Mobhitech — Gérard Levicki
Incident Response & Cybersecurity Crisis Management: Contain, Understand, and Resume Operations
Whether it’s ransomware, account compromise, intrusion, data breach, or system downtime, incident response coordinates the technical and business decisions needed to limit the spread, preserve evidence relevant to the investigation, restore priority functions, and prepare for a lasting remediation.
In a crisis situation, it is important to avoid making the situation worse and to maintain the ability to make decisions.
Are you experiencing an attack right now?
If a security breach is underway or suspected, avoid taking irreversible actions in a rush. Plan your response carefully, preserve any available evidence, and quickly determine what needs to be isolated.
Mobhitech: +33 6 72 86 04 26 · Contact Gérard Levicki
For entities within its scope, CERT-FR also has an official reporting and assistance system in the event of a cyber incident.
What is a cyber incident response?
Cyber incident response encompasses the actions taken to assess an incident, contain its effects, investigate it, eliminate its causes or persistence mechanisms, restore operations, and reduce the risk of recurrence.
When an incident becomes disruptive, the technical response must be coordinated with crisis management: senior management, business units, the IT department, the legal department, communications, insurance, and service providers may need to make coordinated decisions.
ANSSI identifies investigation, crisis management, and remediation as key components of incident response.
What should you do in the first few hours of a cyberattack?
| Priority | Action | Why |
|---|---|---|
| Organize | Identify the crisis manager and key contacts | Maintain a clear chain of command |
| Qualify | Distinguishing Between Facts, Indicators, and Hypotheses | Avoid making decisions based on unconfirmed conclusions |
| Contain | Isolate systems or access points as appropriate | Limit the spread by managing the business impact |
| Preserve | Keep logs, records, and useful information | Maintain investigative capacity |
| Prioritize the activity | Identify the functions to be maintained or restored | Guiding Continuity and Recovery |
| Check the requirements | Involve the legal department, the DPO, or the appropriate departments | Address applicable deadlines concurrently with the investigation |
In what situations should an incident response be initiated?
- ransomware or suspicious encryption;
- compromised accounts or email;
- suspected intrusion or persistence;
- data leak or data exfiltration;
- critical unavailability;
- An incident at a supplier that poses a risk to your access, data, or business continuity.
How does a cyber incident response unfold?
- Qualification and Mobilization: Initial Facts, Key Players, and Level of Escalation.
- Containment: Limit the spread and restrict attacker access.
- Investigation: vector, accounts, systems, actions, and persistence.
- Crisis Management and Business Continuity: Balancing Business Priorities.
- Remediation and Restoration: Regain Control and Restore in a Controlled Manner.
- Lessons Learned: Turning Insights into Sustainable Improvements.
Digital and Forensic Investigation: Establishing the Facts Without Getting Ahead of the Evidence
The investigation aims to determine how the attacker gained access, which accounts and systems were used, how far the attacker progressed, whether any persistent access remains, and what data may have been compromised.
Forensic analysis may require the examination of logs, artifacts, systems, or other technical elements. It is important to distinguish between what has been proven, what is probable, and what remains to be confirmed.
Cyber Crisis Management: Coordinating Technical Responses and Business Decisions
A cyber crisis quickly goes beyond the scope of the IT department. ANSSI recommends, in particular, aligning business-side leadership with technical response, coordinating teams, involving business units in remediation efforts, and preparing communications.
Primary Source: ANSSI — Anticipating and Managing a Cyber Crisis
PCA and PRA: Maintaining Operations Without Restoring a Compromised System Too Quickly
The PCA ensures that priority functions continue to operate, if necessary in degraded mode. The PRA ensures that systems are restored to service according to defined priorities.
In a cybersecurity context, restoring systems too quickly can reintroduce a compromised account, a persistence mechanism, or a vulnerable configuration. The recovery process must be coordinated with the investigation and remediation efforts.
Remediation: Regaining Long-Term Control of the Information System
Remediation is not just about bringing servers back online. It aims to regain control of the compromised IT system and restore sufficiently secure operations: identities, persistence, vulnerabilities, reconstruction, segmentation, or restoration, depending on the context.
Primary Source: ANSSI — Managing the Response to a Cyber Incident
Data Breach: When Should You Consider Notifying the CNIL?
When an incident involves personal data, the data controller must document the breach and assess the risk to the rights and freedoms of individuals.
If the breach poses a risk, the CNIL states that it must be reported as soon as possible and, if possible, within 72 hours of becoming aware of it. In the event of a high risk, it may also be necessary to notify the individuals concerned.
Not all cyber incidents are personal data breaches, and not all breaches result in the same obligations.
NIS2: What are the notification deadlines for a major incident?
For essential and important entities subject to the applicable NIS2 regime, Article 23 of the European Directive provides for a phased notification of significant incidents: an early warning within 24 hours, followed by an incident notification within 72 hours, without undue delay. A final report must be submitted no later than one month after the notification, subject to the applicable procedures.
These deadlines should not be applied automatically to every company or incident: it is first necessary to verify the scope of application, the classification of the incident, and the national framework that actually applies to the entity.
Ransomware: Should You Pay the Ransom?
The decision should not be made on the spur of the moment solely under pressure from the attacker. It raises technical, legal, financial, insurance, and operational issues that must be analyzed with the relevant stakeholders.
Payment does not constitute a remedy: it does not prove that the systems are secure, that the data was not copied, or that the attacker has revoked his access.
What deliverables should you expect from an incident response?
- timeline of known events and decisions;
- known or suspected scope of the compromise;
- relevant investigation findings;
- containment and remediation plan;
- restoration priorities;
- record of crisis decisions;
- information relevant to notifications, as needed;
- Feedback and improvement plan.
What mistakes should you avoid during a cyber incident?
- deleting or reinstalling too soon and losing evidence;
- report an unconfirmed cause or data leak;
- restore without addressing the compromise;
- allowing each service provider to operate without coordination;
- wait until the investigation is complete before reviewing the obligations;
- to confuse the resumption of operations with the end of the incident.
Who responds to a Mobhitech incident?
Investigations and remediation efforts may require specialized expertise. Mobhitech can engage partners best suited to the situation while providing guidance, coordination, and oversight.
Mobhitech remains the point of contact for the mission and does not present a technical conclusion that is still under investigation as a certainty.
What Should You Do to Prepare for a Cyber Incident?
Incident response is more effective when key responsibilities and resources are established before a crisis occurs. There is no need to wait for an incident to occur to determine who makes decisions, how to contact key personnel, and which services should be restored first.
- crisis contacts and escalation chain available outside the main information system;
- roles among management, the CIO, business units, the legal department, the DPO, communications, and service providers;
- inventory of critical services and facilities;
- tested backup and restore procedures;
- logging and retention of records tailored to investigative needs;
- PCA/PRA that takes into account a scenario in which the information system is compromised;
- contact information for the insurer, service providers, and relevant authorities, where applicable.
This process can be integrated into CISO oversight, an audit, or a risk management initiative.
After the crisis: How can we reduce the risk of a relapse?
Lessons learned should lead to addressing not only the root causes but also the weaknesses in detection, governance, business continuity, and decision-making that were revealed by the crisis.
Depending on the results, next steps may include an audit, security testing, an outsourced CISO, consulting, or awareness training.
One-time incident response or SOC monitoring: What's the difference?
Incident response occurs when an event must be assessed, contained, investigated, and resolved. A SOC, on the other hand, provides continuous or periodic monitoring and detection, depending on its service model.
Mobhitech should not be presented as a 24/7 monitoring SOC if this service is not actually provided as such. The service described here focuses on supporting and coordinating incident and crisis response, with the involvement of specialists when necessary.
A mission supervised by Gérard Levicki
Gérard Levicki leads Mobhitech with an approach that integrates technical considerations, risk management, governance, business continuity, and business challenges. He has over 25 years of experience in cybersecurity.
Frequently Asked Questions About Incident Response
What should you do immediately after detecting a cyberattack?
Organize the decision-making process, assess the facts, contain the situation when appropriate, preserve records, and identify priority business functions.
Should compromised machines be shut down?
Not always. An irreversible action may erase traces or disrupt operations. The decision depends on the context and must be coordinated.
What is the difference between incident response and crisis management?
Incident response primarily addresses technical and operational aspects; crisis management coordinates decisions related to business operations, leadership, communications, legal matters, and business continuity.
When should you notify the CNIL?
When a personal data breach poses a risk to rights and freedoms, notification must be provided as soon as possible and, if possible, within 72 hours of becoming aware of the breach.
How long does it take to resolve an incident?
There is no universal timeframe. Assessment, investigation, restoration, and remediation may proceed at different paces.
Does "service restored" mean that the incident is over?
No. Restoration may take place before the investigation, remediation, or lessons-learned process is complete.
Should you conduct an audit after a cyberattack?
An audit or targeted test is often appropriate after stabilization, but its scope depends on the causes and weaknesses that have actually been identified.
Who should you officially contact in France in the event of a serious cyber incident?
Depending on the type of organization and the incident, CERT-FR may receive reports and provide assistance within its scope. Reporting requirements must be verified based on the organization’s status and the applicable framework.
Should you pay a ransom?
The decision should not be made on the fly. A payment does not constitute a remedy and does not guarantee recovery, the absence of data exfiltration, or the removal of the attacker’s access.
Are you experiencing or suspecting a cyberattack?
The priority is to quickly assess the situation, safeguard business operations, and avoid actions that could complicate the investigation.
In the event of an incident, contact Mobhitech to help guide initial decisions.