Expert support for robust incident response planning
An Incident Response Plan (IRP) is a document which sets out an organisation’s strategy for responding to different types of security incidents, including ransomware attacks, IP theft and data breaches.
An incident response plan outlines the specific procedures and responsibilities associated with addressing each stage of an incident, with defined roles for completing specific incident response actions. An IRP is your organisation’s roadmap for taking timely and effective action in the event of disruption caused by a cyber-attack.
Kroll responds to more than 3,000 security events every year, including some of the most complex investigations in the world. Whether you’re looking to validate your existing incident response plan or develop a new one, we are well placed to assist. Our methodology combines our front-line experience of investigating persistent and emerging threats with guidance from leading security standards to fully support the unique needs of your organisation.
- Incident response planning and validation
- Assignment of Incident Response Team (IRT) responsibilities
- Gathering and documenting key information
- Establishing a review and testing schedule
- Developing communications procedures and responsibilities
- Determining the person with authority to declare an incident
- What is incident response?
Incident response is the strategy an organisation uses to manage and mitigate cyber security incidents. Incident response aims to contain and limit the damage and disruption of cyber-attacks. It usually also includes steps to restore business operations as smoothly and quickly as possible.
- What is a security incident?
A cyber incident or cyber security incident is any type of event with the potential to negatively impact an organisation through a compromise of confidentiality, integrity or availability. Types of events include unauthorised data breaches, unlawful data processing or a denial of service.
- What is the most effective way to respond to a security incident?
The best response to a security incident is to follow a clear incident response plan which will have already defined the key actions, people and responsibilities to be involved. Following an incident response plan reduces the risks of damaging delays or mis-steps in response.
- What is an incident response plan?
An incident response plan sets out how an organisation will respond to different types of security incidents. It enables better mitigation of cyber incidents by clearly outlining which actions need to be taken and the people responsible for those steps.
- What does an effective incident response plan include?
A robust incident response plan will cover guidance for:
- Assigning responsibilities between responders
- Setting technical protocols and escalation points
- Defining a strategy for resource-gathering and documentation
- Setting up communications and notification procedures
- Establishing a review and testing schedule
- What are the key incident response steps?
The six main incident response steps are:
- Preparation – incident response planning and process creation
- Identification – information gathering and incident analysis
- Containment – patching and damage limitation
- Eradication – threat removal and mitigation
- Recovery – returning systems to full operation
- Learning – identification of improvements, further testing
Get immediate assistanceGet in touch
Effective response planning - whatever the incident
What’s the first thing you should do when you discover that your organisation has been affected by a security incident? Which steps should you take to contain and minimise the harm to your business continuity and reputation?
Our incident response planning services reduce the potential damage of a cyber incident by setting out a strategic roadmap outlining the steps your organisation needs to take in the event of different types of attacks. Having an IRP in place also communicates to stakeholders and regulators that your organisation is fully committed to addressing new and emerging cyber threats.
Kroll’s incident response planning services can help your organisation become better prepared to respond to:
- Flexible, on-demand services
- Recognised by CREST and the PCI Council
- Global team of cyber risk experts
- >3,200 security incidents responded to every year
Get in touch
Complete the form for a prompt response from our team.