REDDIT 原始帖子

Reporting Criteria

I am fighting what feels like a losing battle, but I do genuinely want input (other than "run"). For anonymity, i work in financial industry. We had a user get caught by phishing and download (and execute) a piece of remote support software. This was then…

原帖正文r/sysadmin

I am fighting what feels like a losing battle, but I do genuinely want input (other than "run"). For anonymity, i work in financial industry. We had a user get caught by phishing and download (and execute) a piece of remote support software. This was then downloaded and executed by two other users (One a senior exec). We are running app blocking services, but they were circumvented. When we isolated the device using our EDR, the device was still talking to the remote support service until we pulled the NIC. Concerned by this, and not equiped to do our own forensics, the head of security wanted to reach out to cyberinsurance for investigation support (our current IR plan, and only recourse for forensics). We got approval from that same exec and contacted them. Long story short, we got a clean bill from the cyber insurance. Now, myself and the security team are getting dragged before the board to explain ourselves because none of the execs (now including the one who approved) agreed with our decision at the time (retroactively), since it was clean thinks it was a waste of money, and want us to foot the bill. All this to hear, while this was happening, we had an actual breach they were trying to "cover up" (the execs words not mine). This board hearing is still coming, and I was hoping to get advice from anyone else getting chewed out on how to defend myself.

已收录讨论

9 条评论

u/LoPath

I'd definitely write this all up in an executive summary and outline what could have happened if you did nothing. As nothing is exactly what they think you should have done. Make it clear the damage that would have been caused, including reputational damage and potential costs.

u/apple_tech_admin

Period. I have seen people get in some truly gnatly situations because regulations can and will fuck you up.

u/Training_Yak_4655

Best answer

u/Ssakaa

we had an actual breach they were trying to "cover up" other than "run" So they want IT to foot the bill for the by-policy incident response, they're already engaged in fraud in breach of multiple regulations that include mandatory reporting, and you're thinking of anything OTHER than run? If you can get any of that in writing, blow the whistle on the way out the door. But step 1 is run. Edit: And, to add to this. They're LITERALLY telling you they want to throw IT under a bus for the more minor one. If you think they're going to do anything other than that when the big one hits the fan...

u/Khrog

Documentation will handle this for you. Upon recommendation from [Head of Security], we sought and received approval from [exec's name] for initiating a forensic investigation with [vendor] on [date]. Thankfully, the forensics investigation gave us a clean bill of health post- incident. The incident required disconnecting the affected devices from the network and we are fortunate to have [product] detect the phishing breach so early. Something along those lines will indicate the potential that, the good practices that prevented it, and the approval of the extra resources. Should cover all your bases... bring your receipts on the approval.

u/overdosingOnPie1313

Sorry, mate. That battle was lost. If you have those conversations on record, send the emails to a personal mailbox ASAP and start dusting off your resume.

u/apple_tech_admin

Im assuming since you are having a meeting with the board, you are in some position of power. I would simply stick to the facts of the event, and present the evidence (in terms of revenue loss to the business) had you tried to cover it up. Present lessons learned and next steps. Then refresh your resume. Anytime I observe executives trying to cover shit up, my ears perk. Depending on the severity of the event, monitor to see if any execs depart.

u/TechinBellevue

Here's how you start off: Being that we are required, by law, to follow certain protocols and, as per corporate policy... Throw in something about the weakest link in any company is our own people and that is exactly where this started.... End with something like: The penalties for failing to follow the strict protocols are estimated to be $ millions of dollars. I would not, nor will never put this company, our shareholders, or clients in this situation. To do so would not only be illegal, but also unethical. You're welcome. Now, let me outline what we are doing to protect ourselves moving forward.

u/heretogetpwned

You got receipts of those conversations? I'm a bastard and I'd also be sneaking in a litigation hold on my mailbox, too. But that's not advice, you might piss more people off in your org if you do it.