Learning Objectives:

  • Understand the incident response lifecycle.

  • Develop and implement an incident response plan.

  • Recognise the role of incident response in cyber resilience.

  • Apply incident management frameworks to central bank operations.

4.1 The Incident Response Lifecycle

Incident response is the process of detecting, containing, and recovering from cyber incidents. The Skills for Africa course includes “incident response planning and management” as a core topic . The SEACEN course covers “incident response and recovery planning, including the design and execution of cyber exercises at institutional and industry levels” .

Incident Response Stages:

Preparation: Establishing incident response capabilities, including policies, procedures, and trained personnel. The Central Bank of Eswatini’s Guidelines require that financial institutions plan for information-sharing through trusted channels in the event of an incident, collecting and exchanging timely information that could facilitate the detection, response, resumption and recovery of its own systems and those of other sector participants .

Detection and Analysis: Identifying and analysing potential incidents. The Guidelines require that financial institutions “identify cyber threats that could materially affect its ability to perform or to provide services as expected” .

Containment, Eradication, and Recovery: Containing the incident to prevent further damage, eradicating the cause, and recovering affected systems. The Skills for Africa course covers “recovery strategies and restoration of critical services” .

Post-Incident Activity: Conducting a post-mortem analysis to identify lessons learned and improve incident response capabilities.

4.2 Developing an Incident Response Plan

An incident response plan should document the procedures for responding to cyber incidents. The Skills for Africa course includes “developing and implementing risk mitigation strategies” as a core topic .

Key Elements of an Incident Response Plan:

Roles and Responsibilities: Clearly defined roles and responsibilities for incident response team members. The Central Bank of Eswatini’s Guidelines require that “the cyber resilience framework should be supported by clearly defined roles and responsibilities of the financial institution’s board (or equivalent) and its management” .

Procedures: Documented procedures for detection, analysis, containment, eradication, and recovery. The Guidelines require “reporting requirements and capabilities should be consistent with information-sharing arrangements” .

Communication: Communication protocols for internal and external stakeholders. The Guidelines require that financial institutions “plan for information-sharing through trusted channels in the event of an incident” .

Escalation: Procedures for escalating incidents to senior management and regulators. The Skills for Africa course covers “threat intelligence sharing among central banks” .

4.3 Incident Response Coordination

Internal Coordination: The Central Bank of Eswatini’s Guidelines require that “the cyber resilience framework should outline the institution’s people, processes, and technology requirements for managing cyber risks and timely communication, enabling the institution to collaborate with relevant stakeholders to effectively respond to and recover from cyber attacks, whether on the financial institution or on the financial system as a whole” .

External Coordination: The Guidelines require that financial institutions “participate actively in information-sharing groups and collectives, including cross-industry, cross-government and cross-border groups to gather, distribute and assess information about cyber practices, cyber threats and early warning indicators” .

4.4 Incident Response Exercises

The SEACEN course includes “the design and execution of cyber exercises at institutional and industry levels” . The Skills for Africa course covers “incident response planning and management” . The Central Bank of Eswatini’s Guidelines note that “cyber threat intelligence should be used to ensure that the implementation of any cyber resilience measures is threat-informed” .