Takeaway: CISA’s Shield Up Guidance Emphasizes Incident Response Planning
With the specter of an expanding war in Europe, the threat of cyber retaliation by Russia, or Russian-sponsored actors, is increased. In response, the Cybersecurity and Infrastructure Security Agency (“CISA”) released its Shields Up Guidance to help organizations and supply chains withstand and prepare for a malicious Russian cyber-attack. The guidance is aligned with previous recommendations from CISA and National Institute of Standards and Technology (“NIST”).
A central theme of the Shields Up Guidance is incident response: putting in place a proper plan in the event of a cybersecurity incident. Indeed, a strong incident response plan (“IRP”) is a pillar of a viable cybersecurity program, as it encourages accountability and helps promote a culture of security.
To get started, it’s important to identify an organization’s most critical data and infrastructure. Once critical data and infrastructure are identified, the organization can assign roles to people who form the Incident Response Team (“IRT”). The IRT is the standard-bearer for how the organization will defend its critical data assets. The IRT meets regularly to augment and execute on the IRP. The IRT also assumes responsibility for triaging and responding to an active incident. It is important to define all roles with specificity and to engage in training exercises to ensure that all people understand their responsibility.
A critical responsibility of the IRT is escalating incidents to senior management and the proper external authorities. Under its Shields Up Guidance, CISA makes it clear that organizations should lower the threshold for reporting cyber incidents. That is, even minor incidents that are blocked by security controls should be reported to CISA.
In addition to the internal IRT, organizations will want to identify critical third-party experts to help execute the IRP. The IRT will coordinate with technical experts and legal counsel to ensure that the breach is reported to the proper authorities, the threat is contained and eradicated, and the organization is ready to safely resume operations.
CISA’s Shields Up Guidance provides more information about how to pursue and implement an IRP at https://www.cisa.gov/shields-up.