Your organization has just recovered from a cyber-attack, what will you do next?
- Lick your wounds and get back to work
- Pray another attack doesn’t happen
- Assess your readiness and prepare
What You Should Do After a Cyber-Attack is Resolved
1. How bad was it?
Not the attack, but how many assets of all types were found that you were unaware of?
2. How many problem areas are there?
Were the majority of rogue assets from one or two departments? If yes, then you have the first areas to focus on fixing.
3. Can you determine where they came from?
4. Why did it happen?
5. What needs fixed?
Are policies and/or procedures not understood or known?
- Review policies for accuracy, completeness, and perhaps most important, clarity.
- Review training practices. Are new employees and contractors educated on the policies and procedures? Do employees and contractors receive continuous training?
- Is the culture supportive of a disciplined approach to managing IT assets?
Are there missing or incomplete processes?
- How are asset purchases approved and paid? Is there a formal request/approval process?
- Are off-boarded employee’s and contractor’s assets collected?
- Are project related assets collected after the project is complete?
- Does the tech refresh cycle retrieve replaced assets?
- Is a physical inventory performed on a regular basis?
- Is there a formal disposal process for asset types?
- Are unused assets properly secured and made available for re-use?
- Are IT’s installs, moves, adds, and changes accurately reflected in the IT asset repository?
Are the tools sufficient?
- Is there a database containing a single source of truth of IT asset data?
- Okay, okay, I know. A single source is like expecting a letter from the government saying you never have to pay taxes again. The single source of truth represents the culmination of a significant effort to combine people, process, and tools and it doesn’t happen overnight. Therefore, you have to develop a strategy that allows incremental improvements to your IT asset repository.
- Are the electronic discovery tools working and is the data they generate being used appropriately?
- Are the assets tagged with either barcodes or RFID tags?
- Is barcode or RFID technology used to track physical assets in support of that single source of truth IT asset management repository?
Additionally, improving your IT asset management operations will pay dividends in other areas like cost savings, compliance, and operational efficiencies.