Back to home
Business·

Andorran Cybersecurity Experts Urge Pre-Planned Incident Response Frameworks

At an Andorra tech event, specialists advised firms to establish advance criteria for executive decisions, response teams, and drills to handle cyber crises effectively amid high stress and limited information.

Key Points

  • Experts at ACTINN's Actinn&Talks event recommend clear decision rules and team drills before cyber attacks.
  • Yobany Barbosa of Var Group Andorra highlights stress, tight timelines, and incomplete data in crises.
  • Session covers crisis team setup, legal duties, and tabletop simulation exercises.
  • Emphasis on protocols for detection, response, resolution, and restoring operations.

Cybersecurity experts at an Andorran technology event have recommended that companies prepare detailed response frameworks before cyber incidents strike, focusing on clear decision-making rules and team drills.

The guidance came during a recent Actinn&Talks session hosted by ACTINN, Andorra's technology and innovation cluster. Titled Quan l’atac ja ha tingut lloc ("When the Attack Has Already Happened"), the conference explored strategic approaches to managing cyber crises.

Nacho Martín, ACTINN's director, moderated the event, which featured a talk by Yobany Barbosa, head of cybersecurity at Var Group Andorra. Barbosa described the high-stakes environment faced by executives in such scenarios, marked by intense stress, tight timelines, and often incomplete data.

"It's important that organisations define criteria in advance for who makes decisions and how to respond depending on the incident type," Barbosa said. He outlined the goal of creating a management structure to detect issues, respond effectively, and fully resolve crises, restoring normal operations.

Discussion also covered crisis team makeup, relevant legal and contractual duties, and the stages of incident handling. Experts advocated simulation drills, including "tabletop" exercises, to assess readiness without real-world risks.

The session wrapped up by stressing pre-planned protocols for decision processes, compliance needs, and cross-team collaboration to navigate attacks successfully.

Share the article via