How to Create an Insider Incident Response Plan

It’s time for organizations to face reality: the sheer amount of cyber attacks essentially confirms that organizations will at some point be under attack by an insider – maliciously or not. It is therefore important that organizations have an intelligent incident response plan in order to mitigate the effects of a breach. In 2015, 62% of organizations that responded to AT&T’s Cyber Security Insights report admitted to being breached, but only 34% believed they had an effective incident response plan in place.

How to Create an Insider Incident Response Plan

Chuck Brooks, vice president at Sutherland Global Services stated explained:

“Breaches can happen and likely will happen sooner than later.”

Instilling the vitality of a on Insider Incident Response Plan. The first step in creating this plan is to accept the reality and recognize that an incident response plan is a business imperative. Guy Bunker from Clearswift states that:

“The first failure a company makes is not having a plan”.

Implementing technology to detect and event prevent insider threats is a vital aspect of an Insider Incident Response Plan, but understanding how to use it is just as important. Begin by creating a policy and standards to help define what can and cannot happen within the network, and once there is an understanding as to where the organization’s data and critical assets are located, so access violations can be monitored. It is extremely important that response teams are empowered to act on the Response Plan when a breach infolds:

“Dose the incident response team have the necessary authority to confiscate or disconnect equipment and monitor suspicious activity if required? If legal, HR, security, audit and leadership are not involved in defining the plan, legal rights could be compromised during a cyber incident” says Kyle F. Kennedy, CISO at Cyber Security Network, instilling the importance of cohesion within the team for a successful response plan.

Organizations need to build the right team as part of their Insider Incident Response Plan. Within the team there needs to be a combination of leadership and expertise, so selecting people that are up to date on the changing digital threat landscape as well as thorough knowledge about the network is quintessential. Senior Cyber security office at the U.S Department of Treasury Steven Fox believes:

“An incident response plan relies on an influential leader that can both articulate the business need for IT investments and rally the associated technical expertise.”

ALSO READ: 8 Convincing Statistics About Insider Threats

It is vital for an organization to be ready and prepared to handle an insider threat in a timely and consistent way which includes understanding and knowing who needs to be involved, who has the authority, who should be coordinated with, whom to report to, what actions need to be taken, and what improvements to make to the network following the incident. The overall goal of an Insider Incident Response Plan is to Prevent, Detect and Respond.

For a Insider Incident Response Plan to be successful multi-level training and awareness needs to come first. All staff need to understand what an insider threat is and the types of activities and motivations that surround it. Similarly staff need to know the consequences of an incident both for the individual and the organization. Throughout training and refresher courses, staff should be explained what to report, to who and when regarding suspicious human or computer activity. At the same time it is important staff understands how their computer activity is monitored while connected to the network. There are of course different types of processes for different types of insider threats including fraud, theft of IP, espionage and sabotage and these should also be discussed during trainings.

Part of the Insider Incident Response Plan is how to handle the aftermath of the attack. It is really important that retraining is at the forefront of the response so that other members of staff understand how insider attacks happen, both accidentally and maliciously.

An incident like an insider attack can be detrimental to an organization so if such an attack takes place, it is important to learn from it in order to prevent further attacks from occurring. In some respects, and insider attack is the best opportunity to learn. Organizations can learn from their response to the attack, and in fact this response consideration should be an important part of an Insider Incident Response Plan. This is an opportunity to update policies, procedures and practices that may be out of date – though it is not recommended to wait until after an attack to update policies!

The CERT Software Engineering Institute has written this Top 10 List for winning the battle against insider threats:

  1. Learn from past incidents
  2. Focus on protecting the “crown jewels”
  3. Use your current technologies differently
  4. Mitigate threats from trusted business partners
  5. Recognize concerning behaviors as a potential indicator
  6. Educate employees regarding potential recruitment
  7. Play close attention at resignation/termination
  8. Address employee privacy issues with General Counsel
  9. Work together across the organization
  10. Create an insider threat program now!

Rosie Goldsack

Rosie Goldsack

With 5 years experience in content creation in the media and technology industries, I am always on the lookout for the next big thing to write about. My educational background in literature and linguistics taught me the rules of writing, while my professional experience has brought back to me the joy of writing. Information security has always been an interest of mine and I am happy to be able to share with Teramind readers the importance and value of online security. Rosie can be contacted at

You may also like...

4 Responses

  1. August 31, 2017

    […] actor this data could provide enough information about a user to turn them into a significant insider threat to their employers. This is only the beginning of its […]

  2. October 12, 2017

    […] incident response plan that may have been required for past regulations. What is different about an insider incident response plan is that this plan provides specific protocols and processes for handling breaches that were caused […]

  3. November 22, 2017

    […] MORE: How to Create an Insider Incident Response Plan Why Data Breach Lag Time Matters The Rise of Threat Hunting 3 Things Deloitte Could’ve Done […]

  4. November 24, 2017

    […] MORE: How to Create an Insider Incident Response Plan How to Enlist Employees in Your Battle Against Insider Threats 4 Ways to Prepare Employees for […]

Leave a Reply

Your email address will not be published. Required fields are marked *