Blueprint: Build the Best in Cyber Defense cover image

Strategy 5: Prioritize Incident Response

Blueprint: Build the Best in Cyber Defense

00:00

How to Close Up an Incident That Has Occurred

Being good at PIRs is actually one of the best ways the SOC can get better and be the engine for change in the entire enterprise. One of the things that I like doing during any medium or larger sized incident is having a scratch pad of what I affectionately refer to as PIR slop. It's a quick space that people who are involved in the incident can jot down notes in the heat of the moment on something they saw that didn't go well for them. And through the course of the big incident or even the medium size incident, they collect slop.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app