Learning Objectives:
-
Understand the stages of the incident response lifecycle and their interconnections.
-
Apply the FSB’s seven-component framework for effective cyber incident response.
-
Recognise the importance of governance and preparation in incident response.
-
Develop a structured incident response plan aligned with international best practices.
1.1 The Incident Response Lifecycle
Incident response is the structured process of detecting, containing, and recovering from cyber incidents. The FSB’s report on “Effective Practices for Cyber Incident Response and Recovery” provides a comprehensive framework for financial institutions, structured across seven components . The FSB notes that “efficient and effective response to and recovery from cyber-incidents by organisations in the financial ecosystem is essential in limiting any related financial stability risks,” such as interconnected IT systems, loss of confidence, and impacts on capital . The FSB emphasised that “a major cyber-incident, if not properly contained, could seriously disrupt financial systems, including critical financial infrastructure, leading to broader financial stability implications.”
The industry-recognised incident response lifecycle (Identify, Protect, Detect, Respond, Recover) provides a comprehensive framework for managing cyber incidents. The “Respond” phase encompasses the activities of detection, analysis, containment, eradication, and recovery. The FSB’s framework provides detailed guidance on each of these activities .
1.2 The FSB’s Seven Components of Cyber Incident Response
The FSB has identified seven components of effective cyber incident response and recovery :
1. Governance: Frames how cyber-incident response and recovery is organised and managed. This includes establishing clear roles and responsibilities, defining escalation paths, and ensuring accountability. The FSB notes that governance is the foundation for effective incident response .
2. Preparation: Establishes and maintains capabilities to respond to cyber-incidents and to restore critical functions, processes, activities, systems and data affected by cyber-incidents . This includes developing incident response plans, establishing communication protocols, and conducting training and exercises.
3. Analysis: Ensures effective response and recovery activities, including forensic analysis, and determines the severity, impact and root cause of the cyber-incident to drive appropriate response and recovery activities . The Central Bank of Eswatini’s Guidelines require financial institutions to have procedures in place for collecting, logging and analysing security-relevant events in order to trigger actionable security alerts or initiate the security incident process.
4. Mitigation: Prevents the aggravation of the situation and eradicates cyber-threats in a timely manner to alleviate their impact on business operations and services . This includes containment activities to limit the spread of the incident and eradication activities to remove the threat.
5. Restoration: Repairs and restores systems or assets affected by a cyber-incident to safely resume business-as-usual delivery of impacted services . This includes recovering data from backups and restoring systems to normal operation.
6. Improvement: Establishes processes to improve response and recovery capabilities through lessons learned from past cyber-incidents and proactive tools, such as tabletop exercises, tests and drills .
7. Coordination and Communication: Coordinates with stakeholders to maintain good cyber-situational awareness and enhances the cyber-resilience of the ecosystem . The Central Bank of Eswatini’s Guidelines require financial institutions to plan for information-sharing through trusted channels in the event of an incident .
1.3 Incident Classification and Prioritisation
The Central Bank of Eswatini’s Guidelines provide an incident classification framework :
High: The incident affects the whole organisation. All or most of the institution’s critical systems are affected.
Medium: The incident affects a section/division or multiple business units. It affects some part of the institution’s operations.
Low: The incident affects an individual or a small group of people and has little or no impact on the institution’s operations.
The Central Bank of Trinidad and Tobago’s mandatory cybersecurity incident reporting requires financial institutions to report incidents that may have characteristics of a material nature, including systemic impact, financial market impact, data impact, business disruption, disaster declaration, reputational impact, severity, and risk appetite breach . The G7’s “Fundamental Elements of Ransomware Resilience for the Financial Sector” provides additional guidance on incident classification and prioritisation.
1.4 Developing an Incident Response Plan
An incident response plan should document the procedures for detecting, containing, and recovering from cyber incidents. The Central Bank of Eswatini’s Guidelines require that the cyber resilience framework should be supported by clearly defined roles and responsibilities and that management should create a culture which recognises that staff at all levels have important responsibilities in ensuring the institution’s cyber resilience . The FSB’s report on “Effective Practices for Cyber Incident Response and Recovery” provides comprehensive guidance for developing incident response plans .
The plan should include:
-
Roles and Responsibilities: Clearly defined roles for incident response team members.
-
Procedures: Documented procedures for detection, analysis, containment, eradication, and recovery.
-
Communication: Communication protocols for internal and external stakeholders.
-
Escalation: Procedures for escalating incidents to senior management and regulators.
-
Recovery: Procedures for restoring systems and data.