New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

IR and SimEx: Can and should they be standardized?

New York Tech Editorial Team by New York Tech Editorial Team
January 17, 2022
in Cybersecurity
0
IR and SimEx: Can and should they be standardized?
Share on FacebookShare on Twitter

The National Cyber Security Centre (NCSC) intends to launch a new assurance scheme for incident response (IR) and simulated exercises (SimEx) in Q2 2022, which could become a real gamechanger for the security sector. This will effectively see the standardization of IR and SimEx across the board and extend the commercial reach, opening new markets to assured providers.

IR SimEx

But is standardization necessary and how will it change things?

Previously, the NCSC only provided the Cyber Incident Response (CIR) Service – soon to be renamed CIR Level 1 – aimed at UK Central Government and large businesses with complex IT systems deemed to have networks of “national significance”. The new CIR service will extend that reach significantly to encompass local businesses, large businesses and SMEs while the new Cyber Incident Exercising Service will target large and medium organizations as well as central and regional UK Government. Such will be the scale of the endeavor that the NCSC intends to recruit Assured Scheme Partners to vet and onboard Assured Service Providers and to police the scheme.

Putting it into practice

It will be interesting to see how the NCSC intends to tailor the assurance scheme to accommodate these new target markets.

The government body is currently selecting its Assured Scheme Partners with whom it intends to work with to devise the operating model and to help determine how it will implement its technical standards across both services. But IR and SimEx are very different beasts. Whether undertaken pre- or post-attack, incident response typically requires the business to go through a prescribed set of steps to triage an incident, so it naturally lends itself to being incorporated into a framework. The same cannot be said of SimEx, which can vary enormously.

SimEx can range from entry level desktop exercises through to full-blown simulations and enable teams within the business to respond to a given attack scenario. They may take the form of a ransomware or phishing attack, DDoS simulation, or sensitive data being published on the dark web, for instance. Multiple actor roleplay then ensues which sees the tester perhaps simulate a call from the attacker demanding a ransom or pretend to be a member of the press enquiring about a breach. The best exercises, i.e., those that yield the most insight, are those that see the initial incident evolve to encompass other departments, so that the attack goes on to ensnare IT, security, and PR, and are designed to test how these teams work together.

The goal of a simulated exercise is to practice, evaluate or improve the IR plan so the real learning comes from how well the incident response process performs. How closely is the IR plan followed? Should the Information Commissioner’s Office be contacted and in which timeframes? Did the comms team know what they should when discussing a with press? Did the technical team remediate using due process? Was evidence safeguarded and protected? This will require the new assurance scheme to set specific tolerances to determine how well departments functioned.

An open market

Although it’s not yet known how the new Cyber Incident Exercising Service will accommodate this range of activities, the NCSC has stated that it will cover table-top and live-play formats. Presumably it will offer a sliding scale of increasingly complex services which should bring some much-needed transparency to the market. One of the chief issues with SimEx today is that once the business looks at testing its IR, costs can begin to spiral, so a formal structure with different methodologies will let teams know exactly what they’ve signed up for and how much bang they’re getting for their buck.

However, as we emerge from the pandemic, many cash-strapped businesses may still regard SimEx as too costly. Yet choosing not to test IR in this way could equally be seen as a false economy. This is because one of the biggest benefits associated with the process, which is that these exercises help steer investment.

Rather than the organization continuing to blindly invest in technology and assuming that its policies are being adhered to, these tests gauge the effectiveness of security measures by using attack scenarios that the organization is likely to face in the current threat landscape, informing the business of what is/isn’t working and where the gaps lie so that future spend becomes focused. Plus, these exercises can also be used to protect the business in other ways, by determining if third-party vendors are sticking to their service commitments and enabling the business to hold them to account, for example.

Adding the SimEx service alongside its IR service is a natural next step for the NCSC but a highly significant one for the security sector. The transparency which the NCSC scheme promises to create will help open the market and drive adoption, making standardization beneficial for business customers and service providers alike, with the latter able to get their IR and SimEx services ratified against the NCSC’s standards, providing them with a new route to market. And the more IR plans that are put through their paces, the better security will become, making standardization a win-win for everyone.

Credit: Source link

Previous Post

Global Polishing Grinding Robot Market Analysis by Industry Size (2021 -2027) – ABB, LXD Robotics, Acme Manufacturing, SHL, Fastems

Next Post

BlueVine sells invoice factoring business to Canadian rival FundThrough

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
BlueVine sells invoice factoring business to Canadian rival FundThrough

BlueVine sells invoice factoring business to Canadian rival FundThrough

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026
Employee Time Tracking

What is an Employee Time Tracking Solution? A Definite Guide for 2026

March 31, 2026
Voltify founders

Voltify Raises $30 Million Seed Round as It Challenges $1 Trillion Rail Electrification Model

March 31, 2026

Recommended

laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media