How to Organize an Incident Response Team
An effective Incident Response (IR) team is absolutely vital, as it could be the difference between a timely recovery process and unsurmountable losses, potentially leading to business closure. Most companies are unaware that IR teams should be cross-functional since many hold the view that IR should be left to the IT department. The conventional reasoning behind this has been that cybersecurity incidents are technical problems and only IT personnel are charged with handling such issues.
In reality, an IR team needs to include experts from several departments and levels, such as public relations, human resources, IT, directors, and legal advisors:
Figure 3.1: IR team members
Therefore, IR should not be seen as a burden reserved for IT staff, since several roles that are necessary for IR require the contributions of many other employees. An effective response team is diverse and broad, and thus can handle many issues relating...