Here, we will look at another element of cyber response that further improves a team’s incident response capability: connectivity analysis. This gives the SOC team a deeper understanding of the potential impact of an incident, by highlighting the connectivity to and from the assets that have been compromised by the incident. In other words, it shows staff the size of the security risk by indicating how far the attack could potentially spread.

The post Why and how to bring connectivity analysis into incident response appeared first on algosec.