it's important for organisations, regardless of whether they opt for in-house forensics or outsourced, to have a basic understanding of forensics readiness to ensure investigations are conducted using forensics principles. The same applies for incident response. An outsourced provider can triage events to a certain extent but depending on the MSSP model you opt for, your outsourced provider won't be able to remediate all incidents to ensure BAU. They can provide you with the necessary context and information (if they manage your EDR they can even isolate affected endpoints), but the BAU part tends to be in-house hence having an internal incident response plan is also vital. Lastly - remember to test these using table top exercises, and ensure post-mortems are also conducted after legitimate incidents as these highlight areas of improvement, or help you confirm your plan is adequate.
Content you might like
Any tips for evaluating/implementing solutions for application detection and response? What’s your experience been like with these tools so far?
Has your organization experienced model denial of service attacks on its LLM?
Yes47%
Not to my knowledge52%
Not sure
View Results
We’re evaluating a new ERP. Our company, PROENERGY is a vertically integrated power partner (gas plant design/build, O&M, manufacturing including our PE6000 turbine, and 2.6 GW ERCOT operations).
Considering: SAP Public Cloud, Oracle Fusion Cloud, Microsoft Dynamics, IFS, and Infor Construction Cloud.
Key needs: manufacturing, complex structure with built-in consolidation/reporting, long-range planning, procurement/inventory, and core accounting.
We use Microsoft Dynamics today for CRM/Field Service. Biggest concerns: implementation partners and support resources.
it's important for organisations, regardless of whether they opt for in-house forensics or outsourced, to have a basic understanding of forensics readiness to ensure investigations are conducted using forensics principles. The same applies for incident response. An outsourced provider can triage events to a certain extent but depending on the MSSP model you opt for, your outsourced provider won't be able to remediate all incidents to ensure BAU. They can provide you with the necessary context and information (if they manage your EDR they can even isolate affected endpoints), but the BAU part tends to be in-house hence having an internal incident response plan is also vital. Lastly - remember to test these using table top exercises, and ensure post-mortems are also conducted after legitimate incidents as these highlight areas of improvement, or help you confirm your plan is adequate.