Eradication refers to what happens following containment of a cyber attack incident. After the threat has been contained, it is necessary to eradicate (remove) key components of the security incident. Removing malware from all infected systems that were moved offline during the containment phase would be done in the eradication phase of an incident. Common examples of eradication tasks include disabling and resetting breached user accounts, resetting passwords on all domain accounts, and scanning the network for indicators of compromise. Eradication is key to prevent attackers from launching additional attacks on your company.
If you own a business, you need to be doing these basic things to protect your sensitive information:
Most of these recommendations are built into CyberHoot. With CyberHoot you can govern, train, assess, and test your employees. Visit CyberHoot.com and sign up for our services today. At the very least continue to learn by enrolling in our monthly Cybersecurity newsletters to stay on top of current cybersecurity updates.
Related Term: Containment, Recovery, Revision, Root Cause Analysis
Source: Bluegrass Cyber Security
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
For years, organizations have relied on fake email phishing simulations to measure employee resilience to...
Read moreWelcome to our two-part blog series on Microsoft’s new email security enhancement now included in Office 365 P1...
Read more"Being an MSP today is like wearing a neon sign that says, ‘Hack me! I’m the gateway to 100...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.