Whether they work for an up-and-coming startup or an industry giant, security response teams are under siege as never before. Today’s cyber attacks are sophisticated, relentless, and devastating, costing U.S. businesses $8.9 million a year each on average*. Attacking in multiple stages across multiple vectors, APTs easily evade signature-based detection and other traditional defenses.

That makes incident response more vital than ever. In the frantic aftermath of a breach, crucial mistakes can prolong the attack and enable more damage. Drawing on extensive front-line experience of the FireEye Labs team, this paper describes these common mistakes incident responders make:

1.   Failing to determine the scope of an incident
2.   Maintaining an inadequate process for handling incidents
3.   Not involving executive leadership
4.   Not considering the legal aspects
5.   Failing to communicate
6.   Not understanding the mechanics of the threat
7.   Incomplete infrastructure awareness
8.   Not monitoring internal network traffic
9.   Failing to log
10. Not leveraging existing tools


Are You Making Crucial Mistakes in Your Incident Response? 

Complimentary Report

Preview

Strong crisis-management skills are rare. In the frantic aftermath of a breach, crucial mistakes can prolong the attack and enable more damage. These errors tend to occur regardless of the size of the organization, the scope of the incident, or the technical savvy of the responders.

Drawing on extensive front-line experience of the FireEye® Labs team, this paper describes the 10 most common mistakes — five strategic and five technical— that incident response teams make when combatting attacks. The paper also explains the effect of these mistakes and how to avoid them with a well-defined incident response plan.

* Ponemon Institute. “2012 Cost of Cyber Crime Study: United States.” October 2012.

  •  
  •  

Download the Report

© 2013 FireEye, Inc. All rights reserved. Privacy Policy. FireEye on Facebook    FireEye on Twitter    FireEye on LinkedIn    FireEye Blog: Malware Intelligence Lab