How To
Avoiding a Meltdown: The Management Incident Response Team
How your company handles a data breach can make the difference between survival and extinction.
By James Christiansen
The MIRT's preincident planning should start by developing realistic scenarios that could arise; typical examples would deal with external fraud, a malicious insider, a technology hack, lost media, a data center disaster and an external security breach.
The next step is to create a high-level set of tasks that must be done in each scenario. Examples include: Notify the MIRT of the incident (this task is usually assigned to the CIRT, members of which may also be part of the MIRT); gather the facts of the incident; determine who should be notified; create the notification letters and notices. Given the members of the MIRT are leaders in your organization, a completely detailed task plan is not necessary or appropriate, but a list of tasks in the form of a RACI (responsible, accountable, consulted and informed) chart can be very effective.
As part of your scenario exercise, prepare the press releases and major stakeholder communications for review by your executive team and your internal and external public relations teams. The style of the communication is very important; it should be informative, take responsibility and reassure your audience that the matter is being handled. The CISO can help by compiling a reading file for members of the MIRT consisting of studies and thoughtful news stories covering similar events in your industry and elsewhere.
Thorough preparation will put your company in a position to minimize the impact of a breach. Without preparation, you may be lucky even to survive it.
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



