FrontRow

Cybersecurity

Incident Response: Rehearsing the First Hour

Presented by Secarma

What the first hour of a cyber incident actually demands: who escalates, who has authority to act, and how to rehearse it before you find out the hard way.

About this webinar

What this webinar covers

The opening stage of an incident is the worst combination: incomplete facts, competing priorities and decisions that can't wait. Most organisations have a plan on paper and have never walked through it.

Secarma cover recognising when a problem should be escalated as a potential incident, the first decisions teams face while the picture is still forming, and clarifying who actually has authority to make them. There's practical detail on keeping contact lists and escalation routes usable, including alternative channels for when your own systems are the problem, and coordinating internal teams with an external IT provider or specialist support.

They also get into the tension between containing the incident, preserving evidence and keeping the business running, and how a tabletop exercise exposes the gaps. The timing is deliberate: there's a section on out-of-hours cover, delegated authority and key contacts before the Christmas break.

Useful for IT and security, and also for the communications, HR, legal and operations colleagues who get pulled in.

I've sat through a fair few Secarma sessions and they consistently stay on the informative side rather than turning into a sales pitch.

Categorisation

Relevant roles

  • IT & Technology
  • Leadership & Management
  • Cybersecurity & Information Security
  • Risk, Compliance & Governance

Event details are provided for information purposes. Registration takes place directly with the event organiser. Something wrong with this listing?

Related webinars