Chapter 5
Planning for Cybersecurity Incident Response
IN THIS CHAPTER
Creating an official cybersecurity incident response plan
Knowing when you’ve been attacked
Recovering from a cybersecurity attack
Communicating in the midst of a crisis
In July 2017, credit reporting giant Equifax discovered that hackers had penetrated its database systems and stolen the personal information, including Social Security numbers, of more than 150 million of its customers. The hackers had unfettered access to Equifax’s systems for 76 days before Equifax discovered the intrusion. Equifax waited until September of that year before notifying its customers that their personal data had been exposed. The incident significantly damaged Equifax’s reputation and resulted in a settlement of more than half a billion dollars.
Equifax did not handle the incident well.
In contrast, in that same year, shipping giant Maersk fell victim to a ransomware attack that crippled its entire shipping operation. Maersk’s IT experts soon discovered that the ransomware was spreading throughout its entire massive infrastructure, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access