Our Services - Incident Management
Incident management is the process of dealing with security events as they occur: efficiently, discreetly and in alignment to organizational needs. A fundamental question is strategic priority – should the incident be remedied, and business restored as soon as possible, or should steps be taken to investigate the incident and root causes in order to pursue a legal remedy, which may be a civil or even a criminal law matter.
Security Heads quickly identify:
- The number of systems affected
- The degree to which the systems are affected
- The business value and sensitivity of the systems affected
- The relative degree of urgency vs. other incidents
Security Heads take particular care to collect evidence to support a legal case whilst we conduct the following activities:
- Containment – limiting scope and magnitude
- Eradication – eliminating the source or entry point
- Recovery – Returning affected systems to full operation
- Follow Up – Documenting the impact and findings of the incident
