Summary
In this chapter, you learned about the importance of having an IR process in place to rapidly identify and respond to security incidents. By planning each phase of the IR lifecycle, you create a cohesive process that can be applied to the entire organization. The foundation of the IR plan is the same for different industries, and on top of this foundation, you can include the customized areas that are relevant to your own business. Lastly, you learned the key aspects of handling an incident, as well as the importance of post-incident activity, which includes full documentation of the lessons learned, and using this information as input to improve the overall process.
Phishing is an old, yet highly effective, security threat that involves attackers masquerading as legitimate individuals or companies to manipulate unsuspecting targets to disclose sensitive information. Due to the volatility of the attack, once phishers acquire sensitive information, the IR team should be...