Ravinn was engaged by a Critical Infrastructure company specilising in Utilities, to review their Cyber security Incident Response Plan (CSIRP) and update it to align with ACSC and SOCI requirements as well as being fit for purpose for the organisation. The Ravinn team conducted a gap analysis against the existing CSIRP with the ACSC requirements, which provided the foundation for a detailed list of recommendations and improvements to their plan. The end result was an updated CSIRP that aligned strongly to industry best practice (ACSC and SOCI) whilst still being tailored to the unique environment that the company operates in.
Two of Ravinn’s security consultants, experienced in Incident response planning and cyber threat intelligence (CTI), worked with the client to ensure that the CSIRP was updated and upgraded whilst being tailored to their unique need and obligations. This included:
The development of this CSIRP was not a challenge, but it is the effects of the clients’ operating environment and the tailoring of this plan to mitigate those that adds complexity.
Creating an effective CSIRP involves several significant challenges, including keeping up with the rapidly evolving and sophisticated threat landscape, managing resource constraints, and ensuring seamless coordination and communication both internally and externally. Additionally, utilities companies must navigate diverse regulatory requirements and legal implications, conduct realistic and regular testing and updates of the IRP, and efficiently manage multiple stakeholders during an incident.
The complexity of their operating environment, which involves multiple locations, systems, and technologies, further complicates the development and implementation of a cohesive IRP. Cultural and organisational challenges, such as ensuring employee awareness and training, and maintaining executive support, also play a crucial role.
Ravinn was able to update and provide a comprehensive CSIRP with supporting artefacts that will provide sufficient guidance and direction to the company in the instance of a cyber security incident. The supporting templates provided allows for a structured response and effective documentation of the incident and flow on effects.
Ravinn has proven experience in Cyber security Incident Response throughout multiple industries and critical infrastructure sectors, specifically having been involved in the development of CSIRPs for organisations within the transport sector, energy sector, water sector and healthcare sector. Our Incident Response Approaches are: