Planning for a security incident before it happens

Planning for a security incident before it happens

Membergate Support -

A security incident rarely announces itself with sirens. More often it is a member emailing to ask why they received a strange message from your site, a password reset you did not request, an unfamiliar admin account in your settings, or a laptop left on a train with a spreadsheet of member details on it. In that moment you have to make decisions quickly, under stress, often without the right information in front of you.

That is why the time to plan is now, while nothing is wrong. A written incident plan does not need to be long. For a small membership site, two or three pages is plenty. What matters is that you know who does what, what to do first, and how you will talk to members.

What counts as an incident

An incident is any event that puts member information, your site or your income at risk. Typical examples include:

  • An admin or staff account logged into by someone else.
  • Member data exposed, whether through a hack, a misconfigured export or an email sent to the wrong list.
  • Your site defaced, taken offline or infected with malicious code.
  • A lost or stolen device containing member information.
  • Fraudulent payments, card testing or a hijacked payment account.
  • Scam emails sent to members pretending to be from you.

It helps to sort incidents into rough levels. Low: contained, no member data involved, such as a spam account. Medium: a compromised staff account or a short outage, with no evidence of data exposure. High: member data exposed or payments affected. The level decides how many people you involve and whether members need to hear from you.

Decide who does what

Even a one-person business needs roles, because you will need outside help. Name who covers each of these:

  • Decision-maker: usually you. Decides what to shut down, what to tell members and when.
  • Technical help: your host, your platform’s support team, or a developer you can call.
  • Communicator: writes and sends messages to members and answers their questions.
  • Record keeper: notes what happened, when and what was done. This can be the same person, but someone must do it.

Then build a contact sheet: support details for your host, membership platform, payment processor, email service and domain registrar, plus a legal or professional adviser and your insurer if you have cover. Keep a copy offline, because your email may be one of the things affected.

The first hour: contain, preserve, assess

  1. Contain. Stop the damage spreading. Change passwords on the affected accounts, sign out all active sessions, disable any unfamiliar admin accounts, and take a feature offline if it is being abused. Access you have already locked down, as described in admin access: who should be able to do what, makes this step much smaller.
  2. Preserve. Resist the urge to wipe everything and start fresh. Take screenshots, save suspicious emails, and ask your host to keep the logs. You will need them to work out what happened.
  3. Assess. Answer three questions as best you can: what was accessed, whose information was involved, and since when.
  4. Recover. Once the cause is closed off, restore clean content from your backups if needed, and check that everything works.
  5. Record. Write down each step and the time it happened.

Telling members and anyone else who needs to know

Depending on where you and your members are, and what information was involved, you may be legally required to notify members, regulators or others within a set time. These rules vary widely, so check with a qualified professional what applies to you, ideally before you ever need it. The obligations you have for handling personal information generally, covered in data protection basics, are a useful starting point.

Whether or not a notice is legally required, members appreciate honesty. A good notice is prompt, specific and practical. Here is one you could adapt:

Subject: A security issue affecting your account

Yesterday we discovered that someone had accessed one of our staff accounts. Our investigation shows they could see member names and email addresses. They could not see passwords or payment details, which are not stored on our site. We have closed the account, changed our security settings and reviewed who has access to member information. You may receive scam emails pretending to be from us, so please be wary of any message asking you to log in or pay through a link. If you have questions, reply to this email and a real person will answer.

After it is over: learn and fix

When things are calm, hold a short review. Focus on the process, not blame. What happened, how was it discovered, what worked, what slowed you down, and what will you change? Update your plan, contact sheet and settings accordingly.

Rehearse with a simple scenario

A plan you have never used will have gaps. Once or twice a year, sit down with your team, or on your own, and talk through a scenario. For example, for a dog-training membership:

A member forwards you an email that looks like it came from your site, asking them to renew through a link to an unfamiliar address. Three more members send similar messages within the hour. Your support inbox shows that someone logged in from another country last night.

Walk through it. Who do you call first? Where are the host’s contact details? How do you sign everyone out? Who drafts the member message, and how long would it take? Every question you cannot answer is a gap to fix.

Build your plan

  1. Write a short list of what counts as an incident, with low, medium and high levels.
  2. Name the decision-maker, technical help, communicator and record keeper.
  3. Create an offline contact sheet for every service you depend on.
  4. Write the first-hour steps and your member notice template.
  5. Find out, with professional help, what notification rules apply to you.
  6. Rehearse one scenario and update the plan with what you learn.

0 Comments

Comments are reviewed before they appear.