How to improve cyber crisis management?

Cyber threats and cyber crises have become increasingly sophisticated over the years.

Rapid digitization allows cybercriminals to continually evolve their tactics and test various methods to identify and exploit vulnerabilities in digital infrastructures. Cyber threats and crises have become increasingly sophisticated over the years, occurring on a larger scale and growing significantly more complex with each successive incident. For cloud providers, this underscores the importance of timely cyber crisis management to uphold the trust and security of their customers.

Effective cyber crisis management ensures resilience, protects critical data, and maintains 24/7 operations despite unexpected threats. Thousands of planes were recently grounded at airports, and banks and hospitals closed. We must always be prepared for cyber crisis management because even popular cyber security software products can develop vulnerabilities. Daticum’s experts shared recommendations, highlighting some of the best practices, the main strategies to improve their management, and the existing national frameworks in Europe.

Regular training and simulation activities

Preparation is the cornerstone of effective cyber crisis management. At Daticum, we regularly prioritize training and simulation exercises to ensure our team is always ready to respond quickly and effectively to any cyber threat. The simulation of a range of cyber-attack scenarios allows us to test the best working response strategies, identify potential weaknesses and improve coordination between different stakeholders.

For example, national frameworks like those in the Netherlands include regular, comprehensive training coordinated by a national central crisis communication team. This approach ensures that all communications professionals are well-prepared to manage a crisis effectively. Likewise, regular simulation training ensures that the team has a working and precise plan to deal with cyber threats in a real-world situation.

Development of communication strategy

A well-defined communications strategy is critical during a cyber crisis. This includes establishing a clear messaging format, identifying key stakeholders, setting priority levels and selecting appropriate communication channels. We understand the importance of providing a unified and transparent message that informs and reassures all stakeholders, from customers to partners and employees.

Another example of national European frameworks is from the Netherlands, where the national central crisis communication team coordinates messages from all public and private organisations involved during a cyber crisis. Local authorities, private companies and ministries comment on their specific areas of responsibility, ensuring consistent and unified messages. At Daticum, we take a similar approach, ensuring that all communications during a crisis are coordinated and consistent, helping to maintain trust and manage attitudes.

Engage certified suppliers and provide support to impacted groups

In the event of a cyber crisis, timely technical assistance is critical. Attracting certified trusted providers from the private sector can significantly improve response capability. At Daticum, we work with a network of suppliers who meet the requirements at a high level and are ready to offer immediate assistance to affected entities.

A good example is the German Federal Office for Information Security (BSI), which maintains a list of qualified service providers for responding to Advanced Persistent Threat (APT) attacks. These vetted providers are essential for dealing with complex cyber incidents. By cooperating with certified suppliers, Daticum ensures that the company’s customers receive quick and effective help during a crisis.

Support crisis communication of affected organisations

Effective crisis communication is about managing public perception and supporting our clients’ communication efforts. Timely and transparent communications help mitigate uncertainty and protect an organisation’s reputation.

An example from France: during the attack on a French car manufacturer, they proactively communicated the measures they were taking to counter the attack. The Director General of ANSSI supported this communication by publicly discussing the agency’s efforts to help the company. At Daticum, we support our customers by providing them with the necessary information and guidance for effective communication during a crisis.

Development of a disaster recovery plan (DRP)

Recovering from a cyber crisis involves more than simply restoring systems; a well-defined business DRP, which is regularly reviewed and updated, is required. At Daticum, together with our clients, we develop customised disaster recovery plans that meet each business’s specific needs and challenges.

Frameworks such as NIST 800-34 and BS 25999-1 provide guidance for developing robust recovery plans. The European Cyber ​​Security Agency offers guidance on the gradual resumption of operations and asset recovery. At Daticum, we follow these best practices to ensure our customers can return to their normal operations smoothly and efficiently.

Establish mechanisms for feedback and process improvement

Post-crisis activities such as gathering feedback, learning lessons and updating procedures are essential. Daticum creates dedicated feedback mechanisms to improve our cyber crisis management framework.

Again we return to the French example: after a ransomware attack on a French hospital, feedback sessions were held to assess the response and identify areas for improvement. At Daticum, we conduct similar sessions with our customers to ensure that the analysis of each incident will improve our future strategies, increasing resilience and preparedness.

Recommendations for improving cyber crisis management

To further improve cyber crisis management, we recommend:

  • Coordination mechanisms with national and EU authorities — cooperation with authorities at the national and European levels to define and regularly update mechanisms for cyber crises. These mechanisms should enable an overall assessment of incidents and identify key players based on the severity of the incident.
  • Development of simulation training — conducting regular simulation training, including strategic, operational, and technical levels. These test the allocation of tasks, cooperation, and information exchange between stakeholders during a cyber crisis.
  • Secure Communication Platforms — establishing secure communication platforms to exchange information with key entities during a cyber crisis should facilitate confidential communication and coordination.
  • Media training for executives — organize media training sessions for executives to ensure they can deliver synchronized, clear, and consistent messages about the current situation during a crisis. Regular awareness sessions and refresher courses on cyber issues are also beneficial.

By adopting these best practices and recommendations, Daticum helps its customers to be well-prepared to deal with potential and actual threats. As a trusted partner, we are committed to robust cyber crisis management, protecting our customers’ critical data and maintaining their trust and security.