Slide 4
Slide 4 text
“Incident:” sounds
innocent but isn’t
✦ “Incident” is info-security-ese for “we got pwned.”
✦ Not all incidents are all-hands-on-deck crises.
✦ Most of the time, something happens, someone notices, it’s not
major, it gets fixed, any closable holes get closed, and that’s that.
✦ Something like that won’t get a full incident report, or incident
reporting would be all infosec pros ever do!
✦ If there’s a full incident report, the incident must
have been major.
✦ Usually, this means either something really bad resulted, or the
incident pointed to a serious, re-pwnable security problem. Or both!
✦ I’ll be using the Equifax breach as our example
this module.