
teissLondon2022 kicked off on Thursday, 8th September, bringing in expert insights from cyber security industry leaders and practitioners on addressing the major cyber security pain points of organisations across industries. In this session, two C-Suite panellists discuss how to best configure incident response for the remote workforce.
The hybrid way of working is becoming the new norm, so much so that, according to a survey by Owl Labs, 60% of UK workers are willing to take a pay cut to avail flexible hours and location, and 42% would stay with their current employer were they to implement a 4-day work week. Considering that many organisations are switching to the hybrid way of working to attract talent, prevent attrition, and enhance productivity, they need to find new solutions to keep their remote devices secured as well.
To understand how organisations can adapt their crisis and incident response solutions to counter risks faced by remote and hybrid-working employees, the teissLondon2022 conference featured an insightful panel discussion with participation from Dave Cartwright, CISO and Head of Technology Risk at Santander International and Paul Wells, Senior Vice President for Cyber Risk at Kroll.
According to Dave Cartwright, many organisations and their workers have gotten used to working remotely over the past two years, and they are now confortable with new processes that were set up for the remote work era. To build an effective incident response plan to counter risks faced by remote workers, security teams need to continually practice scenarios and to learn each step in the incident response process to be most effective when crisis strikes.
Agreeing with Cartwright, Paul Wells opined that over the last couple of years, there has been a kind of convergence of tooling and culture in terms of making remote response a lot easier and a lot more effective than it would have been 2-3 years ago. However, there have been occassions where the SOC team was prepared to handle an incident but stumbled because they needed authorisation from key decision-makers to perform certain actions.
Considering that waiting for an authorisation at a time when time is of essence is not an ideal situation, decision-makers should ensure that critical steps in the remediation process are preauthorised in order to save time when an attack takes place.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543