Improved cyber resilience with Commvault and CrowdStrike
Geplaatst op: 1 April 2025

Last week, two of our key vendors further strengthened their collaboration. We from OpenSight are pleased to see the integration and consolidation continue within our commited vendors.
Commvault en Crowdstrike
Commvault, a leading player in data protection and cyber resilience for hybrid cloud environments, has announced a strategic partnership with CrowdStrike to integrate their advanced cyber security platform, Falcon. This collaboration is aimed at improving cyber threat detection and ensuring rapid recovery, thereby providing businesses with better protection against modern cyber attacks.
By using CrowdStrike’s comprehensive threat intelligence and security data, combined with Commvault’s cloud-first capabilities, this integration provides joint customers with an additional layer of security. This is achieved through real-time threat insights, faster detection and remediation processes.

Benefits of the integration
- Proactive threat detection: Using CrowdStrike’s AI-driven insights and Indicators of Compromise (IOCs), organisations can identify threats early and respond quickly to mitigate damage.
- Faster recovery of clean data: Companies can quickly restore their systems by locating the last known clean version of their data, minimizing disruptions.
- Seamless collaboration: The integration creates smoother workflows between security operations (SecOps) and IT operations (ITOps) teams, leading to more effective threat response and recovery.
- Continuous operation: By reducing recovery time and downtime, companies can keep their critical services running even during complex cyberattacks.
Strengthening the Cybersecurity Ecosystem
This partnership with CrowdStrike reflects Commvault’s ongoing commitment of expanding its cyber security ecosystem. The company is actively working with leading security providers to develop comprehensive solutions to detect, mitigate and recover from cyber attacks. By integrating their respective strengths, Commvault and CrowdStrike aim to provide companies with a solid defence against cyber threats, enabling them to recover quickly and mitigate damage.
If you want to know more about this integration, feel free to contact us.
Commvault Cloud enables CIS-hardened deployment on cloud hyperscalers marketplaces
Geplaatst op: 1 April 2025

Commvault, a leading provider of cyber resilience and data protection solutions for the hybrid cloud, announced today that the Commvault Cloud Platform can be easily deployed from large cloud marketplaces using CIS hardened images. These CIS-hardened images are pre-configured with CIS-recommended settings and controls and are available on the following marketplaces: Amazon Web Services (AWS), Microsoft Azure, Google Cloud and VMware.
CIS-hardened images
CIS-hardened installation copies are software files pre-configured to meet Centre for Internet Security (CIS) benchmarks. Hardening helps reduce vulnerabilities in configurations, such as overly permissive network policies that can create opportunities for malicious actors. In fact, configuration errors are one of the most common causes of vulnerabilities in the cloud, contributing to 23% of attacks on cloud infrastructure, according to industry research. Commvault’s CIS-hardened images are designed to mitigate these risks by pre-configuring the deployment to meet strict security benchmarks out-of-the-box, giving confidence to IT and security teams.
With today’s announcement, Commvault continues its focus on cyber security, adding these deployment options to other security certifications such as FedRAMP® High Authorised, ISO27001:2013, SOC 2, Type II and FIPS 140-2. Customers can use the new CIS-hardened images to quickly and confidently configure and implement Commvault Cloud and benefit from:

- Ready-made compliance controls: CIS hardened images provide organizations with secure, hardened environments from the moment of implementation and give customers confidence that their control plane has been installed and configured using industry-recognised best practices.
- Enhanced cyber security: CIS-hardened images minimize vulnerabilities by addressing common misconfiguration risks and providing peace of mind against attacker misuse.
- Streamlined compliance assignment: CIS benchmarks are assigned to key security frameworks such as NIST CSF, HIPAA, PCI-DSS and ISO 27001, simplifying compliance with complex regulatory requirements.
- Wide availability of marketplaces: Organisations can implement Commvault Cloud directly from AWS, Azure, Google Cloud or VMware marketplaces, enabling fast and secure installations with minimal effort.
Strengthening the Cybersecurity Ecosystem
This announcement coincides with a growing trend of organizations transitioning to the cloud. According to IDC, spending on public cloud services is expected to double to $1.6 trillion by 2028. Over the past year, Commvault has introduced a number of cloud-first offerings to help customers become more resilient in the cloud, including Cleanroom Recovery, Cloud Rewind and Clumio Backtrack. Now the company is taking cloud resiliency to the next level with CIS hardened images for popular cloud marketplaces.
Why is this important?
- Reduction of vulnerabilities: CIS-hardened installation copies are pre-configured to meet CIS benchmarks, which helps reduce configuration vulnerabilities. This is crucial, as configuration errors are one of the most common causes of cloud vulnerabilities, contributing to 23% of attacks on cloud infrastructure.
- Enhanced cyber security: CIS-hardened images minimize vulnerabilities by addressing common misconfiguration risks and provide peace of mind against attacker misuse.
- Ready-made compliance controls: CIS hardened images provide organizations with secure, hardened environments from the moment of implementation and give customers confidence that their control plane has been installed and configured using industry-recognised best practices.
- Streamlined compliance assignment: CIS benchmarks are assigned to key security frameworks such as NIST CSF, HIPAA, PCI-DSS and ISO 27001, simplifying compliance with complex regulatory requirements.
- Wide availability of marketplaces: Organisations can implement Commvault Cloud directly from AWS, Azure, Google Cloud or VMware marketplaces, enabling fast and secure installations with minimal effort.
If you want to know more about how we can harden your Cyber Resilency environment based on the CIS standards, feel free to contact us.
Crowdstrike’s Global Threat report 2025
Geplaatst op: 1 April 2025

Our technology partner Crowdstrike annually publishes the Global Threat Report, which provides insight into key cybersecurity trends and developments. The 2025 report also provides essential insights and clear recommendations for an effective cybersecurity strategy.
This year, some notable trends have been identified:
Breakout time at historic low: The average time it takes attackers to move laterally within a network has decreased to a mere 48 minutes. In fact, the fastest breakout recorded was just 51 seconds.
Voice phishing is skyrocketing: Cybercriminals are increasingly using telephone contact to trick victims with convincing social engineering techniques. Between the first and second half of 2024, this form of cybercrime grew by a whopping 442%.
Growth of initial access as a service: Attacks aimed at gaining initial access have increased significantly. This now accounts for 52% of the vulnerabilities Crowdstrike observed last year. Cybercriminals are increasingly offering initial access ‘as a service’, with an annual increase in ads of around 50%.
Increase in China-nexus cyber activity: Cyber attacks from China-related threat actors increased by 150% on average. Specific industries faced 200% to 300% more attacks.
Deployment of generative AI in cyber attacks: Generative AI technologies were actively deployed for advanced attacks and disinformation campaigns by China-, Russia- and Iran-linked threat actors, among others. For example, highly convincing fake job applicants were created to penetrate organizations.

Crowdstrike offers 5 specific recommendations in the report:
- Secure your entire identity ecosystem: use phishing-resistant MFA solutions such as hardware security keys.
- Eliminate cross-domain gaps: deploy next-gen XDR and SIEM solutions to strengthen detection and response capabilities.
- Protect your cloud infrastructure: deploy CNAPP solutions and implement strict access control and regular audits.
- Prioritise vulnerabilities strategically: Patch and upgrade systems regularly and use tools like Falcon Exposure Management.
- Use threat intelligence effectively: Know who your attackers are, how they operate, and adjust your security strategy accordingly.
Download the full Crowdstrike Global Threat Report 2025 at the bottom of this page.
The AI Act in Europe
Geplaatst op: 1 April 2025

the AI Act is a new European legislation that establishes harmonized rules for artificial intelligence (AI) systems within the EU. The primary goal of this legislation is to encourage reliable and human-centred AI applications. Adding tot that, the AI Act protects fundamental rights of citizens, ensures safety and secures a high level of environmental protection. An additional benefit is that this legislation supports the free movement of AI-based goods and services within the internal market.
The AI Act brings new standards and guidelines that your AI systems are required to comply with. This means that, as an organization, you need to strengthen the confidence in your AI solutions while managing the risks of AI-related cyber attacks. In addition, you need to develop strategies to counter unwanted use of AI. Adapting to these new rules in a timely manner is crucial for compliance and making the most of reliable AI technologies.
The AI Act has different obligations depending on the level of risk of the AI system you are using or developing:
- Prohibited AI: Developing, offering and using certain AI systems is strictly prohibited. Violations are severely punished with fines of up to €35 million or up to 7% of annual global turnover.
- High-risk AI: Systems that pose significant risks are subject to extensive obligations. These include mandatory risk analyses, human control, full transparency and mandatory registration of the system.
- Limited risk AI: These systems primarily require transparency obligations, such as clear user notifications on the use of AI.
- Minimal risk AI: No specific obligations apply. However, best practices are strongly recommended.
In addition, AI developers must meet various compliance obligations:
- Preparing detailed documentation explaining how the AI works and how the system is trained.
- Applying ethical and technical standards to avoid bias and discrimination in the AI model.
- Implementation of an effective risk management system specific to AI.
The AI Act is not isolated legislation, but works together with existing EU regulations, such as:
- GDPR: AI systems processing personal data must comply with strict privacy rules.
- NIS2: AI solutions within essential sectors, such as energy and telecoms, must meet cybersecurity standards.
Non-compliance carries significant risks:
- High fines of up to 7% of global turnover or €35 million.
- Possible ban on the use of non-compliant AI systems.
- Serious reputational damage and legal consequences.

How do you ensure compliance with the AI Act?
The AI Act is already in force. Therefore, Opensight advises your organization to take the following steps:
- Map AI use: Identify which AI systems are being used or developed within your organization. Classify these systems by risk level.
- Check specific obligations: Check whether your AI is transparent enough, risks are well managed and documentation is complete.
- Integrate AI risk management: Make AI compliance part of your existing Information Security Management System (ISMS) or Governance, Risk & Compliance (GRC) framework.
- Combine with existing regulations: Ensure integration with GDPR privacy regulations and NIS2 cybersecurity standards.
- Use support tools: Automate compliance processes and ensure proper documentation to make audits hassle-free.
The AI Act is causing sweeping changes within companies that develop, sell or use AI. Therefore, invest timely in reliable and transparent deployment of AI and avoid fines, legal problems and damage to your reputation.
The future of information security: why Zero Trust and AI are now essential
Geplaatst op: 19 September 2024

The way we work and do business is changing at lightning speed. Cloud computing, SaaS solutions, and remote working have become the norm. This has given businesses tremendous flexibility, but it has also led to new cyber security challenges. Traditional security models, which relied on the idea of a secure perimeter (such as the “castle and moat” model), no longer suffice in this new world. They are simply not designed for today’s distributed IT environments.
Why Zero Trust?
Imagine a company operating like a medieval castle: thick walls, drawbridges, and watchtowers to keep out the invaders. This worked fine when all employees worked within the castle walls, with their applications and data safe behind them. But now that everyone works from different locations, those walls have actually become useless. We don’t need a castle, we need a whole new way of thinking. This is where Zero Trust comes in.
What makes Zero Trust so powerful?
- No Trust, Always Verify: Zero Trust revolves around the principle that no one is automatically trusted. Whether someone is inside or outside the network, their access is continuously verified. This is a radical shift from the old model, where everyone inside the fortress was considered “safe.
- Protection against lateral movement: One of the biggest threats today is the ability for attackers to move laterally within a network once they are inside. Zero Trust prevents this by giving users access only to specific applications, rather than to the entire network.
- Improved user experience: Unlike traditional methods, where traffic was routed back to a data center (causing delays), Zero Trust enhances performance by directing users straight to the apps they need.

The role of AI in modern security?
When we talk about cyber security, AI is often the secret sauce that makes everything just a little bit better. We live in an era where cyber threats are becoming more sophisticated and persistent. The days when a simple firewall was enough are far behind us. AI allows us to look at security in a whole new way.
How AI helps us
- Real-time threat detection: AI can analyze vast amounts of data in an instant and recognize patterns that indicate potential threats. This makes it possible to identify attacks before they do any damage.
- Automation of security: AI makes it possible to automate routine tasks, such as file scanning and traffic monitoring. This means security teams can focus on the really important things.
- Smart decision-making: AI can help make better, data-driven decisions. By adding context to threat intelligence, security analysts can respond more quickly and accurately.
Practical applications and examples
Take the 2020 pandemic, for example, which caused a huge shift to remote working. Many companies that still relied on traditional security models were suddenly faced with new vulnerabilities. In this situation, Zero Trust offered a robust solution. By treating each user as a potential threat, companies were able to protect their systems even while their staff worked from home.
And then there is AI. In the fight against cybercrime, AI has proven itself indispensable. Imagine a suspicious e-mail entering your inbox. Traditional filters might not pick it up, but an AI system, trained on millions of examples of phishing attempts, recognizes the patterns and blocks the e-mail before it can do any damage.
In short…
Today, the combination of Zero Trust and AI offers businesses a powerful way to protect against the ever-increasing threats in the digital world. It’s not just about strengthening defenses; it’s about rethinking how we approach security in an era where the lines between physical and digital worlds are becoming increasingly blurred. Companies that embrace these technologies will not only be better protected, but better positioned to take advantage of the opportunities of the future.
Key takeaways from the 2024 Threat Hunting Report
Geplaatst op: 19 September 2024

“As a Cyber Security Specialist at OpenSight, I deal with the complex world of cybersecurity daily, where we are engaged in a race with criminals and state actors. As a Cyber Security Specialist, you know that you’ve chosen a profession where continuous learning and development are a must, as your adversaries are also constantly evolving. We often review reports from key players in this field. Recently, I reviewed the CrowdStrike 2024 Threat Hunting Report, and I’d like to share some of my findings and advice with you. This report not only provides insights into the latest trends in cyber threats but also emphasizes the need for a proactive approach to effectively combat these threats. Let’s dive deeper into what this means for you and your organization.”
The cunning of modern attackers
“What stood out to me most while reading this report is the constant evolution of attackers. Cybercriminals’ tactics are becoming increasingly sophisticated and dynamic. Where they once relied on simple, automated attacks, we now see a significant rise in so-called ‘interactive intrusions.‘ These are attacks where the attacker is actively sitting behind the keyboard in real-time, ready to bypass security measures as they appear.”
“This has significant implications for how we protect our networks. The speed and cunning with which these attackers operate make it essential not only to rely on automated security measures but also to have well-trained personnel capable of detecting and countering these advanced attacks. CrowdStrike’s report highlights the importance of speed in detection and response, which perfectly aligns with my own experiences.”
Cross-Domain Threats: An Increase in Complexity
“Another key insight from the report is the growing threat of cross-domain attacks. These are attacks where various parts of the IT infrastructure are targeted simultaneously, such as identity systems, endpoints, and cloud environments. What makes these attacks particularly dangerous is that they are often difficult to detect because the activities are spread across multiple domains, making them appear less suspicious when considered individually.”
“The challenge here is to see these activities in context and understand how they are related. This requires not only advanced technology, such as CrowdStrike’s AI-driven solutions, but also an in-depth knowledge of the various IT domains and how attackers can exploit them.”

Insider threats: the invisible danger
“The report also sheds light on one of the most insidious threats we face: insider threats. These are threats originating from within the organization, often from employees who, whether intentionally or unintentionally, engage in harmful activities. What I found particularly concerning is the example of FAMOUS CHOLLIMA, a group of attackers who managed to enroll as employees at over 100 companies in the US, gaining access to sensitive information from within.”
“These insiders used their access to install Remote Monitoring and Management (RMM) tools, allowing them to operate remotely and conduct their malicious activities without immediate detection. This highlights the need for stringent access control and continuous monitoring of user activity, even within the organization.”
The solutions: proactive threat hunting and AI
“In my opinion, the key to securing organizations against these complex threats is a combination of proactive threat hunting and the use of AI. As the report indicates, the time an attacker needs to move laterally within a network (the so-called ‘breakout time’) is often just a few minutes. This means there is no time to waste in detecting and responding to an attack.”
“AI can play a crucial role here by analyzing vast amounts of data in real-time and identifying patterns indicative of a threat. CrowdStrike’s Falcon platform is an excellent example of how AI can be used not only to detect attacks but also to automatically respond and prevent further damage. This kind of technology is indispensable in the fight against modern cyber threats.”
My advice for businesses
Based on the findings in the report and my own field experiences, here are some recommendations I would like to offer to businesses looking to enhance their security:
- Keep learning and adapting: The world of cybersecurity is constantly changing. Stay informed about the latest trends and techniques, and ensure that your security strategy aligns with them.
- Invest in proactive threat hunting: Don’t wait for an attack to occur before taking action. Ensure that you have a team constantly searching for potential threats, both inside and outside the network.
- Utilize AI and Machine Learning: Traditional security systems often fall short when it comes to detecting today’s complex attacks. Invest in AI-driven solutions that can recognize patterns and respond quickly to suspicious activities.
- Manage access strictly: Insider threats are a serious danger. Ensure you have strict access controls in place and continuously monitor who has access to which systems and data.
- Monitor cloud environments closely: With the shift to cloud computing, it is essential to have a clear view of what is happening in your cloud environments. Attackers are increasingly targeting these areas, so make sure your cloud security is robust.
In short…
“The CrowdStrike 2024 Threat Hunting Report provides valuable insights into the modern threat landscape and confirms much of what we already know: threats are becoming more complex, attacks more sophisticated, and response times shorter. As a Cyber Security Specialist, it is clear to me that the future of security lies in a proactive, intelligence-based approach, supported by the power of AI. By combining these approaches, we can ensure that our organizations are not only protected against today’s threats but also prepared for the challenges of tomorrow.”
“Let’s work together towards a safer digital future!”
“Do you have questions or want to learn more about how to better secure your organization? Feel free to reach out via my LinkedIn profile!”
~ Marcel Krommenhoek
Cyber Security Trends for 2024: Why Zero Trust and AI Keep Your Business Safe
Geplaatst op: 12 September 2024

It’s no secret that the world of cybersecurity is constantly evolving. Businesses face new challenges and threats daily, making it essential to stay updated with the latest trends. Two technologies dominating the conversation this year are Zero Trust and Artificial Intelligence (AI). But what do they really mean for your business? Let’s take a closer look at these trends and what they could mean for you.
The transition to Zero Trust
When we talk about Zero Trust, we’re not just referring to a new tool or buzzword. It represents a fundamental shift in how we approach security. The traditional model, where companies relied on perimeter-based security, has seen its day. This approach, which was once enough to keep threats out, now falls short in the era of cloud computing and remote work.
Why is Zero Trust so important?
- Security for a decentralized world: In an era where employees can work from anywhere at any time, it’s crucial to ensure they have secure access to the resources they need, without the risk of unauthorized access.
- Protection against internal threats: Not all threats come from the outside. Sometimes internal actors, whether intentional or not, pose a significant risk. Zero Trust ensures that no one, not even internal users, has access to more than they need.
- Flexibility and scalability: As businesses grow and evolve, Zero Trust offers a flexible approach that can easily be adapted to changing business needs.
The impact of AI on security
AI is not just a buzzword in the world of cybersecurity; it’s a game-changer. Traditional security systems are often reactive, meaning they respond only once an attack is already underway. AI changes this by enabling a proactive approach, where threats are detected and neutralized before they can strike.

How does AI make a difference?
- Forward-thinking with predictive analytics: Imagine being able to predict where the next attack will come from. AI makes this possible by analyzing patterns in data and identifying potential threats before they occur.
- Faster response times: When an attack occurs, time is of the essence. AI can respond instantly, neutralize threats, and prevent further damage.
- Integration with existing systems: AI does not work in isolation. It is increasingly integrated with existing security systems, creating a seamless defense that is both broad and deep.
What do these trends mean for your business?
For businesses, the integration of Zero Trust and AI brings several tangible benefits. Firstly, it means better protection against today’s increasingly complex threats. But it also means that your company can respond more flexibly to changes in the market and technology.
Take, for example, a company that is rapidly growing and hiring new employees. With a traditional security approach, it could take months to securely onboard everyone onto the right systems. However, with Zero Trust and AI, this process can be much faster and more secure.
Additionally, AI gives you the ability to identify threats that you might otherwise overlook. This means you’re not only protecting your data but also safeguarding your reputation and business continuity.
In short…
Zero Trust and AI are essential tools for businesses that want to survive and thrive in an ever-changing digital world. By embracing these technologies, you can ensure that your company remains secure and is also prepared for the challenges of tomorrow. It’s time to think about the future of your business security and take the necessary steps to secure that future.
The NIST ‘Recover’ Domain – The importance of a good Disaster Recovery Plan
Geplaatst op: 29 August 2024

Last month was another one of those days, there was a global disruption caused by a bug in software. Unfortunately, the error turned out to be so severe that Windows machines went into a blue-screen of death (BOSD). So even though CrowdStrike had fixed the issue within 90 minutes and stopped pushing the faulty update, the damage had been done. I sympathise with the IT departments that had to deal with this as this must have caused massive chaos. This incident, where problems with CrowdStrike security software led to computer system failures worldwide, highlights the need for a robust Disaster Recovery (DR) plan. This article discusses the importance of a good DR plan and highlights the essential steps: inventory, plan, test, learn and repeat.
Inventory: understand what you need to protect
The first step in creating an effective DR plan is taking an inventory. This involves making a complete and detailed list of all critical IT assets within your organization.
This includes servers, network equipment, software applications, data storage and even physical locations. Understanding which systems and data are critical to your core processes helps prioritize protection measures, as well as develop a plan.
When taking inventory, it is important to also identify dependencies between systems. This means understanding how different components of your IT infrastructure are connected and how a failure in one system can impact other systems. It’s advisable here to look especially at the organization’s core processes and, from that perspective, determine how to get these processes back up and running when things go wrong.
Plan: develop a strategic DR plan
With a thorough inventory, you can move on to the planning phase. A strategic DR plan should include clear procedures for different disaster scenarios, such as natural disasters, cyber attacks, hardware failures and human error. It is essential to assign specific responsibilities to team members and ensure that everyone knows what is expected of them in case of an emergency.
A good DR plan also includes a communication plan. This plan should describe how to communicate internally and externally during and after a disaster. The CrowdStrike incident highlights the importance of transparent communication to prevent panic and keep customers and partners informed of the recovery measures taken.

Test: ensure regular exercises
A DR plan is only as effective as the testing you do. Regular tests are crucial to verify that your plan works in practice. This can range from tabletop exercises, where you theoretically walk through disaster scenarios, to full-scale tests where you assess the operation of your DR plan in a realistic situation.
Testing your DR plan helps identify weaknesses and potential bottlenecks. By uncovering these problems before a real disaster strikes, you can ensure that your plan remains up-to-date and effective.
Learn: draw lessons from every incident
After every test or actual disaster, it’s important to carry out an evaluation and learn from the experience. This process includes analyzing what went well, what did not go well and what improvements can be made. Learning from incidents and tests helps to continuously improve and adapt your DR plan to new threats and technologies.
Repeat: continuous improvement and updating
Developing a DR plan is not a one-off task. It is an ongoing process that needs to be repeated and updated regularly. Technologies evolve, new threats emerge and business needs change. By regularly reviewing and updating your DR plan, you can ensure that you are always prepared for the latest challenges.
The CrowdStrike incident highlights how vulnerable even the most sophisticated IT systems can be and how important it is to have a robust and up-to-date DR plan. By taking inventory, planning, testing, learning and repeating, you can minimize the impact of disasters and ensure the continuity of your business processes. The IT chain is only as strong as its weakest link!
Of course, it is good to keep in mind that despite CrowdStrike causing this catarostrophic incident, they still prevented more downtime for customers than they caused.
OpenSight Back To School Series
During the OpenSight Back To School Series, we publish weekly blogs diving deeper into the five NIST Security Domains:
By implementing the measures associated with these domains, you can reduce the likelihood of cyber attacks and the impact of potential incidents.
The NIST ‘Respond’ Domain – learning to respond effectively
Geplaatst op: 27 August 2024

In the world of cybersecurity, it’s crucial not only to know how to prevent an attack but also how to respond effectively when something does go wrong. The NIST (National Institute of Standards and Technology) Cybersecurity Framework offers a structured approach for organizations to enhance their cybersecurity. One of the key components of this framework is the ‘Respond’ domain. In this blog, we discuss the main aspects of this domain, including Response Planning, the 24/7 Security Operations Center (SOC), Cyber Security Incident Response Team (CSIRT), Security Orchestration, Automation, and Response (SOAR), and Incident Management Tools.
Response Planning: expecting the unexpected
In our previous NIST blogs, the topic of Response Planning frequently came up as a suggestion for implementation. In this blog, we’ll dive deeper into what Response Planning actually entails and why it is so important. Response planning is the backbone of an effective response strategy. It involves developing and implementing a plan that includes procedures and protocols to ensure that every team member knows what to do in the event of an incident. This guarantees less panic when something does go wrong.
How can you effectively apply Response Planning in your organization?
- Develop a Dynamic Plan: Ensure that your response plan is flexible enough to accommodate changes when new threats or technologies emerge. This means regular updates and reviews.
- Train Your Team: Practice makes perfect! Regular drills and simulations of incidents ensure that everyone on the team knows their role during a real incident.
- Communicatie is Key: Have a clear communication plan that describes how information will be shared during an incident, both internally and externally.

24/7 SOC: The digital night watch
A Security Operations Center (SOC) is a central unit or team within an organization responsible for monitoring, detecting, and responding to security incidents around the clock. They keep an eye on everything that’s happening and if something suspicious comes up, they are quick to respond.
How to implement a SOC successfully?
- Assemble a Team: Gather a team of experienced security experts responsible for monitoring and responding to security incidents. This can be an internal team or an outsourced one.
- 24/7 Monitoring: Ensure that there is always someone on duty. Threats don’t adhere to office hours. Have a robust schedule so your SOC is always staffed, including weekends and holidays, without overburdening your team.
- Use Smart Tools: Automated monitoring tools can help your SOC team work faster and more efficiently.
- Quick Escalation Protocols: Ensure the SOC team has clear protocols for escalation when a critical threat is detected.
CSIRT: “The A-Team” of cyber incidents
The Cyber Security Incident Response Team (CSIRT) is your first line of defense when things go south. This team is there to jump into action, minimize damage, and get your organization back on track. Essentially, a CSIRT is like a fire brigade, but for cybersecurity.
Tips for establishing and deploying a CSIRT within your organization:
- Create a Multidisciplinary Team: Ensure a mix of different experts—from IT to legal—so that all aspects are covered. Like a SOC, a CSIRT doesn’t have to be entirely internal; it can also include external experts. However, ensure clear role distribution. Everyone should know who is in charge during an incident and who is responsible for what task.
- Quick Decision-Making: A good incident triage ensures that the most critical threats are dealt with first.
- Evaluation and Feedback: Conduct thorough evaluation and feedback sessions to identify lessons learned and improve processes.
SOAR: Smarter responses
SOAR (Security Orchestration, Automation, and Response) includes all the tools that make your cybersecurity much more efficient. It automates many of the time-consuming tasks and allows your team to focus on the really important matters. Less time wasted, faster responses—that’s what SOAR is all about.
4 tips for successful SOAR implementation
- Automate Repetitive Tasks: Let SOAR handle tasks like log analysis and incident classification, so your team can focus on more complex issues.
- Develop Playbooks: Create standard procedures for common incidents to ensure quick responses.
- Integrate with Existing Tools: Make sure your SOAR platform integrates with your existing security tools, like SIEM systems, for a seamless workflow.
- Alerts and Notifications: Set up alerts for critical events in SOAR, so relevant teams are immediately informed.
Incident Management Tools: The toolbox for cyber incidents
Incident management helps you keep everything organized, from the initial incident report to the final resolution. These tools help teams work in an organized and efficient manner, especially when multiple incidents need to be managed simultaneously. With the right tools, you can coordinate the entire incident response without causing panic.
How to effectively use Incident Management Tools?
- Choose the right tools: Select incident management tools that fit the size and needs of your organization. They should be scalable and capable of handling different types of incidents.
- Integration with their systems: Ensure that your incident management tools integrate seamlessly with your SOC, SIEM, and other security systems.
- Incident logging: Record every incident in detail, including timestamps, affected systems, and actions taken, for future reference.
- Automate Workflows: Use the tools to automate as many workflows as possible, from incident detection to reporting.
In short…
The NIST ‘Respond’ domain is crucial for reacting calmly, organized, and effectively to cyber threats. By focusing on response planning, having a 24/7 SOC, a sharp CSIRT, and utilizing SOAR and incident management tools, your organization can better prepare for and respond to cyber threats. This not only helps to minimize damage but also to maintain the trust of stakeholders during times of crisis.
Do you have questions about this blog or need help implementing the Respond domain? Feel free to contact us; we at OpenSight are at your disposal!
OpenSight Back To School Series
During the OpenSight Back To School Series, we publish weekly blogs diving deeper into the five NIST Security Domains:
By implementing the measures associated with these domains, you can reduce the likelihood of cyber attacks and the impact of potential incidents.
