Skip to content
11:11 Systems
The Resilient Cloud Platform
11:11 Systems11:11 Systems
  • Why 11:11
    • Submenu
      • Column 1
        • 11:11 Systems Consulting
          Consulting Services
          Global Regions
          Cloud Regions
          11:11 Systems Security
          Security

      • Column 2
        • Cloud Console
          Cloud Console
          Catalyst
          Planning and Assessment
          Compliance
          Compliance

      • WHY CHOOSE 11:11
      • Overview
      • Leadership
      • News & Media
      • ESG Program
      •  
      • Careers
      • Technology Partners
      • Customer Stories
      • Innovation Blog
  • Products & Services
    • Products & Services

        • Cloud Overview
        • Managed Public Cloud
        • Private Cloud
        • Object Storage
        • Cloud Labs
        • Flexible Cloud Environment/Colocation
        • AWS Solutions
        • Managed OS Services
        • Managed DB Services
        Object Storage

        Premium storage without the premium price

        Buy 11:11 Object Storage now
        BUY NOW
        REQUEST A QUOTE

        • Backup Overview
        • Veeam Backup
        • Microsoft 365 Backup
        • Managed Backup for Cohesity
        • Cyber Vault
        • Data Protection Services
        Backup as a Service

        11:11 Cloud Backup

        Protect your data wherever it lives.
        REQUEST A QUOTE
        REQUEST A DEMO

        • DRaaS Overview
        • DRaaS for Veeam
        • DRaaS for Zerto
        • DRaaS for Azure
        • DRaaS for Cohesity
        • Managed Recovery
        • Cloud Recovery
        • Cyber Recovery Platform
        • Infrastructure Recovery
        • Continuity Consulting Services
        • Disaster Recovery Consulting
        Disaster Recovery

        5TB 30Day Free Trial of DRaaS for Veeam

        Protect your business-critical workloads and reduce recovery time with the Leader in Disaster Recovery.
        START FREE TRIAL
        LEARN MORE

        • Security Overview
        • Continuous Risk Scanning
        • Managed Detection and Response
        • Managed SIEM
        • Extended Detection and Response (XDR)
        • Managed EDR
        • Managed Firewall
        • Application and Zero Trust Services
        Security Services

        Take the first steps toward cyber resilience.

        Download our white paper and learn how to stay ahead of threats.
        REQUEST A QUOTE
        DOWNLOAD NOW

        • Networking Overview
        • SD-WAN
        • Managed Connectivity for AWS Direct Connect
        • Multi-Cloud Connect
        • Network Consulting Services
        Connectivity Services

        Transform your network.

        Take your infrastructure and performance to the next level.
        REQUEST A QUOTE
        WATCH VIDEO
  • Solutions
    • Solutions Submenu
      • INDUSTRY
      • Education
      • Financial
      • Government
      • Healthcare
    • Solutions Business Objective Submenu
      • BUSINESS OBJECTIVE
      • Cyber Resilience
      • Modernize
      • Protect
  • Partners
    • Partners Submenu
      • Overview
      • Become a Partner
      • Partner Portals
  • Resources
    • Resources Submenu
      • Events
      • Webinars
      • News & Media
      • White Papers
      • Podcast
      • Data Sheets
      • Customer Stories
      • Innovation Blog
  • Support
    • Support Submenu
      • Contact Support
      • Product Documentation
      • API Documentation
Search:
  • Login
  • Contact
Header Right Menu
Buy NowFree Trial
  • Why 11:11
    • Consulting Services
    • Cloud Console
    • Cloud Regions
    • Planning and Assessment
    • Security
    • Compliance
    • WHY CHOOSE 11:11
    • Overview
    • Leadership
    • News & Media
    • ESG Program
    • Careers
    • Technology Partners
    • Customer Stories
    • Blog
  • Products & Services
    • CLOUD
    • Cloud Overview
    • Managed Public Cloud
    • Private Cloud
    • Object Storage
    • Cloud Labs
    • Flexible Cloud Environment/Colocation
    • AWS Solutions
    • Managed OS Services
    • Managed DB Services
    • BACKUP
    • Backup Overview
    • Veeam Backup
    • Microsoft 365 Backup
    • Managed Backup for Cohesity
    • Cyber Vault
    • Data Protection Services
    • DISASTER RECOVERY
    • DRaaS Overview
    • DRaaS for Veeam
    • DRaaS for Zerto
    • DRaaS for Azure
    • DRaaS for Cohesity
    • Managed Recovery
    • Cloud Recovery
    • Cyber Recovery Platform
    • Infrastructure Recovery Services
    • Continuity Consulting
    • Disaster Recovery Consulting
    • SECURITY
    • Security Overview
    • Continuous Risk Scanning
    • Managed Detection and Response
    • Managed SIEM
    • Extended Detection and Response (XDR)
    • Managed EDR
    • Managed Firewall
    • Application and Zero Trust Services
    • NETWORK
    • Network Overview
    • SD-WAN
    • Managed Connectivity for AWS Direct Connect
    • Multi Cloud Connect
    • Managed IP
  • Solutions
    • INDUSTRY
    • Education
    • Financial
    • Government
    • Healthcare
    • BUSINESS OBJECTIVE
    • Cyber Resilience
    • Modernize
    • Protect
  • Partners
    • Overview
    • Become a Partner
    • Partner Portals
  • Resources
    • Events
    • Webinars
    • News & Media
    • Whitepapers
    • Podcast
    • Datasheets
    • Customer Stories
    • Innovation Blog
  • Support
    • Contact Support
    • Product Documentation
    • API Documentation
  • Contact
  • Login
  • Buy Now
  • Free Trial
Tags: The NIST CyberSecurity FrameworkCyberSecurity Awareness Month
Author: Brian Knudtson
Date: October 28, 2022

The NIST CyberSecurity Framework: Respond

So you’ve found a cyberattack in your environment. The first step is to not panic. The second step is to pull out your cybersecurity response plan, which you’ve hopefully written down during a non-stressful time well before the incident. If you don’t have that plan documented yet, bookmark this page and go find a reputable incident response service provider to help you out. When you return, we’ll discuss what you should do to prepare yourself for a cyber security incident response.

Due to your efforts to protect yourself in the third phase of the NIST Cybersecurity Framework — “Detect” — you now know you have a cybersecurity incident on your hands. If you haven’t yet read our first three CyberSecurity Awareness Month posts, which highlight the functions of the NIST CyberSecurity Framework, you can find them here (Identify, Protect, and Detect). Today, we tackle the start of the fourth stage — “Respond” — perhaps the most panic-prone stage. The adrenaline involved in responding to a cyberattack is why planning is critical in this phase.

Time is of the essence when fighting back a cyberattack, so figuring out what to do during the attack is not ideal. The plan should be figured out ahead of time and practiced regularly so everyone knows their role during the event. Of course, no plan survives engagement with the enemy, but that is no reason to not have a plan; it’s a reason to have multiple flexible plans focused on what needs to happen. Ultimately, your reaction should be second-nature so your brain can concentrate on analyzing data, not deciding what needs to happen next.

Blue Team … Assemble

One of the most important parts of your incident response plan is to identify the team that needs to be involved. This team should include not only internal employees, but also any external support, including vendor support contacts and third-party incident response, legal, and/or cyber forensics teams. Beyond identifying individuals and teams, the plan should include how everyone will be contacted, which is commonly done via call sheets, notification trees, and group messaging. It should also identify how all the team members will get together and coordinate, which should include both in-person or virtual options. 

Through all this planning, consider what technologies and systems you will be able to rely on during a security breach. For example, if your email server has been breached and you need to isolate it on the network, you will not be able to rely on it to send communications. Also, think of interdependencies that may be compromised. For example, if your Active Directory gets shut down with ransomware, collaboration tools like Teams may not be reliable for collaboration. Once the team is assembled, it’s time to start addressing the incident. 

Stop the Spread

Ideally, while you’ve been assembling, the systems have automatically started the response. Your primary tool here is an endpoint detect and response (EDR) product, which likely also participated in the detection of the intruder and was able to immediately execute the first priority: Stop the spread. By running on endpoints in your environment, EDR is able to directly detect anomalous program executions and block them as soon as it determines something nefarious is going on.

If the EDR tool couldn’t detect the anomalous behavior before it executed, it may be able to cut the system off from the network so that it cannot spread, receive instructions from command and control systems, and participate in data exfiltration. Partnering an EDR tool with managed services (MDR) or extended with technologies like SIEM and SOAR (XDR), can improve the speed in which the breach can be contained. 

Unfortunately, the spread cannot always be contained. This is where having an infrastructure based on zero-trust architecture in place before an attack can be a huge asset by limiting horizontal spread. In a worst-case scenario, you may have to disconnect the entire infrastructure from the internet or shut down the entire data center. 

Cleaning Up

However drastic the containment efforts may need to be, you’ll then need to focus on cleaning out the infection. This may be a system-by-system hunt, but is ultimately highly dependent on the type of infection and is why flexibility in the plan is important. Consider having an incident response team contracted and on-call to help with this effort. 

If it has already spread widely or it required a full data center shutdown, you may benefit from simply failing over the data center to your disaster recovery site. Cybersecurity incident response should closely align with, or simply be a special use case within, your business continuity and disaster recovery (BC/DR) plan. But we’re getting a bit ahead of ourselves, because this is part of the fifth phase. More on that in the next post in the series.

Incident Communications

In parallel with all of this, your organization will need to have a plan for communicating with your key stakeholders. You don’t want to leave key decisions around how and what you will communicate to employees, customers, partners, suppliers, legal counsel, law enforcement, and, possibly, the media until you’re in the heat of the moment. Understanding what different audiences need to hear and when may require coordinating with them during the planning phase. Understanding what legal reporting requirements you need to abide by will definitely need to be known ahead of time. 

Decisions around how often and at what depth you need to communicate will need to be defined and differences based on the audience considered. The key is to communicate early so you don’t get caught letting someone else tell your customers and partners what’s going on. Finally, just like communications amongst the response team, don’t assume any given communications channel will be available. Have multiple ways to communicate to these groups.

Digital Forensics

To close out the Respond phase, you’ll need to address the analysis of the incident. Some of this happens as you go along, but every incident should end with an analysis of what happened, the timeline, ramifications, and what can be done to prevent it in the future. In order to preserve and gather as much data as possible, the identification of key data should be in your plan. This will allow the entire team to gather the data you need to satisfy contractual, legal, and self-improvement obligations. Even if this data isn’t collected along the way, your team needs to make sure it isn’t destroyed as part of the mitigation efforts. Many companies choose to rely on an external digital forensics team to help with this planning and data gathering.

As you can see, there is a lot to be dealt with in a very fast, fluid, and high-pressure situation. Having tools like EDR and response plans in place before an incident occurs are critical to successfully navigating these items.

Categories: Cybercrime, Ransomware, SecurityBy Brian KnudtsonOctober 28, 2022
Tags: The NIST CyberSecurity FrameworkCyberSecurity Awareness Month

Author: Brian Knudtson

In his 20-year career, Brian has experienced many different perspectives of the IT industry. He has worked as a value-added reseller, vendor and service provider in roles in web development, system administration, post-sales deployment, pre-sales architecting, public cloud design and technical marketing. Currently, Brian is the Director of Cloud Market Intelligence at 11:11. He enjoys spending time with his wife and three kids. He is also heavily involved with the Destination Imagination program and has been a long-time member of the VMware community, notably starting the Omaha VMUG and putting on VMunderground at VMworld. You can find him online occasionally blogging at http://knudt.net/vblog and tweeting at @bknudtson.

Post navigation

PreviousPrevious post:The NIST CyberSecurity Framework: RecoverNextNext post:A Career in Cybersecurity? Advice from a CISO.

Related Posts

Digital Operational Resilience Act (DORA)
Helping the Financial Sector Deliver Secure and Modern Infrastructure through Regulation
July 10, 2025
vulnerability management
A Modern Approach to Managing Vulnerabilities
May 30, 2025
Cyber Resilience
Data Protection vs. Cyber Resilience: Mastering Both in the Complex World of Gambling
May 27, 2025
ransomware attack, worst day
The Remedy Against Ransomware: Insights from Our April 2025 Webinar
May 19, 2025
Cyber Resilience
Reimagining Cyber Resilience in the Gambling Industry: A Strategic Imperative for the Digital Age
May 13, 2025
effective passwords
Creating Effective Password Policies in Your Organization
May 5, 2025
PRODUCTS & SERVICES
  • Cloud
  • Backup
  • Disaster Recovery
  • Managed Security
  • Network as a Service
  • Compliance
COMPANY
  • Why 11:11
  • Customer Stories
  • Careers
  • Leadership
  • Technology Partners
  • News & Media
  • Contact Support
CLOUD REGIONS
  • North America
  • EMEA
  • APAC
CONNECT
  • LinkedIn
  • X
  • Youtube

© 2025 11:11 Systems Inc., All Rights Reserved | Privacy Notice | Website Terms of Use |

Go to Top