Having an established and tested plan of action for a cybersecurity incident is crucial to limit cost and damage to the organization’s reputation. Often, proper response during an incident is also necessary to maintain regulatory compliance.
Our many decades of real-world experience responding to cybersecurity incidents has taught us that chewy, book-like incident response plans may provide convincing evidence for a compliance auditor but are worthless during an actual incident.