The Art of Planning for an Attack
Sue Bergamo
Global CIO/CISO | Executive Advisor | Board Ready | Podcaster | Author | Passionate to create a safer world, using my expertise in cybersecurity/technology to develop innovative solutions for growth oriented companies.
Today, we’ll be discussing planning for risks, then I’ll step into the controversy of planning for active shooter situations - but before we do, I’d like to talk about my dog.
Big Fluff and I spend a lot of time alone on the trails together. While we run and walk, he likes to greet people, kiss babies and loves to play with toddlers; and I spend the time thinking about the next article to write for you. We have a system, Fluff, and I – even when we are alone, we understand our surroundings and potential threats. We plan for risk, and we train for situations that we hope never happens.
There are no other words to describe Fluff, except big. For the most part, he’s laid back and easy going; but on the rare occasion that we have encountered an abnormal situation (deer, coyote, or weirdo on the trail), he’s learned to assess the situation and if needed, can become unhinged. He looks for me to give him a sign that the situation isn’t right and he’s the perfect dog to walk alone with. When the threat is not real, he listens well to commands and backs down accordingly.
When I run, I have a plan that has several components in the event of a situation. These components won’t be disclosed, though I can assure you, the plan is often thought of and modified as needed. Out on the trail, a perpetrator may assess me as a small-framed women with a very large dog. If they are thinking beyond an intended behavior, they would also need to assess my ability to defend myself against an attack, which is a judgement call on their part. The perpetrator has no idea if I’m prepared for a threat or if I plan and train for different scenarios. They don’t know that my career is to protect companies from unwanted and unwarranted bad situations. As a runner, why wouldn’t I plan for my own personal needs? As a team, Big Fluff and I have a better chance of defending ourselves than individually. We’re also smart, we don’t take uncalculated risks and always know our surroundings, but sometimes in real-life the inevitable happens.
My personal rant regarding the latest school shooting in Nashville that did not need to occur if the school had a better plan in place. Like it or not, planning to defend against attacks is unfortunately an uncomfortable need and a part of life. It is time to stop active shooters in our school systems, personal lives, and workplaces.
While our government continues to dispute the topic, I advise parents to find out how your school system prepares and trains to respond to an active shooter scenario, then make sure that they are running practice tests before a scenario occurs. These tests should include teachers, administrators, law enforcement and children. Questions to be asked of the school administrators include:
领英推荐
There shouldn’t be any excuses to avoid planning and training for an active shooter situation. Our children need to be protected by the preparation of plans that include different types of scenarios and how to resolve them. Law enforcement can be engaged to help in testing scenarios, as they are a part of an effective resolution. Parents should demand answers and not relent until there is a satisfactory plan in place. Please get involved and stay informed.
Let's go back to planning. Most businesses have a CIRT (or SIRT) to follow. The cyber or security incident response plan is a large part of having a security program and ensures that the staff is testing for different types of situations and has the answers figured out before a situation occurs. If your company is audited by a firm, the CIRT is one of the first items of evidence requested. Ask your security team if they have a CIRT plan in place and if they understand what to do when the unexpected happens. As mentioned above, CIRTs are frequently tested and modified as needed.
Testing the plan is called a tabletop exercise and there are three ways to run one: (1) the actual situation is documented, along with how the situation was resolved (2) new scenarios are created, and the group works together to resolve each one (3) automated software solutions can be purchased for the team to participate in.
Tabletop exercises should also include the departments within the organization that are a part of the CIRT and include technical and business representatives. One component of the CIRT is a communications workflow, which describes who is on point to communicate a disruption of business operations, from the department impacted all the way up to the Executive, Board, shareholders and to the public. Each scenario is discussed, and role played amongst the participants. For added value, when I run a tabletop, my management team is requested to stay silent during the exercise and the direction is given upfront that the team will need to come up with the answers on their own. After the test, we’ll revisit the scenarios as a group and critique how we’ve done. Modifications to each plan are made in response to the exercise.
The point of the test is to ensure that each representative has stepped through the actions for the scenario and knows what to do while the situation unfolds - instead of making it up in the heat of the moment.
As I like to say, the best time to plan for a situation is before it happens and make sure that the element of surprise doesn’t overwhelm you.
As always, your feedback on these articles is encouraged.
? 2023. All Rights Reserved
Sue Bergamo is a CISO and CIO and is an executive advisor to C-Suite executives. She can be reached at [email protected].The content within this article are the sole opinions of the author.
Business Development, Marketing Manager , Customer Success Manager, Project Manager
1 年??
Helping IT leaders achieve digital transformation goals faster by removing unnecessary workplace friction.
1 年Sue Bergamo, I really enjoyed this article. You have given me and many others plenty to think about concerning preparing for an attack--especially in a school. Thank you!
Enterprise Sales
1 年Excellent post Sue!
US Cybersecurity Headhunter | We build world class Cybersecurity teams
1 年Great to read Sue Bergamo!
Hands-on Technology Executive | CIO | CISO | Data & Analytics | Governance | (Re)Insurance
1 年Fantastic article, Sue Bergamo. 100% agreed. As an individual, you should be actively thinking about risk scenarios and what you will do if they occur. And more schools need to act like corporations with regards to having a comprehensive incident response plan in place, and trying to test every aspect of that IRP. Also, please tell Fluff he’s a good dog! ??