SlideShare a Scribd company logo
1 of 15
Download to read offline
Incident Response
One Thing
Shaun Mouton
Tirefi.re, Friendgineering Directorate
Ops, some)mes
Incident Response
the old good way
thanks for everything
John Allspaw and crew, of Etsy
Incident Response Response
the new old way
thanks for everything
people who didn't read what Allspaw & co.
wrote
or listen to what they said
Incident Response Response
Response
the new new way
thanks for everything
Allspaw, Sidney Dekker & the Lund U.
Crew
<3 J Paul Reed
See Also, These Things
Karl Katzke's Aus.n Devops talk about
incident response at Kasasa
Boyd Hemphill's talks about workflows at
Contrast Security
An Update From The Field
OH: holy shit incident command with indignant engineers is wild
style!!!!!1
The Gri(y
I leave Chef this month a0er nearly 4 years
I have worked at least 75 Severity 1 incidents for in that 8me,
mostly for F100 enterprises.
(more than 75 less than 380, our tracking for who worked what
could have been be=er)
The Gri(y, Ni(y
3/4 of the people who've reached out to me have commented
about my ability to remain cool under pressure.
I have heard something similar from folks in previous jobs
I do not think you have to be a chonky white dude to have folks
appreciate your value in a crisis.
Incident Response To-Do List 1
Chill Out.
If you're gonna lose your job due to this, you can find a less
stressful job elsewhere.
Incident Response To-Do List 2
Calm Down.
There are enough people panicking already.
Incident Response To-Do List 3
Be Reasonable.
If nobody's able to run through the "is it plugged in? what does the
error log actually say? do I need to go peepee?" list at least once an
hour folks will be was:ng effort and burning themselves out.
Incident Response To-Do List 4
Hand it Off.
If you have an idea and need to dig into something, make sure that
someone's stepping into the "adult in the room" role, even if it's not
the person everyone thinks is the incident commander.
Incident Response Mantra
I will not improve this situa2on by giving in to a panic response
That's It
Incident Response: One Thing

More Related Content

Similar to Incident Response: One Thing

Disorders and Treatments PaperThis assignment will require you t
Disorders and Treatments PaperThis assignment will require you tDisorders and Treatments PaperThis assignment will require you t
Disorders and Treatments PaperThis assignment will require you t
DustiBuckner14
 
Conflict Mediation
Conflict MediationConflict Mediation
Conflict Mediation
beitzjr
 
1. The assignment is worth 100 points and 20 of your gradea. Su.docx
1. The assignment is worth 100 points and 20 of your gradea. Su.docx1. The assignment is worth 100 points and 20 of your gradea. Su.docx
1. The assignment is worth 100 points and 20 of your gradea. Su.docx
jeremylockett77
 

Similar to Incident Response: One Thing (20)

The Last HOPE - Black Hat To A Black Suit
The Last HOPE - Black Hat To A Black SuitThe Last HOPE - Black Hat To A Black Suit
The Last HOPE - Black Hat To A Black Suit
 
Atlassian Summit 2012 - A Communication Cadence
Atlassian Summit 2012 - A Communication CadenceAtlassian Summit 2012 - A Communication Cadence
Atlassian Summit 2012 - A Communication Cadence
 
12 surprising job interview tips
12 surprising job interview tips12 surprising job interview tips
12 surprising job interview tips
 
Rogues At DNI Aug 06 Part 1
Rogues At DNI Aug 06 Part 1Rogues At DNI Aug 06 Part 1
Rogues At DNI Aug 06 Part 1
 
Disorders and Treatments PaperThis assignment will require you t
Disorders and Treatments PaperThis assignment will require you tDisorders and Treatments PaperThis assignment will require you t
Disorders and Treatments PaperThis assignment will require you t
 
Linchpin
LinchpinLinchpin
Linchpin
 
Linchpin
LinchpinLinchpin
Linchpin
 
Conflict Mediation
Conflict MediationConflict Mediation
Conflict Mediation
 
Job Interview: ESL Discussion: How to approach personal questions 2
Job Interview: ESL Discussion: How to approach personal questions 2Job Interview: ESL Discussion: How to approach personal questions 2
Job Interview: ESL Discussion: How to approach personal questions 2
 
Business processes
Business processesBusiness processes
Business processes
 
How to deal with difficult people - Timothy Dimoff
How to deal with difficult people - Timothy DimoffHow to deal with difficult people - Timothy Dimoff
How to deal with difficult people - Timothy Dimoff
 
30 Brilliant marketing growth hack cards.
30 Brilliant marketing growth hack cards.30 Brilliant marketing growth hack cards.
30 Brilliant marketing growth hack cards.
 
It's Not Your Fault - Blameless Post-mortems
It's Not Your Fault - Blameless Post-mortemsIt's Not Your Fault - Blameless Post-mortems
It's Not Your Fault - Blameless Post-mortems
 
Following your fear - Gatineau Ottawa Agile Tour 2016
Following your fear  - Gatineau Ottawa Agile Tour 2016Following your fear  - Gatineau Ottawa Agile Tour 2016
Following your fear - Gatineau Ottawa Agile Tour 2016
 
Learning to say no
Learning to say noLearning to say no
Learning to say no
 
Effective Brainstorming: How to Harvest Constructive Creativity | Seattle Int...
Effective Brainstorming: How to Harvest Constructive Creativity | Seattle Int...Effective Brainstorming: How to Harvest Constructive Creativity | Seattle Int...
Effective Brainstorming: How to Harvest Constructive Creativity | Seattle Int...
 
Things I Believe Now That I'm Old - Ross Tuck - Codemotion Milan 2014
Things I Believe Now That I'm Old - Ross Tuck - Codemotion Milan 2014Things I Believe Now That I'm Old - Ross Tuck - Codemotion Milan 2014
Things I Believe Now That I'm Old - Ross Tuck - Codemotion Milan 2014
 
Four ‘Magic’ Questions that Help Resolve Most Problems - Introduction to The ...
Four ‘Magic’ Questions that Help Resolve Most Problems - Introduction to The ...Four ‘Magic’ Questions that Help Resolve Most Problems - Introduction to The ...
Four ‘Magic’ Questions that Help Resolve Most Problems - Introduction to The ...
 
Time and Priority Management
Time and Priority ManagementTime and Priority Management
Time and Priority Management
 
1. The assignment is worth 100 points and 20 of your gradea. Su.docx
1. The assignment is worth 100 points and 20 of your gradea. Su.docx1. The assignment is worth 100 points and 20 of your gradea. Su.docx
1. The assignment is worth 100 points and 20 of your gradea. Su.docx
 

Recently uploaded

21P35A0312 Internship eccccccReport.docx
21P35A0312 Internship eccccccReport.docx21P35A0312 Internship eccccccReport.docx
21P35A0312 Internship eccccccReport.docx
rahulmanepalli02
 
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
drjose256
 
Seizure stage detection of epileptic seizure using convolutional neural networks
Seizure stage detection of epileptic seizure using convolutional neural networksSeizure stage detection of epileptic seizure using convolutional neural networks
Seizure stage detection of epileptic seizure using convolutional neural networks
IJECEIAES
 

Recently uploaded (20)

Software Engineering Practical File Front Pages.pdf
Software Engineering Practical File Front Pages.pdfSoftware Engineering Practical File Front Pages.pdf
Software Engineering Practical File Front Pages.pdf
 
21P35A0312 Internship eccccccReport.docx
21P35A0312 Internship eccccccReport.docx21P35A0312 Internship eccccccReport.docx
21P35A0312 Internship eccccccReport.docx
 
UNIT 4 PTRP final Convergence in probability.pptx
UNIT 4 PTRP final Convergence in probability.pptxUNIT 4 PTRP final Convergence in probability.pptx
UNIT 4 PTRP final Convergence in probability.pptx
 
Insurance management system project report.pdf
Insurance management system project report.pdfInsurance management system project report.pdf
Insurance management system project report.pdf
 
5G and 6G refer to generations of mobile network technology, each representin...
5G and 6G refer to generations of mobile network technology, each representin...5G and 6G refer to generations of mobile network technology, each representin...
5G and 6G refer to generations of mobile network technology, each representin...
 
Passive Air Cooling System and Solar Water Heater.ppt
Passive Air Cooling System and Solar Water Heater.pptPassive Air Cooling System and Solar Water Heater.ppt
Passive Air Cooling System and Solar Water Heater.ppt
 
Interfacing Analog to Digital Data Converters ee3404.pdf
Interfacing Analog to Digital Data Converters ee3404.pdfInterfacing Analog to Digital Data Converters ee3404.pdf
Interfacing Analog to Digital Data Converters ee3404.pdf
 
Maximizing Incident Investigation Efficacy in Oil & Gas: Techniques and Tools
Maximizing Incident Investigation Efficacy in Oil & Gas: Techniques and ToolsMaximizing Incident Investigation Efficacy in Oil & Gas: Techniques and Tools
Maximizing Incident Investigation Efficacy in Oil & Gas: Techniques and Tools
 
handbook on reinforce concrete and detailing
handbook on reinforce concrete and detailinghandbook on reinforce concrete and detailing
handbook on reinforce concrete and detailing
 
SLIDESHARE PPT-DECISION MAKING METHODS.pptx
SLIDESHARE PPT-DECISION MAKING METHODS.pptxSLIDESHARE PPT-DECISION MAKING METHODS.pptx
SLIDESHARE PPT-DECISION MAKING METHODS.pptx
 
Intro to Design (for Engineers) at Sydney Uni
Intro to Design (for Engineers) at Sydney UniIntro to Design (for Engineers) at Sydney Uni
Intro to Design (for Engineers) at Sydney Uni
 
21scheme vtu syllabus of visveraya technological university
21scheme vtu syllabus of visveraya technological university21scheme vtu syllabus of visveraya technological university
21scheme vtu syllabus of visveraya technological university
 
UNIT-2 image enhancement.pdf Image Processing Unit 2 AKTU
UNIT-2 image enhancement.pdf Image Processing Unit 2 AKTUUNIT-2 image enhancement.pdf Image Processing Unit 2 AKTU
UNIT-2 image enhancement.pdf Image Processing Unit 2 AKTU
 
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
 
Artificial Intelligence in due diligence
Artificial Intelligence in due diligenceArtificial Intelligence in due diligence
Artificial Intelligence in due diligence
 
Seizure stage detection of epileptic seizure using convolutional neural networks
Seizure stage detection of epileptic seizure using convolutional neural networksSeizure stage detection of epileptic seizure using convolutional neural networks
Seizure stage detection of epileptic seizure using convolutional neural networks
 
8th International Conference on Soft Computing, Mathematics and Control (SMC ...
8th International Conference on Soft Computing, Mathematics and Control (SMC ...8th International Conference on Soft Computing, Mathematics and Control (SMC ...
8th International Conference on Soft Computing, Mathematics and Control (SMC ...
 
engineering chemistry power point presentation
engineering chemistry  power point presentationengineering chemistry  power point presentation
engineering chemistry power point presentation
 
Developing a smart system for infant incubators using the internet of things ...
Developing a smart system for infant incubators using the internet of things ...Developing a smart system for infant incubators using the internet of things ...
Developing a smart system for infant incubators using the internet of things ...
 
Worksharing and 3D Modeling with Revit.pptx
Worksharing and 3D Modeling with Revit.pptxWorksharing and 3D Modeling with Revit.pptx
Worksharing and 3D Modeling with Revit.pptx
 

Incident Response: One Thing

  • 1. Incident Response One Thing Shaun Mouton Tirefi.re, Friendgineering Directorate Ops, some)mes
  • 2. Incident Response the old good way thanks for everything John Allspaw and crew, of Etsy
  • 3. Incident Response Response the new old way thanks for everything people who didn't read what Allspaw & co. wrote or listen to what they said
  • 4. Incident Response Response Response the new new way thanks for everything Allspaw, Sidney Dekker & the Lund U. Crew <3 J Paul Reed
  • 5. See Also, These Things Karl Katzke's Aus.n Devops talk about incident response at Kasasa Boyd Hemphill's talks about workflows at Contrast Security
  • 6. An Update From The Field OH: holy shit incident command with indignant engineers is wild style!!!!!1
  • 7. The Gri(y I leave Chef this month a0er nearly 4 years I have worked at least 75 Severity 1 incidents for in that 8me, mostly for F100 enterprises. (more than 75 less than 380, our tracking for who worked what could have been be=er)
  • 8. The Gri(y, Ni(y 3/4 of the people who've reached out to me have commented about my ability to remain cool under pressure. I have heard something similar from folks in previous jobs I do not think you have to be a chonky white dude to have folks appreciate your value in a crisis.
  • 9. Incident Response To-Do List 1 Chill Out. If you're gonna lose your job due to this, you can find a less stressful job elsewhere.
  • 10. Incident Response To-Do List 2 Calm Down. There are enough people panicking already.
  • 11. Incident Response To-Do List 3 Be Reasonable. If nobody's able to run through the "is it plugged in? what does the error log actually say? do I need to go peepee?" list at least once an hour folks will be was:ng effort and burning themselves out.
  • 12. Incident Response To-Do List 4 Hand it Off. If you have an idea and need to dig into something, make sure that someone's stepping into the "adult in the room" role, even if it's not the person everyone thinks is the incident commander.
  • 13. Incident Response Mantra I will not improve this situa2on by giving in to a panic response