Connect with us

Security

Uncovering the True Leaders of Your Cyber Incident Response Team

Published

on

During a cyber incident, organizations often face a rude awakening: the established structure doesn’t quite hold up. Security is dependent on IT for system and network changes, the CISO is juggling board calls while trying to keep up with the security team’s findings, Legal is figuring out disclosure requirements, and the Communications Manager is seeking guidance on messaging. The missing piece? A formally designated Incident Commander.

Our current incident response paradigm is struggling with unclear roles, conflicting priorities, and uneven organizational design. The Incident Commander role varies across companies, with some viewing it as a primary responsibility and others assigning it as an additional duty to the CISO or a member of the security team.

The traditional approach to incident response focused on containing threats, restoring systems, and conducting post-mortems. However, in today’s landscape, where cyber incidents garner widespread attention, a more holistic approach is needed. This includes technical collaboration across departments, business coordination, and clear decision-making accountability. Regulatory and customer notification timelines kick in quickly, and boards are more attuned to the repercussions of high-impact incidents.

While the scope of incidents has expanded, organizational structures for incident response have not kept pace. Even well-prepared security teams find themselves improvising their coordination efforts during critical moments.

The Essential Role You’re Missing in Your Response

Many incident response programs lack a formally designated Incident Commander, whose role is to coordinate the response across all functions, keep key stakeholders informed without overwhelming them with operational details, and maintain accountability in fast-moving situations.

This role is distinct from the CISO, as conflating the two can lead to challenges. The CISO is responsible for owning the incident organization-wide, while the Incident Commander focuses on orchestrating the response, ensuring team alignment, and protecting the response from unnecessary disruptions.

See also  Massive Data Breach Exposes Millions of Email Logins at ISPs

Often, the CISO or a senior security leader ends up juggling both roles, which can result in slower decisions, coordination gaps, and inadequate communication with executive leadership.

Establishing the Role Before It’s Urgently Needed

While many organizations do not have a designated Incident Commander, the concept is gaining traction, especially in larger entities. Successful approaches involve identifying the role early, intentionally staffing it, and building credibility through practice.

Some organizations assign the role internally within the security team, while others look outside the security department for individuals with strong program management and communication skills. Technical expertise is valuable but not the primary requirement; the ability to coordinate across teams, hold people accountable, and communicate effectively under pressure are essential.

Institutionalizing the Incident Commander role requires proactive efforts before an incident occurs. Leadership should be aware of who runs incidents, not just who owns them. Conducting exercises with realistic scenarios that require cross-functional coordination can build credibility and relationships crucial for effective incident response.

The current incident response approach needs to evolve. Organizations don’t need a complete overhaul; instead, they should define the Incident Commander role, clarify their authority during crises, and establish clear interfaces with other departments and leadership.

Matt Hartley, co-founder and chief product officer of BreachRx, brings over 20 years of experience in cybersecurity, threat intelligence, and information operations. His background includes leadership roles at FireEye and iSIGHT Partners, as well as service in the US Air Force. Matt holds a CISSP and degrees in Computer & Systems Engineering.

For inquiries, reach out to Matt at [email protected] or visit https://www.breachrx.com/.

See also  The Manipulation of Claude: Coercing Instructions for Explosives

Transform the following:

From: “I am going to the store to buy some groceries.”

To: “I will be heading to the store to purchase groceries.”

Trending