Building a strong incident response and management plan

1 April 2016 Conferences & Events, News & Events

Security incidents are commonplace in businesses of all types and sizes. Whether through sophisticated malware, violation of security policies or employee carelessness, these threats can be catastrophic to the business.

"Given the digital landscape upon which most organisations are either currently operating on or considering as part of their future strategic imperatives, it is very important to consider incident response and management," says Ritasha Jethva, head of Information Privacy / PAIA officer at the Nedbank Group, who will be presenting on the importance of incident response capabilities in today's digital environment, at the ITWeb Security Summit 2016, to be held at Vodacom World from 16 to 20 May.

She says in the age of consumerism, consumers and employees have access to all sorts of social networking platforms which they can use to complain about companies they are dissatisfied with. "The supporter base grows at exponential speeds through these platforms and as companies, we need to understand how, when and what to do under these circumstances."

While consumers use the technology platforms for their own purposes, explains Jethva, cyber criminals utilise the platforms to expose confidential information in an unauthorised manner, either for financial gain or in order to demonstrate a point to the company they aggrieved about. "Unfortunately, this comes at the cost of both the company concerned as well as the individuals impacted and it is important that we think about different tactics when addressing incidents in a landscape where issues become viral in a matter of seconds."

Drawn out processes

Speaking about what businesses in SA are doing wrong when it comes to incident response and management, she says in her experience, companies are relying too much on long drawn-out incident response and management processes. "It's almost as if they spend too much time on the internal management of the incident and not enough time on responding to it.

"Sometimes, processes are not only lengthy and complicated, but hardly anyone understands how they work. Sometimes processes are not very collaborative across the organisation, and teams still operate in their silos, with pockets and escalations taking far too long, and sometimes the right audience is not involved at the right time."

Concurrently, she says some companies fail to recognise that incidents on digital platforms and landscapes gather media attention far faster than the move from step one to step two on their incident management process. "As a result, companies take too long to respond to the media, which results in further speculation, and at the same time, they take longer responding to queries around the incident from their consumers, partners and employees once it becomes public knowledge.

This degrades the levels of trust people have in the company and can affect the reputation of the organisation concerned. Traditional incident response and management processes were never built for today's types of incidents and hence they fail when the time comes to utilise it."

A different engagement model

In terms of what businesses could be doing better, Jethva says they need to be spending more time understanding who will respond to the incident at hand, and how they will do it. "The management processes need to give priority to both the management aspects and the response aspects. Roping in the public affairs representatives, senior officials of the company concerned, and the key specialist areas, such as IT, privacy, security, legal, risk and compliance, introduces a completely different dynamic within incident management."

She says it suggests a different engagement model, a different way of responding, opens up myriad varying communication channels to utilise, and suggests that all parties are required to be in sync at all times. "Preparing the various stakeholders through simulations and helping everyone understand their role in the process is critical and this is where I believe the emphasis should be placed going forward."

Delegates who attend Jethva's talk can expect some interesting perspectives on incident response and management. They will be left with pointers on what to consider when dealing with incidents in the digital landscape and what to watch out for. "It's a talk that is expected to broaden our horizons and thinking on this topic."

ITWeb Security Summit 2016

Hear opinion from Ritasha Jethva, Nedbank, on incident response and management at the ITWeb Security Summit 2016, 17 and 18 May. To view the full agenda, click here. To register, click here





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Dallmeier extends software maintenance up to 10 years
Dallmeier Electronic Southern Africa Surveillance News & Events
Dallmeier is expanding its software maintenance offering and now provides an additional maintenance package for cameras and recorders, enabling customers to keep their video security systems up to date for up to 10 years.

Read more...
Video surveillance market faces faster growth, and 2026 price shock
Surveillance News & Events
Novaira Insights has released its 2026 edition of The World Market for Video Surveillance Hardware and Software, highlighting a stronger global growth profile in 2025, tentative improvements in China’s market outlook, and unprecedented price increases in 2026.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...
Increase in cyberattacks on the manufacturing sector
Security Services & Risk Management News & Events Industrial (Industry)
According to a new Kaspersky ICS CERT report, in the first quarter of 2026, the percentage of industrial control systems (ICS) on which malicious objects were blocked reached 19,6% globally.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.