ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Why ignoring incident response can be costly

Phil Robinson at Prism Infosec explores the importance of incident response and considers why some organisations are reluctant to create Incident Response Plans

 

The mantra goes: “it’s not if you’ll be attacked, but when”. This makes an Incident Response Plan (IRP) a must-have.

 

An IRP formally sets out the process that kicks in following a breach and covers everything from engaging the right people and teams, using the correct tooling, assessing the impact, containing the breach and ensuring follow-up actions and lessons learnt.  Yet, surprisingly, very few businesses actually have one.

 

The second wave of the Cyber-security Longitudinal Survey revealed that 36% of businesses do not have any formal IRP, with many seeing little value in having one. For those that did, they reported that the level of detail in that plan varied greatly, from simply naming a person to report to, through to comprehensive and detailed process definitions. It is not a surprise that some simply repurposed other plans, either internally or from other organisations. Similarly, the Cyber-security Breaches Survey 2022 found only 19% of businesses have a formal IRP.

 

The problem is that many organisations don’t feel they have the bandwidth or the expertise to devise an IRP. Almost half of those surveyed for the Cyber-security skills in the UK labour market 2023 report said they were not confident they could put together an IRP and a quarter did not regard incident response skills as essential. Yet they recognised that this would impact their ability to respond, with 41% ‘not very’ or ‘not at all’ confident that they would be able to deal with a cyber-security breach or attack. 

 

Those that are looking for guidance on how to do so would do well to look at the guidance from the National Cyber Security Centre (NCSC) which provides step-by-step instructions on what needs to be included.

 

Acting after the event

Sadly, it appears that many organisations only commit to an IRP once they have been attacked. The Longitudinal survey found 60% of businesses were likely to have written processes in place if they had been compromised, compared to 44% of those that had not.

 

Another major driver of adoption was the need to report to an external party, be that an insurer or a regulatory body, with 85% including guidance for external reporting within the IRP. Those who were ISO 27001 compliant also had a document in place, in line with the standard’s requirements, revealing that compliance remains a strong driver.

 

But aside from the assurance aspect, the value conferred by an IRP is compelling. To start with, it can significantly limit the impact of an attack. The longer an attack goes on, the more damage it can do and the more costly it is to resolve, with average time to contain a breach now standing at 70 days, according to a Ponemon report

 

The same report also revealed that an IRP can deliver real cost savings, with the cost to resolve a data breach 58% higher for those without one. Furthermore, it established that an IRP can generate higher cost savings over-time because a post-incident review can quantify the real cost of the attack or to use the experience to improve practices, making the process more efficient. 

 

The value of testing

What many do not realise, however, is that regularly testing the IRP can have much the same effect. Running a simulated exercise can put the plan through its paces and determine if it needs updating. Perhaps job roles have changed, or there’s been a changeover in systems, or new processes are needed to isolate the incident. In fact, the implications of many changes within the business mean the IRP should be reviewed as part of change management and it should be treated as a living document.

 

Identifying these gaps in response can pay real dividends when a breach does happen, minimising downtime. Furthermore, the Ponemon Institute report found organisations with IR teams that regularly tested their plans realised up to $2.66m in savings when breached compared to those that did not, although once again, there is little indication this is happening. Only 43% test their plans annually, according to the Longitudinal survey.

 

Testing can vary in scope, from a tabletop exercise, whereby participants discuss their roles in a role-play response to a scenario, to a full blown live-play exercise which sees the team act out its response in real-time. How the incident was handled, and the effectiveness of the IRP can then be assessed, but businesses need not devise these tests themselves. The NCSC has launched its Cyber-incident Exercising (CIE) scheme, overseen by industry groups IASME and CREST, and this will make available high quality incident exercise testing carried out by Assured Service Providers.

 

Armed with the guidance on how to structure an IRP and the ability to use a third party to test its effectiveness, there’s really no reason why any company should now be without one. The reduction in the Mean Time To Response (MTTR) and the ability to get the business back on its feet again, as well as the cost benefits are clear arguments in favour, suggesting that businesses large and small should take action before, not after, a breach.

 


 

Phil Robinson is Principal Consultant at Prism Infosec

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543