WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Another Installment of 15 Cybersecurity Fundamentals Revisited – Cyber Incident Response Planning
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Another Installment of 15 Cybersecurity Fundamentals Revisited – Cyber Incident Response Planning

Author: Jennifer Walker

Created: Monday, September 23, 2019 - 20:52

Categories: Cybersecurity, General Security and Resilience, Security Preparedness

Developing plans for how utilities will respond to cyber incidents is critical for quick recovery and restoration from such events. An effective cyber incident response (IR) plan will limit damage and reduce recovery time and costs. Most importantly, the IR plan needs to be in place and tested before a cyber incident occurs; nonetheless, research reveals cyber incident response plans are still largely ineffective. The recently released Verizon Incident Preparedness and Response Report (VIPR) – Taming the data beast (sic) breach edition is a valuable resource to help organizations create or improve cyber incident mitigation and response efforts. The VIPR is based on three years of IR plan assessments and data breach simulation recommendations and walks through six main sections of an effective IR plan: planning and preparation, detection and validation, containment and eradication, collection and analysis, remediation and recovery, and assessment and adjustment. The highlight of the report – Breach Simulation Kits (BSKs) to help facilitate tabletop exercises/workshops and each designed to enforce various steps of the IR process. The BSKs include common attack scenarios, including cryptocurrency mining, an insider threat involving a compromise to PCI data, an ICS attack, cyber espionage, and a compromise via third party managed service provider (MSP). The VIPR is a good resource companion to WaterISAC’s 15 Cybersecurity Fundamentals #11 Plan for Incidents, Emergencies and Disasters. Download the full VIPR at Verizon

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar