"Don't panic!" David Gray on Incident ResponseAt some point you will be breached. Those organisations who think it will never happen to them are just an incident waiting to happen. But what happens when a breach occurs? What should you do? What processes and approaches should you have in place? These are just some of the questions that organisations should be asking themselves.

At the NTT University in Berlin, David Gray, Senior Manager & Practice Lead, NTT Security talked with Enterprise Times about incident response. Perhaps the most important thing that Gray had to say was “Don’t Panic!” Panic creates mistakes in resolving an incident. It leads to hurried decisions that could cause more damage than the actual breach.

David Gray, Senior Manager & Practice Lead, NTT Security
David Gray, Senior Manager & Practice Lead, NTT Security

As in any other crime, the first 24 hours is important. The information that the IT security team gathers is still fresh and may not be complete. Management needs to recognise that if it is going to start making public statements, they are just initial estimates. As Gray points out, many recent breaches have had to revise the size of the breach several times.

Gray also talked about the planning and preparation that organisations need to put in place. One area that few do well is the practice of a breach response. This is fast becoming a requirement not just a play book that sits on the shelf until it is called into action.

To hear more of what Gray had to say listen to the podcast

Where can I get it?

obtain it, for Android devices from play.google.com/music/podcasts

use the Enterprise Times page on Stitcher

use the Enterprise Times page on Podchaser

listen to the Enterprise Times channel on Soundcloud

listen to the podcast (below) or download the podcast to your local device and then listen there

Previous articleRamco wins business in North America
Next articleOutlook for fintech in 2019
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here