As a trusted security advisor to both public and private organizations, the following is one of the most important questions we ask our clients at Castellan Information Security (Castellan):
Are you ready to effectively manage a cyber-attack or other incident that breaches your organization's sensitive or confidential information?
Some organizations may, naively, still operate under a false sense of security believing this risk does not apply to them and only really exists in other sectors and with other targets. This approach is dangerous. It is not a matter of if, it's rather a matter of when your organization experiences an information security incident.
One of the most effective strategies to reduce the damage (costs, reputation, downtime) of these incidents is to prepare your organization in advance and develop an emergency management plan so you can properly anticipate and react when the incident occurs.
These 10 questions for CEOs, Executive Directors, Managers, and IT / Security professionals to help identify some potential gaps in your emergency preparedness.
These questions are not intended to be all-inclusive as you develop and implement your organization's emergency management and disaster recovery program in case of data breach. However, they provide a starting point to assess how you would respond.
A common dangerous mistake of organizations is to underestimate the complexity of work that is required to effectively manage the situation and limit the damage of a data breach. Those organizations who have plans in place prior to the event will have better chances at minimizing the costs, overall harm to your corporate reputation, and limiting operational downtime than those that answer "no' to most of these questions.
Castellan Information Security is a Winnipeg-based 'end-to-end' information security company that specializes in information security and have worked with both large and smaller private and public organizations to help them reach their information security objectives. If you have questions about this article or would like to speak to us about how our services can help your company protect its information, please feel free to have a look at our website at www.castellaninformationsecurity.com or contact us directly at info@castellaninformationsecurity.com.