Planning for a Cyber Incident - Preparing the Organisation to Respond, Recover & Learn
Speaker
Introduction
Cyber incidents are now a significant operational and corporate governance risk. Organisations face threats including phishing, business email compromise, ransomware, credential theft, data exfiltration and increasingly sophisticated AI-enabled impersonation. While technology is an important part of the defence, cyber incidents frequently exploit human behaviour and weaknesses in organisational processes.
It is therefore no longer sufficient for cyber security to be regarded solely as an IT responsibility. A serious cyber incident can rapidly affect business continuity, finances, confidential and personal information, client relationships, regulatory obligations and organisational reputation. Senior management need to understand not only how cyber incidents can be prevented, but how the organisation will respond when preventative controls fail.
Effective preparation requires the organisation to decide in advance who will take control, how an incident will be assessed and contained, which critical business functions must be maintained, how evidence will be preserved and who may need to be notified. An effective incident response plan provides the framework for making these decisions quickly and in a controlled manner.
This webinar will examine the principal decisions that organisations should make before a cyber incident occurs. It will consider the cyber threat, corporate preparedness, incident command and escalation. The critical first hours following discovery, legal and regulatory considerations, business recovery and the importance of testing and learning from the response plan will be discussed.
The session is designed principally for board members, directors, senior executives, risk and compliance leaders and others with responsibility for organisational resilience and corporate governance.
What You Will Learn
This webinar will cover the following:
- Understanding the cyber threat
- Key questions the Board should be able to answer before a cyber incident occurs
- The predict, prevent and prepare model of incident management
- Building an effective cyber incident response plan
- Incident command and governance
- Business continuity and containment
- Legal, regulatory and reporting considerations
- Recovery and restoration
- Learning from the incident