Using a well-defined resolution process
Many organizations will experience fast-paced and high-consequence incidents that leave little to no room for error in resolution. Therefore, the IR team has to be well coordinated. Unprepared companies will fail to organize their response teams beforehand. They will make time-wasting moves such as calling for boardroom meetings or a conference meeting with all employees just to restate the obvious. Their response teams will also start allocating responsibilities late in the attack. Hence, their resolution will take much longer and will be inefficient.
Therefore, the IR plan should be well defined according to the advice laid out in this book to guide the team's efforts appropriately when moving fast to contain and recover from a security event. It should have clear roles and responsibilities for the whole team to avoid confusion that might arise. One of the best ways to systematize efforts in IR is to have three tiers of roles. In...