Incident response planning is vulnerable to legacy thinking

Companies need to prioritize risk management and shift focus to internal threats when considering security, with over 80% of incidents stemming from insiders. This calls for a broader approach not focused on outside attacks, but on information-based threats. Ways to improve include more active detection and reporting systems, containment methods, and regular checks on dark web for leaked information. It’s also crucial to delve deeper into root causes of incidents, rather than stopping at ‘human error’. Emphasizing a no-blame culture will foster reporting of near misses, revealing vulnerabilities for improvement.

