First response procedures in different scenarios
The incident response professional plays a key role in supporting organizations in developing first response processes to address cybersecurity incidents. These processes cannot be developed generically and must be based on an evaluation and analysis of the organization where they need to be implemented.
This is a basic example of what the general steps might be in a first response procedure for a particular case of a ransomware attack:
- The incident is reported via the help desk platform, by email or by phone.
- The information provided by the user is evaluated to confirm the incident.
- A ticket is generated on the incident response platform.
- The device is requested to be secured.
- First response staff is assigned to respond to the incident.
- The chain of custody process begins.
- Photos of ransom messages are taken on the screen.
- Acquisition of the RAM on the affected computer or computers is...