eSecurity Solutions Articles/Blog
Search by Keyword
Blog Categories
Security Breach Checklist: What to Do When There’s a Breach
Published On:May 16, 2024 By: Tom Ruffolo 

Post Security Breach / Post Attack / Incident Response Checklist
Cyber-attacks effect companies of all sizes. Larger companies know that they are targets of attacks and spend and plan accordingly to respond to cybersecurity breaches with security breach checklist/ incident response plans.
Many smaller businesses though, think that they are less likely to be attacked, but in fact recent data, shows that for companies with less than 1,000 employees, they were the target of 82% of all ransomware attacks, and 46% of all cyber breaches.
And further, 37% of companies hit by ransomware had fewer than 100 employees. And looking generally at cyber-attacks, 61% of SMBs were the target of some type of cyberattacks in a single year.
When cybersecurity breaches happen, not all are successful in their attacks, but all require a planned incident response by your company.
Your Security Breach Checklist / Incident Response Checklist
Stop the Attack
Shut down infected
devices, networks etc until you can determine root cause
Initial Forensic Analysis
Do a quick analysis to determine the root cause and high-priority actions
Define Your Incident Response for this Incident
Define initial incident response checklist plan to block, remove attacks, and restore your systems
Restore Any Damage and Systems
If you understand cause and can block and eradicate attack, restore systems
- Deep Forensic Analysis
Commission a deep forensic analysis, Make sure you understand the totality of the attack
- Hire and Create or Amend Any Incident Response Checklists Already Formulated
Perform Security Risk Assessments
Based upon whether you have recently done third-party risk assessments:
Commission a top-level security audit to review all your security
Commission security assessment tests to perform specific security tests like pen tests, network tests, social engineering, configuration testing etc.
- Define Your Security Gaps and Prioritize
- A third-party security audit, readiness assessment and gap analysis will define your top security holes and help you prioritize what is most important to your company.
- Define Your Security Roadmap
By doing a 3rd party security audit, you can easily define a security roadmap focusing on your highest-priority security additions and changes over time.
- Acquire High Priority Security Solutions (Services, Control Products, Policies, Processes)
Work with a partner that can provide the right security products that match your needs and budget as well as managed security as required to help you manage, monitor, and respond.
- Monitor Your Security and IT for Ongoing Issues
Define adequate security monitoring solutions to monitor ideally all your security, key IT, and user behavior. A good security partner can advise which MDR solutions are the best fit for your company. Each MDR solution provides a different scope of monitoring and benefit.
- Plan for Future Security Breach Checklist Changes (Roadmap, Incident Response Plan (or updates)
Take what you learned and update your security roadmap and incident response checklist plans. Use what you learned to enhance your security beyond your most urgent needs to include next-level security as well.
Contact us to help you prepare for the inevitable cybersecurity breach. Yes, we can help you prevent, detect and respond, but all companies should have security risk assessments, incident response plans, and prioritized security roadmaps. Lastly, planning ahead with a security breach checklist and incident response plan, is a critical planning activity for all companies regardless of size.
We can help with all phases of your security and to execute your security beach checklist.
devices, networks etc until you can determine root cause