2 BEFORE THE INCIDENT

There is an old phrase that many who’ve worked in the information security world will be very familiar with: ‘No one is interested in security, until everyone is interested in security.’ What this phrase is getting at is that people tend to pay more attention to security after a security incident has occurred. Unfortunately, there is more than a sliver of truth to this. I’ve known many folks, myself included, whose jobs were created thanks to additional funding made available following a security incident. I’ve even heard some security folks wish an incident upon their employer to advance their own security agenda, as extreme as that would be. As good, ethical security professionals, we will not adopt this mindset. Instead, ...

Get Hands-on Incident Response and Digital Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.