Scenario A – internal threat hunt
The team lead for the new internal threat hunt team identified the first course of action for them to complete was to determine when, where, and why communication within and external to the team would need to occur. Since all members of the team were already internal to Widget Maker Inc., they'd be using a tool they already had – Slack.
The team leader set up a channel to discuss the threat hunt just inside the team. This allowed the team members to talk freely, and upon its creation, the team started chatting immediately about their excitement to work on receiving a notification from the FBI.
There was also an update channel set up for the CEO and other stakeholders who wanted to know what was happening with the team without the formality of meetings or briefings. This channel was chosen over email communications since it is easier to control the spread of messages. Therefore, it was locked down to those members on the advice...