- Job title
- Information Security Specialist
- Sector
- Agriculture
- Organization type
- two-branch business
- Joined
- Jul 2023
- Message
- 114
We're a 14-person logistics and customs consulting office based in Frankfurt. Last month, a company next door had all their servers locked by ransomware; they couldn't operate for nearly two weeks and it was sheer chaos. Seeing that hit close to home we sat down as a team and realized: if we faced a similar cyberattack or a major data leak tomorrow morning, we wouldn't even know who to call or who should handle the initial response.
An external IT consultant who supports us said we need to build an 'Incident Response Lifecycle.' He talked about BSI and NIST standards and four core phases like Vorbereitung (preparation) Erkennung (detection), Eindämmung (containment), and Nachbereitung (lessons learned). But honestly, it felt like theoretical guidelines written for massive corporations with hundreds of employees and dedicated security operations centers.
How can a small business like ours, with no full-time in-house IT staff and a tight cybersecurity budget, set up this incident response lifecycle in a practical, workable way? Where should we even start?