1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:04,080
we'll discuss incident response training and testing.

3
00:00:04,080 --> 00:00:06,240
Now, when it comes to training and testing,

4
00:00:06,240 --> 00:00:08,880
many people think that they are the same thing,

5
00:00:08,880 --> 00:00:11,160
but in the world of incident response,

6
00:00:11,160 --> 00:00:12,480
they are different.

7
00:00:12,480 --> 00:00:14,250
First, we have training.

8
00:00:14,250 --> 00:00:15,690
Training is education

9
00:00:15,690 --> 00:00:19,350
to ensure employees and staff understand your processes,

10
00:00:19,350 --> 00:00:22,920
procedures, and priorities during an incident response.

11
00:00:22,920 --> 00:00:24,990
By conducting training, you're going to make sure

12
00:00:24,990 --> 00:00:26,700
that your people are ready to respond

13
00:00:26,700 --> 00:00:28,260
when something bad happens.

14
00:00:28,260 --> 00:00:30,600
Training should be provided to all employees

15
00:00:30,600 --> 00:00:32,280
with a relevant perspective

16
00:00:32,280 --> 00:00:34,590
and focus based on their needs

17
00:00:34,590 --> 00:00:37,410
because not everyone is going to get the same training.

18
00:00:37,410 --> 00:00:39,510
For example, if you're a first responder,

19
00:00:39,510 --> 00:00:42,060
you need training in a technical capacity.

20
00:00:42,060 --> 00:00:44,160
What are the procedures that you're going to follow?

21
00:00:44,160 --> 00:00:45,960
How are you going to re-image a machine?

22
00:00:45,960 --> 00:00:47,640
How do you remove malware?

23
00:00:47,640 --> 00:00:49,530
How do you change configuration settings?

24
00:00:49,530 --> 00:00:53,010
All of that stuff is part of your responding training.

25
00:00:53,010 --> 00:00:55,500
Now, if you're a manager or executive,

26
00:00:55,500 --> 00:00:57,900
you're going to have different training requirements.

27
00:00:57,900 --> 00:01:00,510
You're going to be focused more on risk versus reward.

28
00:01:00,510 --> 00:01:02,970
You'll focus more on managerial decision making

29
00:01:02,970 --> 00:01:04,890
and communication across your organization

30
00:01:04,890 --> 00:01:06,270
and outside the organization

31
00:01:06,270 --> 00:01:08,970
with law enforcement and media as well.

32
00:01:08,970 --> 00:01:11,670
Our end users also need to be trained though.

33
00:01:11,670 --> 00:01:13,230
Our end users should be trained

34
00:01:13,230 --> 00:01:14,370
on the way to report

35
00:01:14,370 --> 00:01:16,410
if they suspect an incident is occurring.

36
00:01:16,410 --> 00:01:18,450
For instance, as an end user,

37
00:01:18,450 --> 00:01:19,740
if I opened up my email

38
00:01:19,740 --> 00:01:20,970
and I see a phishing campaign,

39
00:01:20,970 --> 00:01:23,040
how do I report that to the service desk?

40
00:01:23,040 --> 00:01:25,020
If I went and clicked on one of those links,

41
00:01:25,020 --> 00:01:26,730
I'm going to need remedial training

42
00:01:26,730 --> 00:01:28,740
to know how to identify that in the future

43
00:01:28,740 --> 00:01:30,990
and make sure that I don't fall for that again.

44
00:01:30,990 --> 00:01:34,110
This is the idea of your end user training.

45
00:01:34,110 --> 00:01:36,090
They need training on how to be a better user

46
00:01:36,090 --> 00:01:37,320
and how to prevent incidents

47
00:01:37,320 --> 00:01:38,940
from occurring in the first place.

48
00:01:38,940 --> 00:01:40,710
Now, when you're providing training,

49
00:01:40,710 --> 00:01:43,020
one of the things you want to make sure you're capturing

50
00:01:43,020 --> 00:01:45,690
is lessons learned from the previous incidents,

51
00:01:45,690 --> 00:01:47,970
and you want to make sure you bring those back up

52
00:01:47,970 --> 00:01:49,020
during the training

53
00:01:49,020 --> 00:01:50,880
because when you have lessons learned,

54
00:01:50,880 --> 00:01:53,130
that means that something went wrong in the past

55
00:01:53,130 --> 00:01:55,050
and how can we do better in the future

56
00:01:55,050 --> 00:01:56,790
is by training those people

57
00:01:56,790 --> 00:01:58,530
on the lessons that we've learned.

58
00:01:58,530 --> 00:02:00,180
If we just write down those lessons learned

59
00:02:00,180 --> 00:02:01,500
and nobody reads them again,

60
00:02:01,500 --> 00:02:03,120
then nobody gets training on it,

61
00:02:03,120 --> 00:02:06,330
and then we're going to be doomed to repeat those things again.

62
00:02:06,330 --> 00:02:08,520
And so we want to ensure that we're preventing that.

63
00:02:08,520 --> 00:02:10,350
Remember, when you're doing training,

64
00:02:10,350 --> 00:02:12,360
it's not just about technical skills here.

65
00:02:12,360 --> 00:02:14,160
You also need to include soft skills

66
00:02:14,160 --> 00:02:16,290
in relationship building within your teams,

67
00:02:16,290 --> 00:02:17,550
because that's important as well

68
00:02:17,550 --> 00:02:19,260
if you really want a high functioning

69
00:02:19,260 --> 00:02:21,450
cybersecurity incident response team.

70
00:02:21,450 --> 00:02:23,640
Now, let's take a look at testing.

71
00:02:23,640 --> 00:02:25,440
Testing is the practical exercise

72
00:02:25,440 --> 00:02:27,300
of incident response procedures.

73
00:02:27,300 --> 00:02:28,133
With training,

74
00:02:28,133 --> 00:02:29,550
we're going to teach you what to do.

75
00:02:29,550 --> 00:02:30,383
In testing,

76
00:02:30,383 --> 00:02:32,490
we're going to make sure you know how to do it.

77
00:02:32,490 --> 00:02:34,560
Now, when you're dealing with testing,

78
00:02:34,560 --> 00:02:35,940
we'll often conduct a test

79
00:02:35,940 --> 00:02:38,220
to simulate a significant incident.

80
00:02:38,220 --> 00:02:41,850
Now, the challenge is doing this is very costly

81
00:02:41,850 --> 00:02:43,920
and it can become a complexity.

82
00:02:43,920 --> 00:02:45,450
For example, I've been involved

83
00:02:45,450 --> 00:02:47,340
with a lot of testing over the years.

84
00:02:47,340 --> 00:02:49,860
One such test was a full scale exercise

85
00:02:49,860 --> 00:02:51,240
that showed exactly what we would do

86
00:02:51,240 --> 00:02:53,880
in the event if we had a large scale data breach.

87
00:02:53,880 --> 00:02:56,490
Now, this went across multiple sites around the world

88
00:02:56,490 --> 00:02:59,790
and it cost us hundreds of thousands of dollars to do so,

89
00:02:59,790 --> 00:03:02,700
but it made sure everyone knew what they were doing

90
00:03:02,700 --> 00:03:04,710
and that they could actually go through those actions

91
00:03:04,710 --> 00:03:07,080
and get a bad actor out of our systems.

92
00:03:07,080 --> 00:03:09,210
Now, when you're designing your test,

93
00:03:09,210 --> 00:03:12,120
you can do it in one of three major ways.

94
00:03:12,120 --> 00:03:13,830
The first is a tabletop,

95
00:03:13,830 --> 00:03:15,600
the second is a penetration test,

96
00:03:15,600 --> 00:03:18,930
and the third is a full scale exercise of simulation.

97
00:03:18,930 --> 00:03:21,600
Now, when we're dealing with a tabletop exercise

98
00:03:21,600 --> 00:03:24,450
or a TTX, this is an exercise

99
00:03:24,450 --> 00:03:26,250
that uses an incident response scenario

100
00:03:26,250 --> 00:03:29,220
against a framework of controls or a red team.

101
00:03:29,220 --> 00:03:31,740
Now, the reason we call it a tabletop exercise

102
00:03:31,740 --> 00:03:33,540
is because we're actually doing it on our tabletop

103
00:03:33,540 --> 00:03:35,970
and we're not physically doing it in our networks.

104
00:03:35,970 --> 00:03:36,803
In a tabletop,

105
00:03:36,803 --> 00:03:38,850
we might gather experts around the table

106
00:03:38,850 --> 00:03:40,740
and we'll start presenting scenarios.

107
00:03:40,740 --> 00:03:42,750
For instance, if I was leading the tabletop,

108
00:03:42,750 --> 00:03:45,750
we would say, hey, you have an indication of data breach

109
00:03:45,750 --> 00:03:47,490
occurring in this data breach server.

110
00:03:47,490 --> 00:03:48,600
What would you do?

111
00:03:48,600 --> 00:03:51,300
And the defenders would start saying what they would do,

112
00:03:51,300 --> 00:03:52,560
and each would take turns,

113
00:03:52,560 --> 00:03:54,180
almost like their role playing

114
00:03:54,180 --> 00:03:56,580
on what they would do in this particular scenario.

115
00:03:56,580 --> 00:03:58,890
Now, the benefit of doing a tabletop

116
00:03:58,890 --> 00:04:00,390
is that it's a lot less expensive

117
00:04:00,390 --> 00:04:01,830
than a full-blown exercise,

118
00:04:01,830 --> 00:04:03,930
but there are some negatives due to the fact

119
00:04:03,930 --> 00:04:06,150
that you can't really get the hands-on experience

120
00:04:06,150 --> 00:04:07,710
because you're not physically doing the things

121
00:04:07,710 --> 00:04:08,640
on the keyboard

122
00:04:08,640 --> 00:04:10,920
and making actions happen on the network.

123
00:04:10,920 --> 00:04:13,650
So it's really more of a theoretical exercise.

124
00:04:13,650 --> 00:04:16,500
Now, another way you can do this is you can break up people

125
00:04:16,500 --> 00:04:18,510
into red teams and blue teams.

126
00:04:18,510 --> 00:04:20,459
Now, the red teams are the attackers

127
00:04:20,459 --> 00:04:22,079
and the blue teams are the defenders.

128
00:04:22,079 --> 00:04:24,120
So you can actually take turns

129
00:04:24,120 --> 00:04:26,280
by saying, okay, here's the blue team scenario.

130
00:04:26,280 --> 00:04:28,110
This is what you detect, what do you do?

131
00:04:28,110 --> 00:04:29,460
And then based on what they say,

132
00:04:29,460 --> 00:04:33,450
the red team says, okay, then we would do X, Y, and Z.

133
00:04:33,450 --> 00:04:36,060
Then the blue team will say, well, we will see this

134
00:04:36,060 --> 00:04:38,250
and respond in A, B, and C, way.

135
00:04:38,250 --> 00:04:40,350
And then they'll go back and forth several rounds

136
00:04:40,350 --> 00:04:41,340
to initiate attack,

137
00:04:41,340 --> 00:04:43,230
and defend against attack go back and forth

138
00:04:43,230 --> 00:04:45,420
until we can see what the effects are.

139
00:04:45,420 --> 00:04:46,800
The benefits of doing a red team

140
00:04:46,800 --> 00:04:48,030
versus blue team type of scenario

141
00:04:48,030 --> 00:04:50,370
is that you're going to get live people thinking through

142
00:04:50,370 --> 00:04:52,500
both the attacker side and the defender side

143
00:04:52,500 --> 00:04:54,000
to help come up with a better solution

144
00:04:54,000 --> 00:04:55,170
in how to configure

145
00:04:55,170 --> 00:04:58,230
and better manage those controls to protect your network.

146
00:04:58,230 --> 00:05:00,090
Now, another way you can do this

147
00:05:00,090 --> 00:05:02,340
is by actually getting people on the network.

148
00:05:02,340 --> 00:05:04,410
This is done through a penetration test.

149
00:05:04,410 --> 00:05:06,150
Now, a penetration test occurs

150
00:05:06,150 --> 00:05:08,340
when a red team attempts to conduct an intrusion

151
00:05:08,340 --> 00:05:09,173
into the network

152
00:05:09,173 --> 00:05:10,770
by using a specific scenario

153
00:05:10,770 --> 00:05:12,360
based on threat modeling.

154
00:05:12,360 --> 00:05:14,400
Now, this is an important concept here

155
00:05:14,400 --> 00:05:15,900
when we're talking about penetration tests,

156
00:05:15,900 --> 00:05:18,390
because we're not just doing something against the network

157
00:05:18,390 --> 00:05:20,640
to see what we can do to get in.

158
00:05:20,640 --> 00:05:22,860
We have a specific goal in mind.

159
00:05:22,860 --> 00:05:25,050
So if my goal is to go after the database,

160
00:05:25,050 --> 00:05:26,220
I'm not going to throw

161
00:05:26,220 --> 00:05:28,410
a distributed denial of service attack at you.

162
00:05:28,410 --> 00:05:30,360
That wouldn't be a valid pen test.

163
00:05:30,360 --> 00:05:32,370
So instead, we have specific scenario

164
00:05:32,370 --> 00:05:33,660
based on the threat modeling,

165
00:05:33,660 --> 00:05:36,540
meaning we know what a regular adversary would do,

166
00:05:36,540 --> 00:05:39,360
and we're going to base our actions on that.

167
00:05:39,360 --> 00:05:41,730
Now, when you're dealing with a penetration test,

168
00:05:41,730 --> 00:05:44,430
you always have to agree on a clear methodology

169
00:05:44,430 --> 00:05:45,600
and rules of engagement

170
00:05:45,600 --> 00:05:47,880
before that penetration test is performed.

171
00:05:47,880 --> 00:05:49,290
This is critically important

172
00:05:49,290 --> 00:05:51,540
because there are rules to these things.

173
00:05:51,540 --> 00:05:52,980
As I said, I'm not just going to throw

174
00:05:52,980 --> 00:05:54,810
a distributed denial of service attack at you

175
00:05:54,810 --> 00:05:55,890
because that would probably be

176
00:05:55,890 --> 00:05:57,480
against the rules of engagement.

177
00:05:57,480 --> 00:05:59,640
Now, if they're in my rules of engagement,

178
00:05:59,640 --> 00:06:01,440
then it'll be all fair game,

179
00:06:01,440 --> 00:06:04,410
but in most cases, that's not going to be in there.

180
00:06:04,410 --> 00:06:06,060
Some popular penetration tests and tools

181
00:06:06,060 --> 00:06:08,160
and operating systems you might see in real world

182
00:06:08,160 --> 00:06:10,920
are things like Metasploit, Cobalt Strike,

183
00:06:10,920 --> 00:06:14,250
Kali Linux, ParrotOS and Commando OS.

184
00:06:14,250 --> 00:06:15,510
As a cyber security professional

185
00:06:15,510 --> 00:06:16,950
working as a network defender,

186
00:06:16,950 --> 00:06:18,210
if you ever see these tools

187
00:06:18,210 --> 00:06:20,010
or operating systems on your network,

188
00:06:20,010 --> 00:06:21,420
you should be thinking about the fact

189
00:06:21,420 --> 00:06:23,250
that they are penetration testing tools,

190
00:06:23,250 --> 00:06:25,440
which could be used as part of a penetration test

191
00:06:25,440 --> 00:06:27,150
or even worse, by an attacker

192
00:06:27,150 --> 00:06:29,310
because most of these are open source tools

193
00:06:29,310 --> 00:06:31,320
that anyone could download and use.

194
00:06:31,320 --> 00:06:33,780
The final area we need to discuss in terms of training

195
00:06:33,780 --> 00:06:35,340
and testing for incident response

196
00:06:35,340 --> 00:06:37,170
is the use of a simulation.

197
00:06:37,170 --> 00:06:39,000
A simulation exercise is designed

198
00:06:39,000 --> 00:06:41,190
to go beyond theoretical tabletop discussions

199
00:06:41,190 --> 00:06:43,530
and involve realistic hands-on scenarios

200
00:06:43,530 --> 00:06:45,480
that mimic actual incidents.

201
00:06:45,480 --> 00:06:47,820
These exercises provide a comprehensive view

202
00:06:47,820 --> 00:06:49,740
of how well your incident response teams

203
00:06:49,740 --> 00:06:50,910
can execute their roles

204
00:06:50,910 --> 00:06:53,670
in a controlled yet authentic environment.

205
00:06:53,670 --> 00:06:55,170
Simulation exercises can range

206
00:06:55,170 --> 00:06:56,910
from relatively simple scenarios

207
00:06:56,910 --> 00:06:59,370
such as responding to simulated phishing attacks

208
00:06:59,370 --> 00:07:00,750
or ransomware infection

209
00:07:00,750 --> 00:07:01,653
to complex scenarios

210
00:07:01,653 --> 00:07:03,870
that involve multi-stage attacks,

211
00:07:03,870 --> 00:07:05,340
data breaches in coordination

212
00:07:05,340 --> 00:07:07,170
with external parties like law enforcement

213
00:07:07,170 --> 00:07:08,910
or public relations team.

214
00:07:08,910 --> 00:07:09,807
The goal of these simulations

215
00:07:09,807 --> 00:07:12,390
is to assess not only your technical skills,

216
00:07:12,390 --> 00:07:13,320
but also the ability

217
00:07:13,320 --> 00:07:14,970
to make sound decisions under pressure

218
00:07:14,970 --> 00:07:16,770
and effectively communicate within

219
00:07:16,770 --> 00:07:18,810
and outside the organization.

220
00:07:18,810 --> 00:07:20,310
When conducting simulations,

221
00:07:20,310 --> 00:07:21,600
it's essential to align them

222
00:07:21,600 --> 00:07:23,220
with your organization's threat landscape

223
00:07:23,220 --> 00:07:24,600
and risk profile.

224
00:07:24,600 --> 00:07:26,820
Simulations should challenge your incident response teams

225
00:07:26,820 --> 00:07:29,490
to think critically, adapt to evolving situations

226
00:07:29,490 --> 00:07:31,770
and coordinate their efforts seamlessly.

227
00:07:31,770 --> 00:07:33,390
These exercises are invaluable

228
00:07:33,390 --> 00:07:36,270
for identifying gaps in your incident response plan,

229
00:07:36,270 --> 00:07:38,100
improving coordination between teams

230
00:07:38,100 --> 00:07:40,710
and ensuring that everyone understands their roles

231
00:07:40,710 --> 00:07:42,180
during a real incident.

232
00:07:42,180 --> 00:07:44,790
By regularly incorporating simulation exercises

233
00:07:44,790 --> 00:07:47,340
into your incident response training and testing program,

234
00:07:47,340 --> 00:07:49,140
you can better prepare your organization

235
00:07:49,140 --> 00:07:50,310
to respond effectively

236
00:07:50,310 --> 00:07:52,800
to a wide range of cybersecurity incidents.

237
00:07:52,800 --> 00:07:55,200
So remember, training and testing are used

238
00:07:55,200 --> 00:07:57,960
to create a more robust incident response framework

239
00:07:57,960 --> 00:07:59,910
that can help your organization stay resilient

240
00:07:59,910 --> 00:08:01,830
in the face of evolving threats.

241
00:08:01,830 --> 00:08:03,630
Training is the educational process

242
00:08:03,630 --> 00:08:05,160
that equips employees and staff

243
00:08:05,160 --> 00:08:07,800
with the knowledge and skills needed to understand

244
00:08:07,800 --> 00:08:09,870
and respond effectively to incidents

245
00:08:09,870 --> 00:08:13,350
by focusing on processes, procedures, and priorities.

246
00:08:13,350 --> 00:08:15,540
Testing involves practical exercises

247
00:08:15,540 --> 00:08:18,300
that assess an individual or team's ability

248
00:08:18,300 --> 00:08:20,550
to execute incident response procedures

249
00:08:20,550 --> 00:08:23,100
to ensure that they can apply their training effectively

250
00:08:23,100 --> 00:08:24,810
in real world scenarios.

251
00:08:24,810 --> 00:08:26,070
Simulation on the other hand

252
00:08:26,070 --> 00:08:28,620
refers to realistic hands-on exercises

253
00:08:28,620 --> 00:08:31,470
that replicate actual incident response scenarios

254
00:08:31,470 --> 00:08:33,360
and provide comprehensive assessment

255
00:08:33,360 --> 00:08:35,669
of a incident response team's capabilities,

256
00:08:35,669 --> 00:08:36,900
decision making skills,

257
00:08:36,900 --> 00:08:39,200
and communication under controlled conditions.

