Incident Response
Sharing and communications during an incident
A key component of FS-ISAC’s mission is to help ensure the resilience and continuity of the global financial services infrastructure and individual firms against events that could significantly impact the sector's ability to provide services critical to the orderly functioning of the global economy.
As the sector grows ever more digitized and interconnected, incidents involving even one firm or a supplier have the potential to impact the global financial system.
When the sector faces a major incident, FS-ISAC provides its members with:
- Actionable intelligence related to the incident, including threat actor capabilities
(TTPs and IOCs) - Support for impacted firms with intelligence, analysis, and mitigation guidance
- Analysis of sector-level operational and business impact
- Industry and public-private incident response coordination
- Sector-wide public messaging coordination and management
Sharing of indicators, incident techniques, lessons learned, and operational resilience best practices
- Share is the place for FS-ISAC alerting to members.
- Security alerts contain actionable IOCs and attacker TTPs. In some cases, victim organizations make IOCs and TTPs available only to those directly impacted.
- Additional analysis on the incident and/or the threat actor and their known exploits, methods and/or malicious code is issued as finished intelligence analysis reports in the Collective Intelligence section of Share.
- Share also issues post-incident analysis on best practices and lessons learned to help all FS-ISAC members become more resilient.
Active discussion and sharing on dedicated chat channels
- FS-ISAC’s Connect allows members to discuss security topics confidentially and securely.
- Upon notification of an incident, FS-ISAC creates public channels open to all members on a TLP Amber basis to share Indicators of Compromise (IOCs), attacker tools and techniques (TTPs), operational and cyber mitigation strategies, chain effect impact, and breaking news.
- Connect may also create TLP Red private channels limited to those directly impacted to share threat intelligence, resilience considerations related to operational risk, security approach advice, and lessons learned during the incident.
- Members may also contact each other directly to get advice and collaborate.
Intelligence Spotlight Call
FS-ISAC may schedule a Spotlight Call on short notice to brief members on the available threat intelligence related to the incident, arming members with timely, actionable threat information to protect themselves and their customers. These calls include speakers with primary, direct knowledge of the incident and/or the threat actor. A Share announcement will be issued about the call, as well as a post to Connect’s Town Square in the ALL team/area. Members on the mailing list will receive an invite (contact Member Services to be added). All calls are recorded and accessible on FS-ISAC Video.
From the CISO's Desk
FS-ISAC publishes its own security response in From the CISO’s Desk memos. These reports offer members detailed mitigation guidance, actionable steps to strengthen controls, as well as external links and research to help security teams find the best solutions for their firms and programs.
Community Discussions
FS-ISAC’s communities (also known as communities of interest or COIs) are smaller groups within the larger membership that focus on specific sub-sectors, geographies, functions, or topics. Depending on the scope and impact of the incident, relevant communities may do ad-hoc, invite-only, non-recorded calls or relay incident information via mailing lists.
FS-ISAC operates public-private partnerships (PPPs) regarding intelligence and resilience matters around the world, with security-cleared analysts in the US and UK and intelligence liaisons in other geographies.
For intelligence-related sharing and collaboration, FS-ISAC’s Global Intelligence Office (GIO) assigns liaisons to certain PPPs to safeguard member-generated information, anonymize data when needed, and share information with the private sector as appropriate. Member intelligence is never shared with public sector partners without originator approval.
For resilience-related analysis and coordination, FS-ISAC’s Resilience team collaborates with PPPs before, during, and after incidents to understand sector risks, assess impact severity at the sector-level, and share information on sector operational capabilities. The Resilience team holds regular coordination calls with PPPs to review playbooks and continuously assess and exercise operational risks.