{"id":2664,"date":"2019-06-26T12:27:47","date_gmt":"2019-06-26T16:27:47","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=2664"},"modified":"2019-06-26T12:27:47","modified_gmt":"2019-06-26T16:27:47","slug":"how-to-improve-your-incident-response-plans-and-team","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/","title":{"rendered":"How to Improve Your Incident Response Plans and Team"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-2559\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png\" alt=\"How to Improve Your Incident Response Plans and Team\" width=\"800\" height=\"450\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png 800w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod-300x169.png 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod-768x432.png 768w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod-480x270.png 480w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod-144x81.png 144w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod-320x180.png 320w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Incident response must become part of every enterprise\u2019s cybersecurity efforts. Yet most either let their incident response languish or neglect it entirely.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The longer you neglect your incident response, the more likely hackers penetrate your network and cause untold damage. Hackers, after all, love targeting low-hanging fruit and few targets prove more low-hanging than unprepared businesses. Without an incident response plan, your enterprise may end up scrambling during an incident response and exacerbating the problem.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\"><br \/>Widget not in any sidebars<br \/><\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Therefore, you need to improve your incident response plan. Here\u2019s how you can start.\u00a0<\/span><\/p>\n<h2 style=\"text-align: justify\"><b>How to Improve Your Incident Response Plans and Team<\/b><\/h2>\n<h3><b>1. Aim For 24\/7 Preparedness<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">It\u2019s no secret: hacking now constitutes a global enterprise. That means it follows global business hours, i.e. 24 hours a day, 7 days a week.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Even if you serve a global enterprise yourself, ensuring constant cybersecurity and incident response surveillance proves easier said than done. Even automated solutions like SIEM require human intelligence to help them determine false positives from legitimate alerts.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Unfortunately, human intelligence remains bound to physical humans, who need to sleep and have a reasonable work-life balance (more on that in a bit).\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Yet to improve your incident response, you need to aim for as close to 24\/7 preparedness as possible. This can mean having a night shift of threat hunters and incident response team members. If you serve a global enterprise with the resources to employ such a team, this may not prove far-fetched.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">However, if you work for a smaller business, solution providers still offer ways to help you improve your incident response. If you struggle to fill your cybersecurity staff roles, you can seek out a managed security services provider (MSSP). These can handle your cybersecurity\u2014including <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/siem-buyers-guide-security-information-and-event-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">SIEM<\/a> and incident response\u2014for you, including interacting with employees during an incident.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">For businesses with a limited but staffed cybersecurity team, you can also employ the MSSP to take over the hours when the team can\u2019t work. Thus your business can enjoy a stronger incident response plan without risking burnout.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">SMBs aren\u2019t the only ones who can enjoy these perks; enterprises can absolutely take advantage of them<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">However, speaking of cybersecurity staffing crisis&#8230;<\/span><\/p>\n<h3><b>2. Seek Out Volunteers or Virtual Members<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">We\u2019ve heard the reports: millions of cybersecurity jobs look to go unfilled over the next few years; meanwhile, increased burnout rates among members of the cybersecurity community results in lower retention rates. There doesn\u2019t seem to be an end to the portents of doom and gloom.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">All of which means your enterprise\u2019s incident response team, without help, could easily suffer in the short and long term. While your entire enterprise should become involved in your incident response plan (we go into more detail about that below) you need cybersecurity experts to handle the most technical parts of mitigation and removal.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">So having an in-house cybersecurity team for incident response remains the ideal. However, you can improve your incident response by expanding your IT workforce beyond the merely physical.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/alienvault-incident-response\/\" target=\"_blank\" rel=\"noopener noreferrer\">AT&amp;T Cybersecurity<\/a> suggests you supplement your in-house team with virtual or volunteer members. In many ways, this resembles volunteer fire departments. For example, you can contact and coordinate these members through your IT Help Desk. Simultaneously, your Help Desk can handle the initial investigations and data gathering.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Also, don\u2019t rule out the power of automation via a <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/siem-buyers-guide-security-information-and-event-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">SIEM solution<\/a>. It can help bridge a lot of gaps caused by overworked or understaffed incident response teams.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">So far, these suggestions to improve your incident response have focused on the humans performing your incident response. Your enterprise should remember this reliance on the human in the digital world, especially in light of the next suggestion\u2026<\/span><\/p>\n<h3><b>3. Keep Team Morale High<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Burnout rates and the cybersecurity staffing crisis overall persist because of the incredible stress within cybersecurity. After all, a job in cybersecurity often requires constantly being on-call, fielding requests, and queries from other employees at nearly all hours, and investigating alerts both false and legitimate. That doesn\u2019t even get into the stress of a security event or incident. Just thinking about it can provoke anxiety.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Of course, not every cybersecurity staff member suffers from burnout; some relish that environment. However, enough do for it to present a legitimate problem. Burnout can lead to a lack of focus and motivation, neither of which proves conducive to incident response or investigation.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">To improve your incident response overall, you need to take care of these vital members of your enterprise\u2019s IT department. Here are a few suggestions on how to begin:<\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Encourage a sustainable and consistent work-life balance. If a team member needs time off, do not ask them to work from home during that time. Ensure you have any and all relevant information to handle any issues related to their position during their absence to ensure they remain undisturbed. Don\u2019t just encourage work-life balance, make policies that facilitate it.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Only mandate reasonable hours for employees. If you need employees to work unusual or demanding hours, you may want to consider stepping outside the typical 9 to 5 workday schedule. Moreover, if you need someone to be on call, make sure you compensate them fairly (including overtime or more days off).\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Additionally, make sure your team receives fair compensation generally, including good benefits.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Encourage healthy workplace habits, such as regular breaks.\u00a0 <\/span><\/li>\n<\/ul>\n<h3><b><\/b><b>4. Keep Everyone Informed Of Your Incident Response Plan<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Here\u2019s a trick question: who in your enterprise is responsible for your overall cybersecurity hygiene and practices?\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Of course, the question is \u201ceveryone.\u201d\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Every employee, IT member, and C-suite executive contributes to your overall cybersecurity and thus your incident response effectiveness. Your C-suite and cybersecurity team should spearhead your efforts, without question. However, if you truly wish to improve your incident response, you need to involve your enterprise in its entirety.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Thankfully, your enterprise can do this in a number of ways!\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">First, you can make cybersecurity training a regular occurrence for your employees. These training sessions don\u2019t have to drag on\u2014in fact, shorter sessions occurring more frequently improve retention long-term; instead, they need to present critical threat intelligence in a digestible manner.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Additionally, these training sessions must demonstrate proper best practices for recognizing threats and avoiding them as well as how to alert the incident response team in the event of a digital attack or phishing. This can happen even to the most conscientious employee.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Moreover, you can enforce these training sessions in employee reviews or through rewards programs. While punishing employees for human error shouldn\u2019t become a policy, you should make sure deliberate neglect of cybersecurity does result in consequences. On the other hand, rewards programs can encourage employees in a much more collaborative and constructive manner.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Finally, the best way to improve your incident response efforts is to inform your employees about the incident response plan. Don\u2019t just keep it in a binder in your Security Operations Center. Run drills with your employees, see if there are any inefficiencies, and highlight principle points of contact during a security incident. Above all, keep everyone up-to-date.\u00a0<\/span><\/p>\n<h3><b>5. Have A Solid Chain of Command and Communication<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">This means both an internal chain of command and communication and an enterprise-wide one in the event of a security incident. To improve your incident response, you need an IT team that knows their roles and has the capacity to carry those roles out. These include (but are certainly not limited to):\u00a0<\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Team Leader.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Lead Investigator.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Communications Lead.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Documentation and Timeline Lead.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">HR and Legal Representation.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Threat Hunter.<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Your team may have more of some positions than others. Additionally, in the event of a breach, your non-IT departments may need to become involved, such as public relations, legal, and financial. They should know how to respond in the event of a breach and who they must inform of a security incident.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In fact, your incident response plan should also outline who in which department gets informed when and by whom. Your plan should have considerable details to ensure you handle any attack in an efficient and comprehensive manner.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><div class=\"hr hr\"><\/div><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">If you would like to learn more about how to improve your incident response plans with SIEM, check out our <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/siem-buyers-guide-security-information-and-event-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">SIEM Buyer\u2019s Guide<\/a> and <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/security-information-event-management-vendor-map\/\" target=\"_blank\" rel=\"noopener noreferrer\">Vendor Map<\/a>!<\/span><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/security-information-event-management-vendor-map\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2020\/02\/SIEM_VM_SB.jpg\" alt=\"Download Link to SIEM Vendor Map\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Incident response must become part of every enterprise\u2019s cybersecurity efforts. Yet most either let their incident response languish or neglect it entirely.\u00a0 The longer you neglect your incident response, the more likely hackers penetrate your network and cause untold damage. Hackers, after all, love targeting low-hanging fruit and few targets prove more low-hanging than unprepared [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":2559,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[551,1],"tags":[175,1019,353,95,145,112,86,199,21,57,22],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Improve Your Incident Response Plans and Team<\/title>\n<meta name=\"description\" content=\"Without an incident response plan, your enterprise may end up scrambling. Therefore, you need to improve your incident response plan.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Improve Your Incident Response Plans and Team\" \/>\n<meta property=\"og:description\" content=\"Without an incident response plan, your enterprise may end up scrambling. Therefore, you need to improve your incident response plan.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:published_time\" content=\"2019-06-26T16:27:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ben Canner\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/\",\"name\":\"How to Improve Your Incident Response Plans and Team\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png\",\"datePublished\":\"2019-06-26T16:27:47+00:00\",\"dateModified\":\"2019-06-26T16:27:47+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"Without an incident response plan, your enterprise may end up scrambling. Therefore, you need to improve your incident response plan.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png\",\"width\":800,\"height\":450,\"caption\":\"How to Improve Your Incident Response Plans and Team\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Improve Your Incident Response Plans and Team\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Improve Your Incident Response Plans and Team","description":"Without an incident response plan, your enterprise may end up scrambling. Therefore, you need to improve your incident response plan.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/","og_locale":"en_US","og_type":"article","og_title":"How to Improve Your Incident Response Plans and Team","og_description":"Without an incident response plan, your enterprise may end up scrambling. Therefore, you need to improve your incident response plan.","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/","og_site_name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","article_published_time":"2019-06-26T16:27:47+00:00","og_image":[{"width":800,"height":450,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png","type":"image\/png"}],"author":"Ben Canner","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/","name":"How to Improve Your Incident Response Plans and Team","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png","datePublished":"2019-06-26T16:27:47+00:00","dateModified":"2019-06-26T16:27:47+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"Without an incident response plan, your enterprise may end up scrambling. Therefore, you need to improve your incident response plan.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2019\/04\/managed-security-mod.png","width":800,"height":450,"caption":"How to Improve Your Incident Response Plans and Team"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-to-improve-your-incident-response-plans-and-team\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"How to Improve Your Incident Response Plans and Team"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/2664"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=2664"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/2664\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/2559"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=2664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=2664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=2664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}