systems
that are attached to the network. But
I don't think that that doesn't mean that you have Whoa, you do especially whoever is a sign as the incident manage,
because the authority is invested in your manager in order to make sure that he steps are actually followed through on and completed, and that all has to be documented by your incident recorder. Whoever may have been assigned to that
position on these steps failed on recovery is not completed entirely. Then again,
you could have some other issues to Dio. As I said, the incident man's wrist order becomes a playground monitor here. He has to corral all of these different beings and persons and positions together to make sure that
the recovery process is still flowing along and being properly managed him.
If you've never been involved in an incident, you're going to be
involved in a ton of meetings, calls
I find him to be highly annoying, but they also are essential because it's through those calls and meetings that all the responsible parties are held to tax there be are held to the fire, so to speak. Then if you don't have meetings,
um, you're not going to be able to confirm
that your recovery process is actually flowing along
sweetly on rapidly as well. So if the incident manager isn't calling meetings on holding them and making sure that these things were being available and then there's, ah problem in the works that could hinder the entire incident response process.
Hey, saved by the meetings are essential,
especially if there were vanished in a long a thon. Uncle, I know sitting through these lessons with me here. In the past, I've been involved in these meetings, but internally and externally, and I've seen do it. And Dad, it's the managers.
And the incident management position is one of extreme authority and responsibility. So that person, whoever is assigned there, needs to be someone who can manage a wide variety of dispirit person. Allen's Room four story. We're doing tabletop exercise for a company.
Um, we show up on what we're actually doing, meeting with difference
entities within the company's. Our first meeting was with the security.
They were our exit response sales or sake analysts. Our,
uh, whoever was assigned to security team in order to help protect now work. And we went to Devon, topped with them and got to the ish side where we're discussing problems that they were facing. And they venture that they have problems working with the exchange. And
so we go on through a series of other meetings. Finally, we have all the leadership sitting on more room from sis. Oh, all the way down on the incident response team leaders sitting across table from the exchange that and by the time the meeting was over, the two were screaming at each other across the table.
And this is so basically just sat there
on did nothing to quell the problem. That is that leadership, everyone. So don't be that person now. There are a lot of items covered under recovery that will hit on here, restoring systems normal operation. Some of these should be pretty obvious to you by now,
confirming the restorations important. Often times I've seen
systems were put back into operation whenever he confirms
to remediating vulnerabilities and ensuring that they are fixed, uh, replacing compromised files with clean versions patching is huge, but oftentimes difficult in the corporate environment, but it needs to be done. Password changes should happen, if necessary.
Tightening the network security I mentioned just a few minutes ago. Perimeter needs to be checked. Firewall Admin is needed. The involved. Just a madman so that
you can tighten down your perimeter and make sure that no other attacks might occur. The same variety increased logging, monitoring and auditing should also come and play. Their metrics comes into play.
I personally don't like metrics very much, but I know and recognise it is essential. So how do you determine them?
A lot of people use costs. They'll break it down by systems, personnel, legal fees and finds there's this disruption costs. Time could be a useful metric when it comes to recovery and measuring the progress. Different issues come into play there.
You could do a loss of time, do the system. They're your loss that you could do personnel time
that has been expended on the incident. So let's review quickly to find recover for me, right? Return to normal. Who handles the recovery process?
The larger team with the incident manager uh, making sure that is being taken care of, uh, providing good list of recovery items. We just covered that and define metrics and provides examples.
Yeah, gone. Personnel costs, business destruction could all be metrics to use to judge the recovery process. You have any questions? Reach out to me. I'm on cyber. Gave me 135 Have a great day.