Home About Speaking Framework Press Podcasts Field Notes Say Hello
SCORE Mentors Chicago — 2026 Cybersecurity Web Series

SCORE Session 1 — Cybersecurity Incident Response

Restoring your business after a cyber attack

A session for non-technical small business owners on what to do before, during and after a cyber incident — the four-phase incident response framework, and why preparation rather than technology decides whether a small organization recovers.

I wanna give a hearty welcome to everyone that has joined us today. I'm looking at the chat and where everyone is shouting themselves out from, and I am actually quite surprised to see such a geographically diverse audience today. I'm honored to be here to share this information with you, and I, I know that you'll get a lot out of it. So let's go ahead and jump right into it. We're gonna talk about cybersecurity incident response, restoring your business after a cyber attack. Today there's a lot going on in the world around us. Geopolitically, there's a lot of unrest. Of course, we know what's going on between the United States and Iran.

Typically, when we have those kinds of situations going on in the world around us, that generally kicks up the bees' nest of malicious actors from a cyber perspective, who get really busy at attempting to exploit vulnerable computer systems around the world. We see that today. You might have heard of the Stryker incident that happened a couple of weeks ago. There are even more incidents that are occurring as a result of the geopolitical unrest that we have going on today. So I'm glad that you guys are here partaking of this webinar because hopefully this, y- if you apply this information to your own businesses to protect your technology infrastructures, you won't be the next Stryker.

So we're gonna talk about where we are today. We're gonna look at a couple of statistics that kinda put the framework around what's going on in the world around us. Then we'll jump into the incident response planning framework. I'm gonna take you through a step-by-step process that you can employ to some varying degree, based on your level of maturity in your business, build resilience or the capability of being able to respond to an incident after it happens, or even in a lot of cases, prevent the incident from happening in the first place. And then we'll look at where do we go from here.

S- I'll offer some tidbits of information that you can use to enhance your protection that will make it much more tougher for you to be that next victim. As Stacey mentioned, I bring over 30 years of experience in cybersecurity, digital forensics, AI, and high-speed network design. I'm a f- former professor and department chair of computer security and computer forensics, and I have been a contributing analyst on all the major networks related to addressing or discussing cybersecurity-related issues happening around the world. So let's look at some trends and statistics that begin to frame the issue that we're dealing with today.

Today in 2026, the cost of cybercrime has grown to $10.8 trillion, up from 8 trillion in 2000, in 2023. That makes the amount of money generated from cybercrime activities the third largest GDP in the world behind the United States and China. With that amount of money that's being generated in the world through malicious activities- You can see why cybercrime continues to remain one of the world's major issues that we need to stay on top of. If we relax ourselves, this will get worse. Some stats to be mindful of as we continue to frame this issue, about 94% of small businesses will be a victim of a cyber attack.

And what that means is you, the small business owner, have a high probability of being a victim if you haven't already been a victim of cybercrime. Now, Stacey mentioned that it's not a matter of if, it's a matter of when it happens, but today, given AI coming online and quantum computing coming online here in the very near future, it won't just be a matter of when, it'll be a matter of how soon will you be a victim of cybercrime. And so, the more proactive that you can be now, the harder you will make it for you to be a victim. 37% of companies hit by ransomware had fewer than 100 employees. The average ransom paid this year is up to $137,000.

Insurance, and I'll talk a little bit about this later on, insurance, as a result of this figure, insurance companies are becoming much more strict in how they underwrite customers because this dollar figure continues to grow. 78% of SMBs could not continue operating after they've been hit by ransomware. We're gonna talk a little bit about ransomware. This is a part of a series of webinars that'll be going on throughout the year. One of those webinars will be on ransomware, so we'll delve deeper into what this whole ransomware threat vector is all about, and how to harden your business against being a victim to a ransomware attack.

65% of SMBs, SMBs if you don't know stands for small and medium businesses, did not purchase insurance until after the attack, meaning it was too late, which meant that they had to bear the total cost of recovery if they were able to stay in business after that cyber attack. 95% of SMB cybersecurity incidents cost as much as $250,000. So what that means is, not just in the payment of a ransom if it was a ransomware attack, but also in the cost for the money that you'll spend in recovery activities like hiring professionals, recovering your data, hardening your infrastructure after the incident.

This makes insurance a very valuable tool to have in your toolbox to help you guard against not only the threat of a cyber attack, but also the impact of it. 80% of SMBs were the tar- cyber attacks this year 87% of SMBs have customer data that could be compromised by a cyber attack. We're gonna talk a little bit about some things that you can do to protect your customer data, because it's not just about protecting the customer data, it's also what liability will you be exposed to after the attack occurs. So we'll look at that a little bit.

78% of SMBs would stop doing business after a cyber attack, and the median number of cyber attacks still sit at four this year, which means that the number of cyber attacks that a small business will experience is about four, and that's four too many. Let's look at some of the top 10 cyber threats for this year. Of course, AI-driven phishing and social engineering. We've heard all about the capabilities of AI, the fakes. We've seen the videos, the artificially generated videos. We've seen the images. We've heard about the AI's capability of being able to mimic live voices.

Those are very real threats out there, and now that AI has become capable enough to be able to access data and streamline threat vectors, it makes this one of the top 10 threats that you as a business owner have to be concerned about. Social engineering and phishing, still responsible for about 70% to 90% of the breaches that, uh, occur throughout businesses.

Ransomware 2.0, it's an evolution of the original threat vector of ransomware, now involving data extortion, which means that not only do they encrypt your data and require you to pay in order to decrypt your data, they also now extort you, meaning they are threatening to release your data into the, onto the dark web or into the general cyber marketplace, which could expose you to great liability. So, for instance, you had put in place countermeasures to prevent your business from being impacted by data being encrypted, like having air gap data backups.

If your data is still impacted through the encryption process and exfiltrated out of your environment, they have the ability to threaten to release that data, which generally results in the business paying in order to prevent that from happening. In some cases, they pay and it still happens. Cloud misconfiguration and SaaS exploits.

Most SMBs are cloud first but not cloud secure, and what that means is because cloud architectures have become very affordable and accessible to pretty much any business- We moved so far into the cloud, but have not really considered what it means to keep our cloud infrastructure secure, and that's where we see a lot of cyber incidents occurring today, as a result of the insecure configurations of cloud architectures. Business email compromise through wire transfers, uh, invoice manipulations, and so forth and so on.

I can't tell you how many calls we get a week from businesses that have either been negatively impacted by or have caught it in time before they made the big $500,000 transfer to this individual posing as a l- legitimate vendor. We just had one last week of a vendor in Las Vegas who caught it in time before they made the transfer, but realized that they needed to step up their security countermeasures to prevent this from happening again. This is a very common attack because it's a lucrative one right off the bat. Credential theft and identity attacks. Identity is now the number one attack surface. Why?

Because it directly involves the human being, and as we say in the security business, the human being is the weakest link in any security architecture. And so if we can attack that link, we can generally guarantee ourselves success. Supply chain and third-party attacks. Trusted access equals biggest risk. We've third party or vendor risk, issues. For instance, you might heard about the Target incident that happened about maybe 10 years or so ago.

Target was a victim of a cyberattack as a result of the vendor that they had managing their HVAC systems that was vulnerable, that for whatever reason was connected to Target systems and allowed that malicious actor to get into Target systems through that vendor. Vendor risk management has become a really big deal today, and what that basically is is partners ensuring that, uh, each is doing what it can possibly do, its due diligence basically, to ensure that they are mitigating any vulnerabilities between the two so that they don't become a residual or pass-through victim of a cyberattack Endpoint mobile device attacks. Endpoints remain the primary initial access vector. Why?

Because we get very lax and in our comfort zone as it relates to our cellphone usage, our tablet usage, our laptop usage. We access sites without care or concern. We download data, we click on links without care or concern. And so the endpoint has become that main attack vector or access vector for malicious activity. Insider threat. Insider threat remains a very high potential, and the reason being is because that individual knows all about your business. They know how th- th- your processes work, they know how your systems are configured, and in most cases, they have the direct credential access into the data and those systems, which makes them a very viable and potent threat Dr.

Jerry Post, who's deceased now, is famous for his work that he did for the CIA in profiling Saddam Hussein, did some work, a study commissioned by IBM, about the insider threat. And what his research determined was that about 80% of cybersecurity related issues are going to come from the inside of the organization and not from the outside. So you can see how the people that you work with every day can be a potential threat to your business. Zero-day vulnerabilities and explo- zero-day vulnerability exploitation. Speed is now the attacker's advantage. Again, with AI and quantum computing coming online, speed will be even s- faster.

And what I mean by that is the ability to be able to parse through data, to identify those vulnerabilities in complex in- infrastructures. The amount of time that it takes to do that will be so significantly reduced that zero-day vulnerabilities will be a very big concern. They, I mean, they already are, but they will be becoming even a bigger concern with those new technologies coming online. Malware-as-a-service. Malware-as-a-service is a big deal these days because now malicious actors are hiring, uh, attackers to build malware and attack systems through weak and vulnerable vectors into those infrastructures.

So instead of them doing the work, they hire these individuals that are specifically tasked to doing that kind of work. So as you can see, th- these are significant threats that we face every day. What we're gonna talk about will, will help you to put in place response capabilities so that you, you can recover quickly from these incidents should you be a victim of a cyber attack. So we're gonna look at four components today that make up the complete framework of incident response. The first is preparation.

The things that you need to do before an attack occurs in order to ensure that, one, you've hardened your infrastructure, you've put in place the processes and procedures necessary to help you streamline your response. The detection and analysis of an incident. What are some of the things that you need to do, or that you will be doing in order to detect and analyze an event to determine whether it's an event or an incident? And we'll discuss the differences between those two shortly here. Containment, eradication, and recovery.

What do you do from a technical perspective to contain the incident, to eradicate the malicious actor from your environment, to recover control over your environment, and then to harden your environment to prevent the incident from occurring again? We've had a number of customers in our past that did go through this process, but they didn't go through the hardening phase of it. The attacker returned to the scene of the crime because they knew that the systems were weak, and they had to go through this process all over again. Lastly is the post-incident phase.

This is where you're gonna take time to review your incident response process to determine any shortcomings or deficiencies in your process that you need to improve on to make sure that next time an incident occurs that your incident response process can be delivered in as efficient of a manner as possible. So, some quick definitions that I'm gonna offer to you. First is the event or an event.

Now, when you have a technology infrastructure, whether you have one computer or thousands of computers, network devices, um, and any manner of IoT devices, those are all those devices that have IP addresses associated with them, like TVs or watches or cameras or whatever appliances you might have in your environment. At some point in time, you're gonna have some operational issues with, with a device or more. Just be- because you have an issue, an operational issue with that device, meaning that the device is not functioning way that it normally does, it doesn't necessarily mean it's a cyberattack that's causing malfunction of the device.

It could just be software-related issue, a network connectivity-related issue, um, that, uh, is, is occurring on that device. That's what we would generally call an event. Uh, an event where your IT guy, if you, if you have one, or your IT team, if you have one, would respond to that event in order to address the issue or remediate it to get that device back, uh, online and operating as expected An information security event, uh, is one that is related directly to a, um, cyber attack of some sort. Um, it generally means that there's been a failure in some way, shape, or form of your countermeasures if you had them enabled.

Um, if you didn't have en- have them enabled, then it, it generally means that that event is going to translate into some negative impact, uh, on your, on your i- infrastructure and your business. An information security incident, uh, is, is a single or series of unwanted or expected events that have a significant probability of compromising the confidentiality, availability, and integrity of the information in your business. Um, you'll hear me use the, the, those terms, confidentiality, availability, and integrity as it relates to data.

Um, some of your businesses are subject to ordinances, municipal ordinances, municipal, state, or federal ordinances that require you to protect y- uh, uh, PII or personally identifiable information. Um, when we talk about that, we're us- um, from a cybersecurity perspective, we usually refer to CIA or confidentiality, availability, and integrity as it relates to how you maintain that data within your own, within your environment. Ensuring that it's, the confid- confidentiality is maintained, ensuring that that data's always available to those authorized users, and ensuring that the integrity of that data is maintained while it's in your possession. And then lastly, an incident. Incident.

A declared incident, and what that means is that you have done the due diligence to weed out or rule out the consideration of this being an event. You're now considering to be an incident, and you're declaring it such. And when you declare that as an incident, there's a whole, uh, set of steps that occur that we're gonna talk about that you will launch, including calling third parties, getting your insurance company involved, maybe even calling law enforcement depending on the, um, indicators of compromise of that incident You wanna be very judicious in declaring an incident because there's a lot of other implications that come about as a result of that declaration.

So let's talk about preparation. There are basically three phases of preparation that you can go through. Now, s- a lot of this, y- your, your intention to pursue this also depends on the maturity of your business. If you are a single business owner, more than likely you're not going to have to go through most of this because it's just you. But if you've got a number of employees, you may wanna seriously consider going through this at least to prep your team in what the expectation is as it relates to how you're gonna deal with an incident once that incident has occurred. So we're gonna look at policy development, tools and resource allocation, and process and procedure development.

If you engage in these three phases of preparation, you should be well prepared to respond to an incident when it occurs. So first step in preparation is policy development. Policy development is basically going to be a step that you take to define how you're gonna prepare for the incident, what resources you're gonna allocate to support you in that incident, rules and processes and procedures that you're going to stipulate that allow for, um, and govern behavior around the response to the incident. I'll give you an example.

If you're a decent sized business, and you more than likely have some official financial procurement alloc- allocation and management processes in place that helps you to manage your day-to-day financial operations That might take several steps in order to engage in procuring a service or a device. But during the time of an incident, you might not have the time to go through the official set of steps required to procure a service or equipment.

And so having a policy in place that allows for the exception for you to go beyond what is traditionally followed is a good thing to do because it shortens the amount of time that it takes for you to get allocated the money, the services, the resources that you need in order to support the response effort and not get tied down in the day-to-day red tape that you normally would engage in in order to manage. So that would be an example of a policy that you would implement that would stipulate the exceptions that you can engage in when dealing with an incident. Policies and procedures around governing the hiring and termination of employees. This is a big one.

Most organizations are immature in the policies related to how they hire and fire employees, especially terminating employees. When you are terminating an employee, that is a potential area where, especially if that person is disgruntled and they have access to your system, they could become that insider threat and evoke damage in your system in retaliation to being terminated.

So having those right processes and procedures in place, for instance, to alert your IT team that you're gonna be terminating this individual so that they can be vigilant in either shutting off credentials or access, retrieving endpoints that they may have in their possession that they could use to retaliate against you Depending on the, the maturity level of your organization, you may have in place policies and procedures governing deployment of new technologies. You might have procurement rules and strategies, you might have staging rules and strategies, you might have testing rules and strategies around how you integrate new technologies in your environment.

If you're dealing with an incident, you're not gonna have time to go through those standard operating procedures that you've implemented in your organization. You might have to usurp those processes and procedures in order to get some new technology in to help to streamline or facilitate your incident response process. So policies around that allowing for exceptions are necessary. Change management. Of course, during an incident, there's gonna be a lot of changes going on.

D- depending on the maturity level of your organization, you may have change processes and procedures in place that govern how changes are made, who reviews them, who approves them, the testing functions that go along with changes before they are put into production, for instance. During an incident, you're not gonna have that time to go through that process if you need to implement or integrate new technologies that you've purchased to help support the incident response process. So policies that allow for the exception to change management are necessary.

The next step in preparation is the tool set that you're going to procure in a proactive way that will help you to bolster your incident response capabilities and your team should you need them. So tools such as virus scanning tools, which you should actually already have in place to help you deal with malware threats in a proactive way, monitoring, reporting, and alerting. I highly recommend even if you are a one-person shop, that you procure a monitoring, reporting, and alerting capability that will let you know what's happening underneath the covers of your technology.

For instance, if you're dealing with a credential attack against your endpoints, more than likely you're gonna have a lot of failed logins i- in- in a short period of time that indicate that there's a potential of a credential attack occurring against your endpoints. If you don't have the monitoring, reporting, and alerting tools in place to help alert you to that, you will never know that And so again, I go back to my recommendation of making sure that you've got some monitoring, reporting, or alerting capability, whether you can implement it or you have to procure it through a third party, through an IT guy, for instance.

If you're a one-person shop and you have someone who is taking care of the management of your IT technology, your endpoints, have them have some capability enabled that allows you to see those kinds of things happening so that you can respond to them Most incidents that are discovered did not occur at the time of discovery. Those initial breaches into the environment generally occurred months before, even years before, the incident was actually discovered. And so a- as a result, if they were not alerted to the initial breach, they would have never have known that the m- malicious intruder was in their system poking around and finding other vulnerabilities or exfiltrating data off of...

And so again, I go back to that recommendation that monitoring, reporting, and alerting is extremely important to both pro- proactive and reactive management of your environment. Next is forensic data collection toolkits. After an incident has occurred, one of the most important functions you're gonna engage in is evidence collection. You never know where the investigation or response to that incident is going to wind up, and so you wanna make sure that you have maintained what's called a forensically sound posture when collecting that data.

Because if that incident winds up in some kinda litigious activity, meaning you've, you're headed to a lawsuit or some kind of prosecution, then the data that you've collected, you need to make sure was collected in a forensically sound manner so that it can be used in the commission of that prosecution. If it has not been, then more than likely that data will be dismissed. We'll talk a little bit about what it means to abide in a forensically sound manner as you're going through the containment, eradication, and recovery phases of the incident. Intrusion detection tools, similar to monitoring, reporting, and alerting, give you some sense of what's going on behind the scenes.

They give you some sense of the activities that might indicate that a potential breach is occurring or that there's a malicious actor who's attempting to breach your environment in some way, shape, or form. These tools today not only detect potential incidents, but dependent on the sophistication of the intrusion detection tool itself, can even mitigate or stop the attack in its tracks.

Netflow data capturing and analysis tools are extremely important because they help from an investigative perspective- The forensic examiners or the IT people who are investigating the incident to determine how the incident occurred, where it came from, how it propagated through your environment, the endpoints that were under threat by the malicious actor. So being able to capture that NetFlow data helps us as forensic examiners to really do a deep dive investigation into, uh, the propagation of that event throughout your environment. We had a situation, a customer a few years ago, who got hit by ransomware attack, shut their entire business down. And not just for a day, for weeks.

They went through the incident response process But they were not following forensic sound data collection processes, and they did not have NetFlow data captured. And so by the time they called us in, they had pretty much erased all the pertinent data that we needed in order to determine root cause of the incident. And so the only thing we could really do was to help them in the recovery... in, in the eradication and the recovery effort, but we couldn't tell them how it happened because through their process, they had erased everything.

Cloud communication tools, Office 365, Teams, Zoom, et cetera, are extremely important because what they do is they help you set up secure communications amongst all the parties involved in your incident response process. Um, this is key because, uh, for instance, if you are ever dealing with an email spoofing attack, which is what most wire transfer or invoicing fraud issues are born from, if you are communicating with people that you are engaged in the response with, the attacker can see those emails as well and be able to maneuver around your environment in order to continue to maintain privilege in your environment.

So you don't wanna use your compromised email tenant to communicate about what's happening, what you're doing, because they can see that as well. So you wanna use secure cloud communications like Teams and Zoom to make sure that you can securely communicate effectively, but not give away what you're doing to the bad guys that are in your environment. One of the recommended preparation steps that I suggest is to speed up recovery of your environment is to make what we call clean system images of all of your key systems at least.

If you only have a few endpoints, then to make clean images of those endpoints so that after the compromise has occurred, you can restore your devices from those clean ima- images, get rid of all the, uh, malicious indicators of compromise, malware variants, configuration changes, anything that the malicious actor might have done while they were in your endpoint or your device. These products here, Acronis, Cyber Protect, SnapDeploy, uh, OpenText, EnCase, and ManageEngine are tools that can be used to make those system images that you would store offline for safekeeping and only use when you needed to restore those devices back to an operational state. IRP training, important here as well.

IRP training or incident response planning training basically takes your key people in your organization the training process for processes and procedures that you've established for responding to the incident We've identified four groups of people or four groups of roles within your organization that need to be, to go through this training. So your senior management, they need to obviously understand the proce- the policies that you've established to, um, help to support the execution of the incident response.

Mid-level managers, who are more than likely gonna be involved in the on-the-ground technical response, along with the IT staff and other employees, uh, involved in the on-the-ground response are gonna need to understand what this process is. They're gonna need to understand who to communicate with, how to communicate with them, and what to communicate to the various parts of your incident response team. And we're gonna talk about testing later, which takes each of these roles through the testing process to ensure that they can maintain a high level of vigilance and readiness to execute the incident response plan should you need to do that. The incident response contact list is, is important.

Having that prepared and ready to go is necessary because it shortens the amount of time of you figuring out who do you need to call when this incident happens. Depending on the size of your organization, you're gonna have multiple roles on that list. So as you see here, we have law enforcement, legal support, insurance, technology vendor support, employees in the company. You should have those roles identified on your contact list, and backup roles because you never know when someone's on vacation or just unavailable at the time of an incident. You wanna make sure you've got a backup to that role as well.

Information you're gonna have on that list is the member name, job title, the role that they're gonna play in the incident response process. You're gonna have a, a primary member, phone number, home, cell, all the phone numbers necessary that allows you to get in contact with an individual. Because if an incident occurs at night, off-hours, you're gonna need a way to get in touch with them quickly. The office address, primary and secondary emails, and again, as I mentioned, backup teams.

We're gonna get a little bit deeper into the third-party support, including law enforcement, legal, insurance, and technology vendor support, um, because those are all gonna play critical roles, a- and again, related to the maturity level of your business and how they're gonna support you in your incident response. It is n- absolutely necessary that you have this identified upfront because, again, you don't wanna have to scramble to try to figure out, "Who do I call now that my systems are not available to me," daily business. You're losing time, which could do even more damage to your systems, your data, and your ability to restore in the long run Incident categorization.

This is a necessary function of preparation. Incident categorization helps you to Predefined steps that you're gonna take in your response process based on the type of incident that occurs. There are generally three incidents that you're going to deal with. It's either a malware infection, a network, um, or, or, or system security breach, or data loss or private- privacy breach. Most incidents, well, all incidents that you're gonna deal with are going to fall into one of those three categories. Um, and so it's, it's helpful to have processes and procedures defined for how you're gonna triage that incident, uh, to confirm that it's one of those three.

Uh, once you've confirmed that it's one of those three, how you're going to, uh, begin your response process, your containment, your eradication and recovery process, uh, what tools you need in order to facilitate the recovery process based on the category of the incident. Having this predefined streamlines this process and saves you a lot of time, uh, in, in your incident response activities. The escalation decision tree. For those businesses that are a bit more mature in their operations, um, an escalation decision tree, uh, is... I recommend, it is very helpful to, um... Is, is, is a helpful tool to also helping us streamline the response process.

An escalation decision tree is basically a flow chart that's associated with the category of the incident that I just talked about that really outlines all the steps in a flow chart that if you follow those steps, um, according to that flow chart, will lead you to the, the resolution process, but also to m-make sure that you do all the proper data collection, all the proper data reporting, all the proper communications, uh, and that you're not leaving out any steps along the way. And I'll show you here, uh, on the next slide, what a, a decision tree looks like.

So this might look a little complicated, but if you really delve deep into it, this helps you as an incident response team to really figure out what your response is gonna look like without you having to do that on the fly. It maps out each step, and it maps out all sub-steps from that step, should there be an affirmative or a negative associated with that step, and it takes you all the way to the end of the incident response process. This is a generic escalation decision tree- Uh, you can take this and modify it based on your business, based on your maturity level.

Bus- typically, most businesses that, that have a, a number of employees would look to engage in this because it helps, again, to streamline the process. If you're a one or two-person, uh, firm or business, you might not need to engage in this because it's just the two of you or the few of you, coupled with any outside resources that you might bring in. Another component of the preparation process is defining what your business critical path is. The business critical path is basically that path of operations that are absolutely necessary for you to do business on a daily basis.

If any one of those components on your path were to disappear, would your business stop being able to be viable and delivering products or services as a result of that missing piece in that critical path? Every business has a critical path. Those are the most important functions in your business that are absolutely necessary. There are functions in your business that are what we would call secondary, that if they were not available, that you could still do business. Uh, it might be a little challenging to do business, but you could still do business on a daily basis. I'll give you an example. The, one of the local hospitals here in Chicago experienced a security breach about two years ago.

It was a ransomware attack that encrypted their databases to the point where it prevented them from being able to do surgeries and procedures, from being able to deliver basic care. They really couldn't do anything. As a matter of fact, they had to resort back to paper operations in order to keep things moving along as best they could, but some of their essential services they couldn't deliver because they, they didn't have access to their data or their computer systems. That database that was attacked was a part of their business critical path, that when it disappeared, it stopped them from being able to do business normally.

You want to identify this for yourself because the identification of your business critical path, you can proactively put in place recovery, uh, mechanisms or secondary processes or procedures that could take over in order to ensure that you can continue to do business and not lose complete functionality. What do we need from start to finish in order to execute this mission? What are those components of our operations that we need in order to execute this operation, in order to pursue our mission, if you're a nonprofit, and what can we absolutely do without?

Once you identify those, then you really know where your focus needs to be, especially when it comes in, uh, when you're looking at the proactive ways of protecting those components of your business. As a part of the business critical path definition, you can do what we call a business impact analysis. A business impact analysis is a formal process of engaging in that analysis- To qualify and quantify the impact to your business if you were to lose one of those components in that business-critical path.

And what this'll help you do is to determine or give you the business case to do the things that you need to do to put in place those recovery or backup measures to ensure that if you lose that primary component, that that backup measure can take over and keep you moving forward. As a part of the preparation process, who are you gonna call? You need to know that upfront. As I mentioned before, you- one of the things you don't wanna do is have to sit down and figure that out after the incident has occurred.

Most likely, you're gonna be contacting support organizations, customers, and folks internal to your organization, especially if they're identified on the CIRT list to get engaged in the response process. So some of those types of roles that will come to your aid, again, technical incident response support, depending on the maturity level of your business, you might need some outside support to help you with that. Uh, law enforcement, this is a kind of a tricky one because the... used to be that there were certain dollar levels that, or thresholds that law enforcement would require before you would get involved.

Now, anytime you're dealing with a, an incident, you should always file a police report at the very least, because that data could then be used to help support trending and also help law enforcement understand what they need to do to help better support the general public. Depending on the dollar threshold that is associated with the cyber attack, that might trigger a higher level of response from law enforcement like state police or FBI, who will get involved after that threshold has been crossed, uh, in a very technical way to help support the investigation, doing everything from taking forensic images of, of, of devices, endpoints in your environment, doing the analysis.

It also depends on the incident. If you're dealing with, for instance, a contraband kind of issue like child pornography, they will immediately get involved, no matter if you are a person, business, or a 50,000-person business. If you're dealing with child pornography or some kind of sexual abuse attack, they will immediately get involved, and when they get involved, you're in a whole different space of operations at that point. The next thing you need to do is to be calling your legal support in to help guide you through that process They are on this list. Depending on the maturity level of your business, you might have a legal team involved. You definitely wanna get them involved.

You might have crisis support. If you have a large customer contingent on the consumer side, crisis communication providers are a good tool to have to help you determine how to get information out there, what information to get out there so that you don't make the situation worse Partners, if you're doing business with partners who are gonna be impacted by the incident, you wanna communicate with them so that they can at least start investigations on their ends to make sure that they've not been impacted by the incident, and can heighten their level of vigilance and due diligence to ensure that it doesn't propagate into their business environments.

Of course, employees, you're gonna wanna get involved to some degree, depending on the role they've identified on the CRT list, and regulators. Depending on the incident and the customers or consumers that are involved or exposed, you might be subject to some regulatory liability that might require you to do things like offer free credit reports, make notice to those individuals that are affected.

I would imagine that we've all received the letters in the mail from our credit card company or financial institution or some business that we've been engaged with r- making the report to us that they have been a victim of a cyber attack, and that our data has been exposed or compromised in that attack. These are the things that we're gonna offer you, like credit monitoring or some other service to help you ensure that you're not gonna be negatively impacted by that cyber incident. That's why you're getting those letters, because they are legally mandated to send out that communication. Incident testing, we talked about the need to test.

You wanna test every component of your incident management process, from the triage process to the communication process, and you wanna do that on an annual basis to make improvements to that plan. You don't want to, the first time that you crack open that incident management plan to be during an incident. You wanna make sure that you do this, the testing, on an annual basis to make sure that you've got all the right pieces and parts in place to ensure that this plan is going to support your incident response process based on the categories that you are planning for, that we mentioned earlier. So detection and analysis. Detection and analysis, three phases.

The incident triage phase, the indicators of compromise review, and the evidence collection, preservation, and handling. These are all extremely important in the detection and analysis because what this is going to do is tell you what actually happened, where it happened, when it happened, and you might a- m- You might even be able to determine the how it happened and the who did it. Now, the who did it piece, last thing you wanna be thinking about. You really wanna be focused on are restoring control over your business. The who did it piece can come after you have regained control over your business, and now you can focus on potentially identifying the source for prosecution later on.

In the incident communications protocol, there's the pre-incident declaration communication, the incident response execution communication, and the post-incident response communication This level of communication is basically gonna provide you with guidance or provide the team and the company with guidance on what's happening during the incident response process, the who, what, where, why, and how of it all, so that people know what they are expected to do during the incident. The alerting to your partners, third party organizations who either need to get involved or who might be impacted by the incident, are all gonna happen as a part of your communications protocol.

In the testing phase of this, you wanna test out this protocol to make sure that you're communicating the right things to the right people at the right time, and that you're not over-communicating, which could make the situation worse. What do we need to communicate about during the incident? Again, all communication should be on a need-to-know basis. All communication should be secure. I mentioned using Zoom or Teams. A standard form of distribution list should be used for status reporting. What you communicate about will depend on what you know and how soon you know it.

Depending on the maturity level of your business, if you have a crisis team in place, they will help guide you through the communication process so that you are communicating appropriately every step of the way. For incident triage, this is the place where you're gonna do your initial investigation to determine what happened that has brought this event on. So I'll give you an example. You're going about your day, your business is going about its day, and your employees or one of your employees start to complain about an inability to access emails, or someone's complaining that they've sent emails out to an individual, and that individual realizes that they never received the emails.

We had a customer call us about that about a week and a half ago. One of their vendors called them and said, "Hey, did you get my emails?" And the individual said, "No, I never received them." And they said, "I've emailed you three or four times," which then triggered some concern about why they're not suddenly receiving emails. This is typically how an incident gets discovered if you don't have those monitoring capabilities in place. It's typically a loss of some daily functionality that you're used to having that's no longer there that could, uh, indicate that there's an incident. Now, this just might be an event.

Could be that- Maybe the tenant expired, or maybe the license needed to be reviewed and it wasn't renewed. It could be that maybe the hard drive on the computer crashed somewhere, or maybe even provider has somehow lost the ability to provide that service. That's happened before in the past. This incident triage is the process where you're gonna figure that out. What's going on here that's causing us to lose daily access to the functions that we're used to having every day? You're gonna collect a full account of all initial reports and indicators related to the event. You'll begin to bring these together to piece together what's going on here.

You'll conduct an initial assessment of the impact of the event. How many people are experiencing this issue? Is it just one, or is it multiple people? So that tick kicked off an investigation that determined that their Microsoft 360 had been hacked into. You're gonna assess the impact to the key and critical business processes and functions. Remember that critical business path and that BIA that we talked about. If you've already predefined that business critical path and you know what technologies support the processes on that path, then you can immediately go and look at the components of that path to determine whether or not they have been impacted by this event.

Depending on the outcome of the analysis of those three steps will help you to determine whether you're dealing with an event or you're dealing with an incident. As a part of the analysis and detection, and as a part of the triage, you're gonna be doing what's called an indicator of compromise review, and this means what are all the indicators in our environment that indicate that we've been compromised? If your technical team is able to do an initial assessment of endpoints to see log files or data that's either been encrypted or deleted.

We had a situation where a, a company, a customer experienced a cyberattack, and the attack was that some individual overseas uploaded a porn site to their web infrastructure and was running this porn site from their business. The indicator of compromise was all the data that suddenly appeared on their servers that indicated that someone had broken in and uploaded this data. Log files, volatile memory, and NetFlow data artifacts are what we call indirect, uh, indicators of compromise.

As you're going through your triage, you wanna make sure that you are collecting this information and you're storing it away so that if you do move into a litigious or prosecutorial, um, uh, process, if you will- That that data's available for the investigators to, uh, analyze and help to also piece together what happened. Um, direct indicators of compromise, again, log files, volatile memory, uh, Windows registry, startup folders, um, TCP connectivity records.

Uh, if you go onto any computer that's connected to a, a network, there are TCP connectivity records that show who is connected to that device at any point in time Uh, and then file systems, depending on the amount of data in the file system that's traditionally in a file system, um, that can help you determine, um, that you, that, that their compromise has occurred. Uh, evidence collection and preservation, um, as I just mentioned, that's an extremely important process, um, that i- is, is, is focused on how you collect and store away that information. We, we, we use this term in our business called the chain of custody.

Uh, the chain of custody is extremely important, uh, to maintain, uh, if you're moving into the legal process because that en- ensures or records the integrity of the information that you've collected. If you don't have that chain of custody, then it's gonna be very hard to use that data down the line. So you always wanna be maintaining the chain of custody. You can Google what chain of custody looks like. It's a very simple process of just keeping a log of when the information was collected, who collected it, where do they collect it from, and then what do they do with it after they collected it.

Uh, and then storing that information into some, in some secure location like a locked box or drawer or room, um, where, um, you can control the access to that evidence or even to the compromised device itself. As a part of the de- detection and analysis... Oh, I'm sorry, let me, let's go through the, the, the, the chain of custody that I just talked about. So, um, these are questions that are gonna be asked if you're moving down the legal route. Um, was the evidence gathered and verified in a forensically sound manner? You heard me use that term early on. Uh, was the chain of custody maintained?

Um, that's basically the record-keeping of how the data was collected and what was done with it afterwards. Uh, is the ownership of the licensing appropriate for the forensics tool used? Sometimes we might procure a tool that we don't necessarily have license to use. Like for instance, we might call up a buddy at another company who might have a forensic tool that they can lend to us, but the tool hasn't been licensed to us, it's been licensed to them. If we're using that tool support our forensic data collection process, we could be poisoning that data.

It's called fruit of the poison tree, which is the legal term used to describe the data that you collected using unlicensed tools Was the proper examination environment being maintained and controlled by those other members of the CIRT? So this again goes to the chain of custody. Were we able to keep control over the environment while we were doing the analysis or the triage? Can the results of the technical analysis be duplicated by using other tools? Does the analyst understand what they're doing, or are they just punching buttons and clicking on things to produce results? Do other professionals use the same techniques and methodologies?

This is important because if you wind up in a defense situation or a situation where there's gonna be a defense, someone's being prosecuted, if the defense can prove that the techniques that you used were not appropriate, it will invalidate that data. Is the analyst technically capable of defending and supporting the interpretation of the evidence? Can they tell you what, what they did, why they did it, how they did it, and why the results were the way that they are?

So in situations where you don't have this capability in-house, make sure that you do bring someone in that does have this skill set and capability, because all eight of these questions are gonna be definitely asked to that individual, and you wanna be able to answer those questions in the affirmative. Otherwise, your ability to prosecute will be put in jeopardy. Now, not all hacking incidents move to some prosecutorial level, but you never know that, and so you wanna make sure that you are following the step-by-step process that I previously laid out related to forensically collecting data, so that if it does, you are prepared.

Eradication and recovery, the next step in the incident response process. The goal of containment is to remove control of your systems and your environment by the malicious third party. You wanna contain their functions and capabilities that they've executed in your environment, so you're basically stopping the attack as it's happening. You wanna in some cases be performing containment- As you are executing the triage, because what that will do is minimize the l- level of liability that you could be potentially exposed to th- through the loss of data or any facts related to the incident that could expose you to a high level of liability.

The overall goal of the incident response process is, one, to help you to respond to the incident timely and efficient manner, but also to minimize your liability based on the incident as well. For short-term containment, if your systems have been impacted by the incident, a lot of us are not using on-prem servers anymore. We're in the cloud, so unplugging isn't a option, but if you do have on-prem equipment, unplugging might be the way to go. Now, when you unplug, just remember that you're gonna be losing some valuable data, like in the volatile memory, the TCP connects or other information that could help in the investigation process.

Pulling the cord may be necessary to prevent the loss of data or to prevent further propagation of the attack. That's something that you're gonna weigh during the triage process to determine what the best response is to this incident. It might just disconnecting the device from the network to prevent any further outside access to that device. But again, those are some of the things that you're gonna figure out as you're sitting and contemplating what your response is going to be. Long-term recovery can involve a number of different steps, from disabling applications on a system, identifying vulnerabilities that could have been used to exploit the system and removing those vulnerabilities.

Updating and patching your operating systems can be one way to help support long-term containment. Hardening your firewalls and your network devices, putting in new rules, closing ports are ways to not only harden, but stop the access or prevalence of the attacker in your environment. Redirecting network traffic, depending on the complexity of your environment, to what we call a honeypot, so that you can continue to keep an eye on the individual to see what their intention is, what their activities are, which you can use as intelligence to better strengthen your environment Identifying the possible sources of the attack.

Again, as I mentioned before, the source is a last consideration you wanna make in your containment, eradication and recovery. You wanna focus on getting control over your systems to start with. Eradication, depending on the threat prev- prevalence and eradication confidence levels, the compromised systems may need to be completely rebuilt. Depends on how deep the attacker got into your environment, how long they were there. The longer an attacker is in your environment, the more prevalence they will have established in your environment.

What that means is, the more control over the environment they would have sought to gain, the more configuration changes, malware variants or applications that they would have installed in your environment to allow them to continue to retain control over your environment. It might just be... The, the quickest way to reduce prevalence to zero might just be to rebuild the system from scratch, taking it completely offline, re-imaging it using those tools that I talked about earlier for re-imaging key and critical systems to get rid of any prevalence that that individual might have established in your environment.

Using any vulnerability analysis tools to identify vulnerabilities that they could have used to exploit the security in the system, getting rid of accounts. This is one of the biggest ways that attackers find their ways into other systems, particularly into cloud-based tenants, because some unsuspecting user with admin access logged into a device that was compromised and that attacker was able to commandeer those credentials and then use them to get into your tenant and then make configuration changes that give them prevalence and control over your tenant. So you wanna make sure that you are going through the process of hardening or removing any rules.

For instance, a situation that we dealt with a week or so ago, we found that there were a bunch of rules that the individual wrote in their Microsoft 365 tenant to reroute emails to different accounts, and once we discovered those rules, we were able to r- remove them and any configuration changes that the malicious attacker had made that then gave the customer back control over their 365 tenant. So for the eradication process, you wanna remove all malicious artifacts that you discovered through your triage, detection and analysis process You want to review the incident analysis and perform vulnerability remediation through all of your endpoints.

Now, one thing I will recommend is even though you might have discovered what endpoints were involved in the incident, it probably behooves you to do a complete analysis and vulnerability remediation across all of your endpoints to ensure that those devices are not subjected or susceptible to those attack vectors that were used by the malicious actor And then we want to look at improving security controls. This is where the procurement policy piece comes in that I talked about earlier. If you need to implement new security countermeasures, if you have the policies in place for exceptions, you can go out and make those procurements and implement those new tools that harden your environment.

The, it's the recovery piece after you've done the eradication, meaning you've gotten rid of the malicious actors' footprints and presence in your environment, now you're going through system recovery. Depending on the size of your business, the system owner's gonna have to determine when is the best time to go through that process, because it might affect production. It also depends on the extent of the incident itself. If you're dealing with, let's say, a law enforcement related issue, you're gonna have to coordinate that with them, because the thing that you don't wanna do is get rid of pertinent evidence that can be used in the prosecution.

Once you get law enforcement involved, you are more than likely headed down the prosecution route. You're gonna work with your teams to determine what tests need to be run and how long those tests need to be run, and you're gonna develop a criteria that will indicate that the integrity of those systems has been restored so that you can then begin to resume production usage of your infrastructure. The post-incident review, you're gonna review everything that happened in the incident up to that point. You're gonna review the timelines of all activities. You're gonna review all the communications that happened d- during that timeline.

And the reason why you're doing this is because you wanna see where there are any deficiencies in your process that need to be improved upon. You gotta look at all the incident details and descriptions that help you to understand how effective your processes were when they were executed. You gotta look at the individuals to understand whether they had the proper skillsets to support the incident response process efficiently. You're gonna determine what areas are in your plan that you need to improve upon, and then you're gonna test that again just to make sure that they are properly integrated and function as you expect.

Generally, this lessons learned session is probably what gets most ignored, and the reason being is because the staff are generally of the mindset that they just wanna get things back up and going so that they can get back to work. It's more than likely the incident response process is gonna fall on staff There's fatigue from the late hours and the stress and pressure being applied upon them to get the systems back up and going.

The last thing they wanna do is sit down and do a lessons learned, but this is as valuable as the other three components of the incident response process because it helps you understand where you're deficient and what you need to do in order to show up so that that process goes a lot more efficiently the next time you need to execute it. So that's the preparation and the response process. Let's talk a little bit about some things that you need to do to reduce the vulnerability to cyber incidents. Here, what we've done is we've laid out areas of focus based on the levels of maturity of your business.

Uh, if you are a new or s- very small business with small staff, level one items are where your focus needs to be. So data backup and re- restoration, endpoint security, network and endpoint security, privileged access management, vulnerability management, and incident response are really where your focus needs to be in order to ensure that you are being proactive, that you're putting in place the right countermeasures to harden your business against a cyberattack. At level two maturity, you're looking more at operations. You're looking at management of managed detection and response.

You're looking at regular recurring cybersecurity assessments to identify issues in your business and your technology infrastructure that need to be remediated. As you're adding more technology to your business, as it's growing, as you're making changes to your business, you're inadvertently introducing new risks into your business, and you want to identify that through the assessment, cybersecurity assessment process, so that you can mitigate those risks and keep your infrastructure and business operations hardened Disaster recovery, a more official process of recovering a business when critical, recovering operations when critical systems have been taken offline.

That does require secondary systems, maybe even a secondary location. But with today's cloud infrastructure, much easier to do than in the past because it's really just an allocation of separate resources to support disaster recovery. And at level three, now you're looking at more management level strategies like risk management, risk register management, which is basically a listing of all the risks that have been identified in the organization, and the remediation that's, uh, assigned to those risks, or an acceptance. Some risk you can't accept without having to do anything about it.

You will indicate that so that you can focus your team on those risks that you can accept and that you need to remediate intentionally. Governance related to strategy around cybersecurity, as well as policy development, supporting what the organization's going to do to implement the right cybersecurity program and operations, uh, to continuously protect the business.

And then you might even look at getting a, a CISO, a chief information security officer, either in a full-time or fractional basis to help guide you through these things, and the value there is that the CISO, who should understand the industry that you're in, can also help you understand what regulatory requirements you have to meet to ensure that you're not exposed to any liability. A- another part of the proactive countermeasures that you need to be taking, doing regular vulnerability scans to identify and remediate vulnerabilities, conducting your cybersecurity assessments on a biannual or an annual basis.

One key item here is conducting security awareness for your employees on a regular basis, and what this does is this keep, keeps your employees vigilant in how they use your data and your systems on a daily basis. Tools like KnowBe4, which is a very popular tool that h- can help facilitate canned training and assessment, I highly recommend because that, as I mentioned before, your employees are the weakest link in your security operations, and you can harden that link by taking your employees through regular awareness training And then just being aware of the malicious insider, those individuals that have the deep keys to the kingdom that can affect some serious damage on your business.

You wanna make sure that you've got countermeasures in place to prevent that from happening. We talked about working with HR, for instance, if you're gonna be terminating that individual, having compartmentalized credentials in place to prevent that individual from having complete access throughout your entire environment. Those things are all useful. Online account protection. Every one of us on this call has about 40 to 50 online accounts that we use or that we have used over our digital lifespan. Online accounts are one of the very easy ways that an attacker can get access to your digital life, particularly if you're using weak credentials.

You wanna use MFA and have that enabled on your email accounts at the very least. And we offer some rules, tips, and guidance in the YouTube video that we put together that talk about how you can create compartmentalization and other, uh, techniques that you can use to strengthen your, your online accounts. Cyber liability insurance are extremely important, especially during the time of an incident from a financial perspective. Not only can they make money available to you, but they can also make resources available to you as well. Resources like, uh, forensic examiners or incident response technicians that can help you address the incident.

Um, components of cyber li- liability insurance that you wanna consider, uh, te- technology errors and omission and cyber liability are those things that you wanna consider having, uh, as a part of your, uh, insurance, um, platform. Uh, we do... We've got-- We are gonna be offering a webinar on this, uh, later on in the year, uh, to talk in detail about, uh, cyber liability insurance and what you need to do in order to be prepared for it. So where do we go from here? Um, we do offer a, uh, incident response planning template, uh, that you can use to help outline your incident response process. Uh, you can customize this template for your needs.

Uh, I highly recommend you consult an IT or cybersecurity resource to help you, to support you in the development of that template. Uh, and you can consult an insurance broker about the, the, uh, li-- cyber liability that we've talked about Uh, and with that I will open it up for, uh, questions and answers. Um, if you... When you have a moment, if you would, uh, do us a favor and take this survey, uh, about this particular webinar to help us improvement- improve it as we go along, uh, in the future, that would be extremely appreciated. So I'll turn it back over to you, Stacey. Cyrus, thank you so much.

Uh, I have been collecting some of the questions, uh, that we've gotten in our Q&A and in our chat. There is a specific question from John, Marja, and Brenda, but I think it's gonna be covered in our upcoming webinar on May 21st, which is focused on insurance. So just some questions around qualifying for insurance, recommendations or references or resources for some insurance, and then costs, the range of costs. Like, what does the insurance environment look like? But as a reference for everyone, we will be covering that specific topic on May 21st. But Cyrus, if you have anything to comment on it, that would be awesome. Yeah.

So the cost of insurance varies, depends on your carrier, but the process is changing. It used to be that to qualify for cyber liability insurance, you just had to fill out a checklist. Do you have a firewall? Do you use malware software? Do you have passwords on your accounts? Those kinds of things. And most people would check yes. But what insurance companies were finding is that as claims were rising, they were realizing that they needed to do more due diligence to ensure that the... was actually doing the due diligence to protect their environment.

So not only do you get that checklist, now you have to provide artifacts that show your password architect- or nomenclature, your firewall configuration, your incident response plan, um, any vulnerability analysis that you've done on a regular basis, any policies and procedures that you have around cybersecurity. So you're gonna have to do a lot more work in order to qualify for insurance. And that's why the last slide I recommended engaging an IT professional in cybersecurity because they can help guide you through that process.

If your business is mature enough, you might wanna look at getting a V- of some sort, fractional or full-time, that can help guide you through that process and make you ready for insurance. But insurance is a very valuable tool. It's widely available these days. Most carriers do offer it. If you do have an incident and you're... don't measure up to the due diligence, you will get dropped, and it'll make it harder in the future to get insurance. So that's the climate that we're dealing with today.

I recommend getting some type of IT professional to help you address the due diligence piece Yeah, Cyrus, I think that's why I think understanding what those requirements are is gonna be really helpful for our participants. So John, I hope that helps. And Marja and Brenda. Brenda had a follow-up question asking, does SOC 2 and penetration testing help their cybersecurity efforts? Absolutely. If you go through a SOC 2 assessment or penetration testing, you are definitely showing due diligence. As a matter of fact, most insurance companies are gonna require you to do at least a pen test on an annual basis, not only to get insurance, but to maintain it as well.

So if you're going through either one of those, SOC 2 is a very rigorous process and assessment of the environment that shows the due diligence, so that's one way to do it. Penetration testing is a very technical way to go about it. I recommend both. SOC 2 is more of a paper-based assessment. Penetration test is an on-the-ground, hands-on keyboard test of your actual infrastructure, which is complementary to the SOC 2 assessment Great affirmation too. I have a question in here regarding when clients are utilizing and accessing all of their software through third parties like Zoom, Calendly, what do we need to consider in protection of our clients when those third party platforms are included?

Yeah. So the more third party platforms you integrate into your environment, the more risk you integrate as well. Tools like Calendly are very useful for booking, but because they integrate into your office or your client, your calendar client, they open up to whatever the vulnerabilities or risks are for those tools that you're opening up. And so you wanna make sure that you do your research. If there have been some previous incidents with these tools, you wanna know that, because if you are going for insurance, for instance, and you're exposing yourself to these tools, then you are mitigating your insurability as a result. So do your research. It's hard to test these tools.

Um, the only way you're really gonna know is if there have been incidents that have happened and people have reported them through user reviews and things like that indicate that they've had some negative experience with those tools. So I would do the research before you integrate those tools into the environment tenants or your business in any way, shape, or form, and see what their mitigation or warranties or liability are in the agreements that you would sign with them to determine whether or not you would have recourse against them if your business was impacted through a vulnerability in their tools. And when it comes to... A few questions in here.

Can you recommend any monitoring, reporting, and alerting tools that you would say would be most beneficial? Yeah. The most common one is Microsoft's Sentinel SIM tool. If you have an Azure environment, that comes with that tenant Some of the bigger ones on the marketplace like Splunk or LogRhythm or Nable are also tools that you can use. But those are very large solutions typically meant for large organizations. The ones that I think that can be easily i- i- implemented and scaled to the business is SentinelSIM. We make a tool called DataShare Analytics that can be scaled to the business as well. So those are some recommendations that I would suggest you look at.

And depends on the size of your business. You might be a Splunk or Nable candidate. If you are, more power to you because they are very challenging to implement. But if you're not, SIM or DataShare Analytics are tools that you can use as well that are easier and scalable to your size. Awesome. Thank you for that. And I think we just have one more question, and if anyone else has anything that you wanna pop into the chat or, like I mentioned, you can come off mute. I think we can push it through for maybe a couple more minutes here. Any advice on how to proceed when working with a company that has had a previous data breach? Yeah.

So the vendor risk management process is that process that you want to engage in when you're dealing with a partner company. And basically the vendor risk management process is a set of steps That the partner needs to engage in to prove their due diligence and vigilance implementing the right technical procedures to ensure that they are doing everything they can possibly do to protect their environment. So as a part of the contract that you might establish between the two parties, you wanna make sure that there's a vendor risk management component to that contract that stipulates that they need to do this before the contract can be considered executed.

And there are many, many ways to do that. AI can help provide some guidance in that. You can Google it. We also offer a risk management template that you can use to guide you through the step-by-step process of establishing the right relationship between two partners. Cyrus, thank you so much for all of this valuable information. Anyone who's on the line still, if you didn't take the survey, please, I know it's such valuable information to data defenders and bringing such great quality content and support to all of their clients. I'm gonna go ahead and attempt to copy and paste our upcoming seminars, our webinars into the chat. So if you have the opportunity to take note, the dates are there.

So please join us again. And I just wanna say thank you again to Cyrus. I can't wait for our other four sessions this year. Absolutely fantastic. I know that everybody on the line was really informed, and I hope that everyone has a few great key takeaways to take on. And this recorded, it'll be sent out, and we really appreciate you so much. Thank you so much, and thanks to everybody for joining us today. Thank you. Have a wonderful day. Thanks, everyone.

← Back to Podcasts