Attack simulations
To know what to do in case of an incident, you should regularly perform drills to practice your standard operating procedures (SOPs) for IR and improve your response times. As with fire drills in your offices, if you do not practice these drills, you don't know if your security measures will really work in the event of a real fire.
You should try to improve on the following metrics:
- Mean Time To Detect (MTTD)
- Mean Time To Recover (MTTR)
In such a drill, you would simulate an attack scenario, practice your IR process, and conduct a post-mortem with the learnings of the drill.
Here are some example attack scenarios:
- Service compromise
- Inside attacker
- Remote code execution
- Malware outbreak
- Customer data compromised
- Denial of service (DoS) attack
Practicing these drills will give you confidence that your SOPs work and let you react in case of a real incident quickly and efficiently.