One of the most critical steps to Incident Response is the initial triage phase. The same can be said of the decision Paramedics make when responding to emergency calls. During this presentation we will review how to properly triage an incident based on the information available while relating the process back to real life emergencies.
Watch the recorded presentation here: ig2.me/o5
2. Who Am I
TECHNICAL
• B.S. Digital Forensics
• CISSP
• InfoSec Analyst – Duo
Security
• Incident Response
• Security Awareness
Training
NON-TECHNICAL
• Family
• Mom of three… fur
babies
• Memorizing movie lines
• Searching for new
music
• DIY projects
• Taking naps
Kendra Cooley - @4n6Kendra
24. ASSESSING THE IMPACT
INFOSEC
FUNCTIONAL
ARE CRITICAL FUNCTIONS
DISRUPTED?
INFORMATIONAL
HAS DATA BEEN
COMPROMISED?
EMS
SITUATION
WHAT WAS REPORTED?
SEVERITY
IS IT LIFE THREATENING?
27. Category: car accident
Scenario 1
Caller witnessed a
single car accident
One passenger: male,
26 years of age
Driver status: Out of the
vehicle, fully coherent
with a visibly broken
wrist
29. Category: car accident
Scenario 2
Caller witnessed a car
accident
One passenger: male,
26 years of age
Driver status: Out of the
vehicle. Complaining of
dizziness. Laceration to
left side of his head
36. Category: Phishing campaign
Scenario 2
Employee reports a
suspicious email
immediately after:
• Clicking the link
• Entering their
credentials on a
fake Google site
38. Category: Phishing campaign
Scenario 3
Employee reports
odd email activity
What they know:
• Hundreds of
emails have
been sent from
their account
containing an
attachment
40. Spotting the similarities
Priority Level Car Accident Phishing Campaign
High
LIGHTS AND SIRENS
Additional resources needed
‘Worst case’ scenario
Medium
LIGHTS AND SIRENS
Additional resources may be needed
Scenario could potentially get worse
Low
Additional resources not needed
Unlikely to cause further damage
Something else could take priority over this
41. Why does this matter?
A new perspective
Seemingly similar
categories resulted
in extremely
responses
46. How can we improve?
MANAGERS
• Support your Analysts
• Implement a strong IR
process
• Organize your
resources
• Put more emphasis on
triage
• Be flexible
ANALYSTS
• Trust your gut
• Focus less on the
category
• Understand the
information in front of
you
• Be flexible
47. Key Takeaways
• Triage is more than categorization
• Triage sets the tone for the rest of the process
• Treat each situation as unique
• Not every incident requires ‘lights and sirens’