Mapping Leadership Talent To Cybersecurity: Part 6, Recover
And eventually -- it stops. They move on. You are victorious, but frazzled. Now is the time to take stock, rebuild relationships, and prepare for the next engagement. Time for the final NIST CSF pillar, Recover. Let's let Brendan discuss it : Recover is the step you take to undo the damage or restore the service. Recover is a bit more deliberate and thoughtful than Respond. You have time pressure, almost always, but there is rather less of it. The cybersecurity crisis is over, but if you need to keep your systems down for the recovery, then the operations crisis has just begun: how long can the downtime continue, in the name of preventing future problems and gathering evidence? The answer depends on your situation. Your ability to arrive at that answer often depends on how well thought-out your IRP is. Recover should always end with a review that considers how to be better in the future. This is a crucial step to making you safer than you were before. It is very common to just want...