< ciso
brief />
Tag Banner

All news with #incident response tag

281 articles · page 3 of 15

Accelerating AWS security investigations with Kiro CLI

🔐 This post shows how Kiro CLI, an AI-powered command line assistant, speeds AWS security investigations by proposing, explaining, and optionally executing AWS CLI commands while documenting each step. It demonstrates a GuardDuty-driven investigation following the AWS Security Incident Response Guide: triage, EC2 and IAM assessment, CloudTrail analysis, containment, and remediation. The walkthrough highlights benefits like faster triage, automated CloudTrail queries, and guided remediation, while advising human validation and forensic preservation.
read more →

Law enforcement disrupts SocGholish infections at scale

🛡️ International law enforcement agencies cleaned nearly 15,000 WordPress sites and took down over 100 servers tied to the SocGholish botnet and the Evil Corp cybercrime group as part of Operation Endgame. Authorities from the Netherlands, Canada, the United States, and Germany removed malware and backdoors from 14,971 compromised sites, advised remediation steps, and decommissioned 106 servers and domains. The action aims to deny criminals access, limit malware spread, and reduce risks to critical infrastructure.
read more →

Lessons from 22,000 Breaches for Incident Preparedness

🔍 The 2026 Verizon DBIR analyzed over 22,000 confirmed breaches across 145 countries and concludes that organizations cannot patch fast enough to prevent every incident. Exploitation of vulnerabilities became the leading initial access vector as critical flaws and their remediation windows grew, while ransomware and third-party breaches surged. The report urges realistic, technical tabletop exercises that rehearse containment, communication, and coordination under time pressure.
read more →

SOC Speed Gap: How Attack Timelines Compressed Fast

⚠️ This article launches Unit 42's series Inside the Modern SOC, drawing on customer environments, SOC assessments and investigations to highlight a defining challenge: the speed gap. Attack timelines have compressed dramatically — in some cases from initial access to data exfiltration in about 72 minutes — driven by identity-driven tactics and AI-accelerated adversaries. The piece emphasizes that manual, sequential workflows and fragmented tooling leave defenders behind and argues for automated correlation, predefined response actions and behavior-focused detection to close the gap.
read more →

JLR CISO Ordered In-Person Password Resets

🔒 At Infosecurity Europe, Ashish Shrestha, then group CISO of Jaguar Land Rover, recounted the September 2025 cyber-attack response that required over 30,000 staff to reset passwords on site. He said the in-person resets ensured trusted identities for communications after the incident and validated Microsoft 365 integrity. The firm also reset MFA and validated users’ identities physically to mitigate risks of remote account takeover.
read more →

Normalcy Bias and the Risk of Criminal ‘Auditors’

🔍 Normalcy bias leads organisations to assume “no news is good news” about security, delaying detection and response. This complacency lets cybercriminals effectively perform their own audits, exposing gaps between perceived and actual security. The article urges proactive testing, continuous monitoring, and investment in MDR/MXDR and awareness to prevent costly breaches.
read more →

How enterprises fall short of military cyber readiness

🛡️ Military cyber teams rehearse constantly using realistic, dynamic simulations while many enterprises treat security as a compliance exercise. The article contrasts rigorous military practices — continuous exercises, defined roles, and realistic cyber ranges — with corporate annual tabletop drills that fail to reflect daily adversary innovation. It urges businesses to adopt regular live simulations, AI Proving Grounds, clear decision-making hierarchies, and cross-industry intelligence sharing to build operational cyber resilience.
read more →

Ukraine’s resilience lessons for cybersecurity planning

🛡️ Dmytro Kuleba, Ukraine’s foreign minister from 2020–2024, told Infosecurity Europe that pre-planning and contingency-driven resilience underpinned Ukraine’s survival after the 2022 full-scale invasion. He described a December 2023 attack that knocked KyivStar offline via a single compromised employee account, and praised rapid recovery and hardened defences thereafter. Kuleba advised organisations to rehearse crisis responses, understand systems intimately, and build instinctive survival practices. He warned that even benign third-party CRM tools can be weaponised for targeted intelligence, urging technological sovereignty and strict data security.
read more →

Crisis communications playbook for cyber incidents

🛡️ Senior cybersecurity leaders at Infosecurity Europe 2026 urged organisations to prepare concise, practical crisis playbooks that focus on defining the type of incident, roles and decision authority, and responsibilities. They emphasised that playbooks must be adaptable to unfolding realities, and that human factors — fatigue management, clear communication and staff welfare — are as vital as technical response steps.
read more →

Resilience and Self-Reliance in Cyber Conflict

🛡️ Dmytro Kuleba, Ukraine’s former foreign minister, told Infosecurity Europe that preparation, resilience and self-reliance are crucial for cybersecurity professionals facing wartime threats. He cited KyivStar’s rapid recovery from a December 2023 hack and stressed the value of wargaming and muscle-memory incident response. Kuleba warned that innocuous services such as CRMs can be weaponized and urged businesses to distrust products from potential adversaries.
read more →

Executives and CISOs Must Treat Cyber as Statecraft

🔒 Bharat Thakrar of ISACA’s London Chapter told Infosecurity Europe 2026 that cyber, AI and geopolitics are now inseparable and warned against treating security as merely an IT problem. He cited breaches like Sony Pictures (2014), Viasat (2022) and Stryker (2026) to show private firms can be legitimate geopolitical targets. Thakrar proposed the Cyber Geopolitical Preparedness and Response (CGPR) framework—assess exposure, evaluate readiness, plan response and continuous monitoring—and urged geopolitical stress‑tests, revamped HR vetting, tighter access controls and predefined executive authorities.
read more →

Microsoft Exchange Online outage delays emails

📧 Microsoft is addressing a widespread service issue impacting the mail flow pipeline for Exchange Online customers in North America and Germany. Users reported SMTP deferral errors and abrupt connection closures, causing significant delays or failures when sending and receiving email. Engineers are investigating incident EX1331830 to identify root causes and restore normal service.
read more →

NCSC: Act Now to Build Cyber Resilience

🔒 Paul Chichester of the NCSC warned at Infosecurity Europe that escalating technological change, geopolitical tensions and evolving threats make predicting cyber risk harder than ever. He highlighted hyper-connectivity, rapid tech transformation and state-backed cyber operations as key challenges, and urged stronger public-private collaboration. Chichester praised the Cyber Security and Resilience Bill and called for practical steps like reducing attack surface, addressing legacy systems, enforcing access controls and running incident exercises.
read more →

Seven tabletop exercise mistakes that undermine readiness

🛡️ Discussion-based, low-stress simulations let IT, legal, and business leaders walk through hypothetical incidents to test preparedness, but poorly run tabletops can mislead and harm response capabilities. The article outlines seven common mistakes — from lacking clear objectives and testing only familiar scenarios to favoring conceptual scripts over practical ambiguity — and offers expert recommendations to design realistic, business-relevant exercises. Emphasis is placed on including the right stakeholders, introducing technical detail and uncertainty, and aligning scenarios to actual risks and interdependencies to avoid false confidence and reveal true process gaps.
read more →

Semperis to Stage War Room Tabletop at Infosecurity

🛡️ Semperis will host "Enter the War Room: A Tabletop Experience" at Infosecurity Europe 2026, a 90-minute red team vs blue team simulation based on real retailer ransomware incidents. The immersive exercise places participants in a fast-moving, multi-stage cyber-attack on a fictional supermarket, testing detection, decision-making, communication and executive escalation. Attendees will work with reformed hackers and defenders from government, law enforcement and industry to identify blind spots and sharpen crisis playbooks.
read more →

Microsoft resolves outage impacting MFA setup access

🔧 Microsoft confirmed and mitigated an incident that prevented some users from setting up multi-factor authentication and accessing the My Sign-Ins site, where affected users encountered 504 Gateway Timeout errors. The company failed over to alternate infrastructure and monitored telemetry while evaluating further mitigations. Microsoft later restored the service, attributing the outage to a cache configuration change that caused high CPU and memory load during an EU traffic peak.
read more →

How Google SRE Uses Agentic AI to Improve Operations

🤖 Google SRE describes how agentic AI augments traditional Site Reliability Engineering across the software lifecycle, from design and deployment to incident response and postmortems. The team applies AI agents for anomaly detection, playbook maintenance, alert enrichment, and automated mitigation while enforcing strong controls for security, explainability, and business continuity. Their approach pairs Gemini-based models and internal platforms with existing observability and governance practices.
read more →

CERT-In urges tighter remediation timelines amid AI risks

🔒 India’s cybersecurity agency, CERT-In, has issued a framework urging organizations to patch, mitigate, or isolate known exploited internet-facing “crown jewel” systems within 12 hours where feasible, citing AI-assisted attacks that compress exploitation timelines. The 38-page blueprint prescribes tiered remediation windows—one day for externally exposed critical flaws, three days for critical internal issues, and five days for high-severity vulnerabilities—while emphasizing temporary mitigations and continuous exposure management over periodic assessments.
read more →

Incident-hardened CISOs earn greater trust

🔍 ISC2 research of 796 cybersecurity professionals shows that leaders who've managed real, high-profile incidents gain greater credibility. Over three quarters agreed such experience boosts trust, with 35% strongly agreeing. The survey finds outcome or blame of the prior incident is less relevant than the experience itself. Respondents emphasised a blend of technical and strategic skills, plus clear communication and team development.
read more →

Microsoft previews automatic device isolation feature

🛡️ Microsoft is previewing an automatic device isolation feature in Defender for Endpoint to help contain active cyberattacks by severing most network traffic while preserving connections to security services. The capability is part of its auto attack disruption tool within Defender XDR, and Microsoft says actions are time-limited and can be tuned or reversed by administrators. A new SANS Institute paper warns threshold-driven autonomous containment can be weaponized to disable user accounts, underscoring the need for careful configuration and governance.
read more →