The First 48: The Early Hours of Incident Response

  • Wednesday, February 27, 2013 | 10:40 AM – 11:40 AM | Room: Room 309

View all Sessions

Many large organizations find themselves taken aback when evidence of a major breach or data theft is suddenly uncovered. It's always bad to look for help after your hair is on fire, so you need to plan ahead. Whether you have an internal IR team or not, here are the first ten things you need to do to scope, and begin to respond to a major incident.


This document was retrieved from on Fri, 22 Feb 2019 05:21:46 -0500.