| | JULY 2024ENTERPRISE SECURITY8IN MY OPINIONIN MY OPINIONHow can I write an article on what we CISOs are all looking for: the almost magic recipe for successful cyber crisis management?The answer is very simple: I don't know how.There is no ultimate recipe for success every time that would be too simple. We'd all keep it tucked away, ready to be used at the slightest opportunity.What I can share with you is my experience of managing a cyber-crisis. Who am I? A CISO who has lived two lives: the first in which I knew full well that the right question was not if a cyber-attack could happen, but when. My second life as a CISO began the day that my company and I, along with it, fell victim to a crypto locker. One of the first things to do in such a cyber-incident is to launch investigations: forensics.Whether you've shut down your IS or not, whether your servers are encrypted or not, if you don't know what hit you or how they did it, you risk a relapse.The only thing that matters at the moment is restarting your company's critical activities as quickly as possible; otherwise, your business could disappear. But you have to restart carefully, with an acceptable level of risk, to avoid any further attacks. There's nothing worse than telling your colleagues that you have to start from scratch because they've done it again.To get through this ordeal, you have to get organised, but you have to invent an organisation, a system that doesn't exist. Each attack and each crisis has its own specificities, and your organisation will have to adapt: local or global, destruction of the IS or compromise of administration accounts, theft of customer data or company data.Your organisation will adapt and evolve as the crisis progresses. At some point, you may no longer need to work 24 hours a day (and this is a very tiring system for night shifts!). Crisis meetings may become less frequent as PREPARING FOR CYBER-ATTACKSBy Thomas Degardin, Group Cybersecurity Director, Bouygues GroupThomas Degardin
<
Page 7 |
Page 9 >