Building an IR strategy
So far in this chapter, we have learned how you can build an IR team. In this section, you will learn about the term reactive cybersecurity, and how to implement a reactive security strategy as well as an overview of operational security. Later in the chapter, proactive security, an alternative security system, will also be discussed, along with operational security, a midpoint between the two approaches. While there are a number of software solutions that can help you to deal with low-level security events by automating responses, sophisticated attacks such as advanced persistent threats (APTs) require you to have an IR team either internally or via partners.
Reactive security
It may not always be possible to foresee oncoming attacks. In addition, it might be expensive for some companies to keep so many threat-monitoring tools running if the organization seldom gets attacked. Reactive security is an approach that, instead of anticipating cybersecurity...