How to Contain a Cybersecurity Incident

96 views
β€’
July 18, 2018
by
RSAC Cybersecurity
YouTube video player
How to Contain a Cybersecurity Incident

TL;DR

Effective incident containment starts by observing symptoms, determining the incident's scope, and assessing affected assets before choosing whether to isolate systems immediately or monitor them longer. The right action depends on the attack's behavior, available evidence, business impact, privacy concerns, and operational obligations, so technical responders must coordinate with legal, HR, developers, and client-facing stakeholders.

Transcript

I'd like to, uh, my name is Bobby Stimpley, and I'd like to welcome you here today for the panel discussion this afternoon with two, uh, incredibly talented individuals. Um, Terry from, Terry Griffith, who is the, I never can get your title right, Director of Incident Management at Royal Caribbean Cruise Line. Exactly. And I need to thank you for p... Read More

Key Insights

  • Containment is the effort to prevent further damage while preserving forensic information, but its practical execution varies according to the incident type, the response stage, and the evidence available when decisions must be made.
  • Effective containment is based on scope, because responders must consider both how to stop an infected asset or user from affecting others and how to protect additional assets from the same threat.
  • Initial observation is a critical response activity, because visible symptoms, network communications, and on-screen behavior help responders identify what may be happening before they disconnect a device or allow it to continue operating.
  • Premature isolation can create a Whac-A-Mole response, because disconnecting one compromised machine without finding other affected systems may cause the intruder's activity to reappear elsewhere while yielding little useful understanding.
  • High-value asset status influences containment speed, because a system containing guest information or supporting point-of-sale operations can require a different decision from a system whose purpose and business importance remain unclear.
  • Prepared containment strategies give response teams practical options, including blocking inbound or outbound traffic, isolating affected machines, and segmenting networks, while standard operating procedures help staff know which technical actions are available.
  • Business impact is part of containment decision-making, because shutting down systems can affect clients, service-level agreements, and the organization's ability to operate, requiring coordination beyond the security and incident response teams.
  • Ransomware behavior determines the response, because evidence that malware is trying to spread can justify immediate network disconnection, while ransomware that does not spread may allow more time to understand the affected system and its role.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should a cybersecurity team begin incident containment?

A cybersecurity team should begin by absorbing the available symptoms and examining what the affected machine is doing. Relevant observations include network communications, visible screen activity, signs of movement toward other systems, and the importance of the affected asset. That initial assessment helps the team decide whether to disconnect the device immediately or observe it longer to understand the incident's scope.

Q: When should responders disconnect an infected device?

Responders should disconnect an infected device quickly when the observed behavior indicates an urgent risk of further damage, such as ransomware attempting to spread to other systems. The decision also depends on whether the device is a high-value asset, contains guest information, supports point-of-sale functions, or presents privacy concerns that lead legal stakeholders to recommend immediate isolation.

Q: Why can immediate containment make an incident harder to manage?

Immediate containment can make an incident harder to manage when responders act before determining its full scope. Disconnecting one compromised machine may remove useful visibility while leaving other compromised systems active. The intruder can then appear on another system, creating a Whac-A-Mole pattern in which the team repeatedly reacts without understanding or effectively containing the broader incident.

Q: How does incident scope affect containment decisions?

Incident scope determines whether a proposed action will contain the whole problem or only one visible symptom. Responders must identify how an infected asset or user could affect others and determine whether additional assets face the same threat. Because complete information is rarely available immediately, teams accept some uncertainty while gathering enough evidence to make containment effective.

Q: What technical methods can teams use for containment?

Technical containment methods discussed by the panel include blocking inbound traffic, blocking outbound traffic, isolating affected machines, and segmenting affected parts of the network. These actions should be supported by strategies and standard operating procedures prepared before an incident. The selected method depends on the evidence, attack behavior, affected assets, and potential consequences for continued business operations.

Q: Which stakeholders should participate in containment decisions?

Containment decisions may require security operations and incident response staff to work with legal, HR, developers, asset owners, and employees who interact with clients. These stakeholders help identify privacy requirements, system functions, client effects, and operational consequences. Their input enables an informed decision when a technical containment action could interrupt services or affect the organization's ability to execute.

Q: How should a team contain a ransomware incident?

A team should first determine how the ransomware behaves. If evidence shows that it is trying to spread or find another system to attack, disconnecting the affected machine from the network can limit further movement. If the ransomware does not spread, responders may choose a different pace so they can understand the affected system's purpose and the business impact of shutting it down.

Q: How do business obligations influence cyber containment?

Business obligations influence containment because isolating systems or shutting services down can affect clients, service-level agreements, and normal operations. Security leaders must explain the actions they are considering and ask relevant stakeholders to assess the consequences. The resulting decision balances the need to prevent further damage with privacy concerns, customer impact, system importance, and the organization's ability to continue operating.

Summary & Key Takeaways

  • Cybersecurity containment is more complicated than simply limiting damage while preserving forensic information. The appropriate response changes with the incident type, its current stage, and the available evidence. Responders must first understand visible symptoms and decide whether immediate isolation or continued observation offers the safer and more informative course of action.

  • Acting too quickly can hide the incident's true scope. Disconnecting one compromised system before identifying other affected systems can create a frustrating Whac-A-Mole pattern in which the intruder repeatedly appears elsewhere. Skilled analysts therefore examine system behavior and communications rapidly, giving incident leaders enough evidence to choose an effective containment direction.

  • Containment requires both technical and business decisions. Response teams may block traffic, isolate machines, or segment networks, but those actions can affect clients, service-level agreements, and normal operations. Legal, HR, developers, asset owners, and client-facing teams may need to evaluate privacy, operational, and customer consequences before disruptive actions occur.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š