We are a boutique B2B software development company based in Barcelona with a 5-person tech team. Last week, we applied to renew our annual cyber insurance and to pass a security audit for a new client in the financial sector. Both institutions made it mandatory for our security policies to include a 'cyber incident taxonomy' and an associated incident response plan.
In our day-to-day operations, whenever a suspicious phishing email arrived, unusual failed database logins occurred, or a server briefly went down, we would just discuss it in our internal chat channel and resolve it quickly. Now they want us to fit every single anomaly into a formal classification scheme and log it.
When I look it up online, I see massive tables with hundreds of terms. What is the actual point of this classification? Won't trying to squeeze everything into this scheme grind operations to a halt for a small team, and how can we set this up simply?