Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You have to make sure the attackers aren’t still in your network, you have to get them out if they are, you have to fully scope out what they messed with, and restore anything that’s plausibly connected. Even in the best case with all the right monitoring systems in place there is a lot of manual work involved from owners of the various different effected services and just managing the overall response adequately. I would say the amount of effort involved is comparable to managing a novel, ongoing SEV1.


Additionally there are legal concerns, for both regulatory compliance and for prepping for inevitable litigation. Those concerns aren’t necessarily a blocker for service restoration, but it really depends on the systems involved. If service could be restored by rebooting a system, for example, but that system also has data related to customers’ (and their customers’) PII and it might have been accessed by the attacker, then you need to make sure it’s all properly preserved forensically first, so that you can comply with regulations regarding breach notifications. The forensic analysis could then happen, but it’s definitely a “measure twice, cut once” situation with lots of lawyers involved (they won’t understand the systems, but they’ll make you explain everything so they can make decisions about risk; and they are in charge).

Also, generally, it’s a “fog of war” scenario, where you can have so many unknowns to work through in a compressed time period, and sometimes there’s an active attacker and they get a vote, too.


Wouldn’t you hire an incident response team who are experts in figuring this stuff out?


Depends. Often yes but at Heroku/Salesforce’s scale you really need a lot of security expertise in-house too.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: