<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=6226337&amp;fmt=gif">

FS-ISAC Sharing and Communications
During an Incident

Incident Response at FS-ISAC

A key component of FS-ISAC’s mission is to help ensure the resilience and continuity of the global financial services infrastructure and individual firms against events that could significantly impact the sector's ability to provide services critical to the orderly functioning of the global economy.

As the sector grows ever more digitized and interconnected, incidents involving even one firm or a supplier have the potential to impact the global financial system.

When the sector faces a major incident, FS-ISAC provides its members with:

  • Actionable intelligence related to the incident, including threat actor capabilities
    (TTPs and IOCs)
  • Support for impacted firms with intelligence, analysis, and mitigation guidance
  • Analysis of sector-level operational and business impact
  • Industry and public-private incident response coordination
  • Sector-wide public messaging coordination and management

 

 

 

FSISAC-IntelExchange_Share-01

 

Sharing of indicators, incident techniques, lessons learned, and operational resilience best practices

  • Share is the place for FS-ISAC alerting to members.
  • Security alerts contain actionable IOCs and attacker TTPs. In some cases, victim organizations make IOCs and TTPs available only to those directly impacted.
  • Additional analysis on the incident and/or the threat actor and their known exploits, methods and/or malicious code is issued as finished intelligence analysis reports in the Collective Intelligence section of Share.
  • Share also issues post-incident analysis on best practices and lessons learned to help all FS-ISAC members become more resilient.

Connect-Webpage

 

Active discussion and sharing on dedicated chat channels

  • FS-ISAC’s Connect allows members to discuss security topics confidentially and securely.
  • Upon notification of an incident, FS-ISAC creates public channels open to all members on a TLP Amber basis to share Indicators of Compromise (IOCs), attacker tools and techniques (TTPs), operational and cyber mitigation strategies, chain effect impact, and breaking news.
  • Connect may also create TLP Red private channels limited to those directly impacted to share threat intelligence, resilience considerations related to operational risk, security approach advice, and lessons learned during the incident.
  • Members may also contact each other directly to get advice and collaborate.

 

Intelligence Spotlight Call

FS-ISAC may schedule a Spotlight Call on short notice to brief members on the available threat intelligence related to the incident, arming members with timely, actionable threat information to protect themselves and their customers. These calls include speakers with primary, direct knowledge of the incident and/or the threat actor. A Share announcement will be issued about the call, as well as a post to Connect’s Town Square in the ALL team/area. Members on the mailing list will receive an invite (contact Member Services to be added). All calls are recorded and accessible on FS-ISAC Video.

 

From the CISO's Desk

FS-ISAC publishes its own security response in From the CISO’s Desk memos. These reports offer members detailed mitigation guidance, actionable steps to strengthen controls, as well as external links and research to help security teams find the best solutions for their firms and programs.

 

Community Discussions

FS-ISAC’s communities (also known as communities of interest or COIs) are smaller groups within the larger membership that focus on specific sub-sectors, geographies, functions, or topics. Depending on the scope and impact of the incident, relevant communities may do ad-hoc, invite-only, non-recorded calls or relay incident information via mailing lists.

The Business Resilience Committees (BRCs) assess operational risks associated with incidents and the sector’s operational resilience to the potential impacts. FS-ISAC may convene all or part of the regional Business Resilience Committee(s) depending on the scope and scale of an incident. BRC assessments help inform FS-ISAC and sector coordinating bodies on the systemic nature of the incident and potential mitigation options available from an operational perspective.

FS-ISAC operates public-private partnerships (PPPs) regarding intelligence and resilience matters around the world, with security-cleared analysts in the US and UK and intelligence liaisons in other geographies.

 

For intelligence-related sharing and collaboration, FS-ISAC’s Global Intelligence Office (GIO) assigns liaisons to certain PPPs to safeguard member-generated information, anonymize data when needed, and share information with the private sector as appropriate. Member intelligence is never shared with public sector partners without originator approval.

 

For resilience-related analysis and coordination, FS-ISAC’s Resilience team collaborates with PPPs before, during, and after incidents to understand sector risks, assess impact severity at the sector-level, and share information on sector operational capabilities. The Resilience team holds regular coordination calls with PPPs to review playbooks and continuously assess and exercise operational risks.

FS-ISAC’s Media Response Team (MRT) helps to support consistent and cohesive messaging to the media in times of sector-level incidents and/or crises to preserve confidence in the global financial system. Managed by FS-ISAC’s Communications team, the MRT is composed of communications leads from Tier S and Tier 1 member firms, major sector associations, and others on an as-needed basis. The MRT functions according to the level of media attention and concern facing the sector regarding specific cyber issues.

FS-ISAC may publish public mitigation guidance on the FS-ISAC website’s Knowledge section, either based on its own internal security response or as assembled by security leadership in consultation with the intelligence team and member peers.