- Preparation (Prior to Any Event):
- Cybersecurity pre-plan checklist (available at https://www.nclgisa.org/page/strike-team)
- Ongoing Shodan reviews (complete this form to sign up: https://forms.gle/R6iXGVPcgm57gkcH9 )
- Weekly Nessus scanning (complete this form to sign up: https://forms.gle/R6iXGVPcgm57gkcH9)
- Consultation on cyber-related questions including backup strategies, centralized logging, EDR, IDS/IPS, MFA, and specific technologies
- Immediate and Sustained Structural Services During and Post-Breach:
- Incident command/ITSL expertise
- Project management
- Cyber liability insurance expertise
- Legal guidance related to public records/breach notification/etc.
- Documentation support
- Communication and coordination guidance
- Resource identification and leverage from NCLGISA community and state of NC
- Identification:
- Research variant and offer insight from previous events (led by NCNG)
- Analyze entry point and spread of breach (led by NCNG, Strike Team assists as needed)
- Review log files (as needed if directed by the NCNG)
- Containment:
- Recommendations to isolate attack
- Recommendations to preserve evidence for forensic investigations
- Eradication:
- Recommendations of approach and tools to assist and mitigate future attacks
- Assist with tool deployment as needed
- Provide recommendations on network protocols, network design/security, applications/services, backup strategies, etc
- Onsite rebuild assistance (depending on availability/skillsets needed)
- Recovery:
- Prioritization of recovery steps, down to department level (if not already established)
- Assistance with hardening infrastructure by applying CIS Level One Controls
- Expertise in firewalls, networking, and other infrastructure components (onsite or remote assistance depending on availability)
- Scripting services for imaging, etc
- Expertise with governmental systems and their critical interdependences
- General troubleshooting of infrastructure and application issues
Download Strike Team Catalog
Contact Information:
Email: itstriketeam@nclgisa.org
Telephone: (919) 726-6508 (monitored 24/7)