140 likes | 565 Views
Rapid Response Retainer Service Overview. Why Verizon Rapid Response Retainer?. Computer security incidents continue to rise Sensitive data breaches, corporate espionage, malware, hacktivism Internal and external threats No company or industry is immune to being attacked
E N D
Why Verizon Rapid Response Retainer? • Computer security incidents continue to rise • Sensitive data breaches, corporate espionage, malware, hacktivism • Internal and external threats • No company or industry is immune to being attacked • Not a matter of “if” but “when” you will have a computer security incident • How prepared are you? • Benefits of the Rapid Response Retainer: • Trusted relationship established upfront – prior to an incident • Quick to engage: Contract already in place when you need us in an emergency • Guaranteed response SLAs, worldwide • Discounted hourly rates (vs. non-Retainer customers) • Ability to leverage Network-based Intelligence from the global Internet backbone • No other forensic vendor offers this capability!
RISK Team Services Proactive Services Reactive Services • Forensic Investigations • Malware Analysis • PCI Investigations (PFI) • Mobile Forensics • Electronic Data Recovery and Destruction • eDiscovery and Litigation Support • Network Intelligence • Incident Response Plan Development • First Responder’s Training • Mock Incident Exercises • Industrial Control Systems Cybersecurity Assessments • IDS 2.0 and Netflow Analysis • Watchlist Matching • Incident Analytics Verizon RISK team has investigated 8 of the world’s 10 largest data breaches!* *Source: http://www.idtheftcenter.com/
Triggering the Retainer Engagement Letter / Scope Objectives Incident Occurs On-Site Delivery Commences Customer Calls Retainer Hotline Investigator(s) In-Transit Forensic Investigation and Documentation of Findings
Retainer Engagement Letter • Engagement Letter: • Defines scope and objectives • Obtains customer’s authorization • Ensures accountability • Filled out by a member of the Verizon RISK team after initial escalation call • Customer signs and returns to Verizon
Retainer Onboarding Process • Escalation Channels • Engagement Process • Investigative Liaisons • Authorized Customer POC’s • RRR Email Distro • Risk Intel Portal • Incident Reviews / Trigger Points • Netflow / CIP Schedule • Upfront Discovery • IR Plan Gap Analysis • First Responder’s Training • Current IR Capabilities
Rapid Response RetainerAnnual SLA Pricing The SLA program components are designed to help Customer enhance their ability to respond to incidents through: 1) quick response from Verizon’s Investigative Response team; 2) built in IR policy review and IR training through Upfront Discovery; and 3) access to Verizon’s Risk Intelligence.
Rapid Response RetainerIR Hours Pricing IR hours are used during engagements for which Customer triggers the Retainer service. OPTION #1: Hours may be purchased on a T&M basis, whereby hours will be invoiced on a monthly basis, for services delivered in the month preceding. If Customer does not trigger the Retainer, hours are not billed. OPTION #2: Hours are purchased in a block, invoiced upfront. Unused hours will roll over if the SLA is renewed. Flexible Use: IR hours may be used for any RISK team services