
Prevention is NOT Preparation
- Failing to prepare is preparing to fail-being a casualty is avoidable
- It’s not if, it’s when - prepare for the when
- Spend equally between prevention and preparation
- React (fear/panic) vs. Respond (logical, planned)
Think Preparation AND Prevention
Preparation - it’s easier to write a check than to spend time - preparation takes time from high level people at your company.
- Risk management assessment (including tech, OT, physical)
- Immutable backups
- Incident Response IR plan-table top exercises
- Disaster Recovery DR Plan-DR Test
- Cyber Insurance-where you follow the declarations!
- MFA
- Setup Zero Trust