---
title: Tips For Setting Up A Cybersecure Response Plan
description: Tips For Setting Up A Cybersecure Response Plan
---

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/head-logo-2.svg "TowerWall")](https://towerwall.com/)

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/towerwall-logo-white-test.svg "TowerWall")](https://towerwall.com/)

- [Our Partners](https://towerwall.com/how-we-protect-you/our-technology-partners/)
- Our Solutions 
    - - Our Cybersecurity Solutions 
                  - We operationalize infosec,  
                     building security solutions that  
                     safeguard your most critical assets.
          - - [Solutions Overview](https://towerwall.com/cybersecurity-solutions/)
                  - [Risk Assessments & Security Reviews](https://towerwall.com/cybersecurity-solutions/risk-assessments-security-reviews/)
                  - [Program & Policy Development](https://towerwall.com/cybersecurity-solutions/program-policy-development/)
                  - [Incident Response & Remediation](https://towerwall.com/cybersecurity-solutions/incident-response-remediation/)
                  - [Managed Detection & Response](https://towerwall.com/cybersecurity-solutions/managed-detection-response/)
          - - [Compliance & Privacy](https://towerwall.com/cybersecurity-solutions/compliance-privacy/)
                  - [Comprehensive Security Training](https://towerwall.com/cybersecurity-solutions/comprehensive-security-training/)
                  - [Vulnerability Protection](https://towerwall.com/cybersecurity-solutions/vulnerability-protection/)
                  - [Penetration Testing](https://towerwall.com/cybersecurity-solutions/penetration-testing/)
- Virtual Security Officers 
    - - Virtual Security Officer 
                  - Leverage the experience and  
                     security acumen of Towerwall’s  
                     on-demand security experts.
          - - [Virtual Chief Information Security Officer (VCISO)](https://towerwall.com/virtual-security-officers/virtual-chief-information-security-officer-vciso/)
                  - [Virtual Data Protection Officer (vDPO)](https://towerwall.com/virtual-security-officers/virtual-data-protection-officer-vdpo/)
                  - [Virtual Chief Privacy Officer (vCPO)](https://towerwall.com/virtual-security-officers/virtual-chief-privacy-officer-vcpo/)
- We Advise 
    - - We Advise 
                  - One-size security solutions only  
                     lead to failure.
          - Industries 
                  - [Higher Education](https://towerwall.com/industries/higher-education/)
                  - [Financial Services & Banking](https://towerwall.com/industries/financial-services-banking/)
                  - [Healthcare](https://towerwall.com/industries/healthcare/)
                  - [BioPharma & Bio-Therapeutics](https://towerwall.com/industries/biopharma-bio-therapeutics/)
                  - [Retail](https://towerwall.com/industries/retail/)
                  - [Government](https://towerwall.com/industries/government/)
                  - [Catholic Diocese](https://towerwall.com/industries/catholic-diocese-cybersecurity/)
                  - [Cannabis](https://towerwall.com/industries/cannabis/)
                  - [Small Business](https://towerwall.com/industries/small-business/)
                  - [Enterprise](https://towerwall.com/industries/enterprise/)
          - Trends & Threats 
                  - [Remote Workforce](https://towerwall.com/trends-threats/remote-workforce/)
                  - [Vendor Questionnaire](https://towerwall.com/trends-threats/vendor-questionnaire/)
                  - [HIPAA](https://towerwall.com/trends-threats/hipaa/)
                  - [Ransomware](https://towerwall.com/trends-threats/ransomware/)
                  - [GDPR](https://towerwall.com/trends-threats/gdpr/)
                  - [Cloud Security](https://towerwall.com/trends-threats/cloud-security/)
                  - [Phishing](https://towerwall.com/trends-threats/phishing/)
                  - [Cybersecurity Insurance](https://towerwall.com/trends-threats/cybersecurity-insurance/)
- [Resources](https://towerwall.com/resources/) 
    - - Resources 
                  - Our latest insights, events,  
                     and tools to keep you safe.
          - - [Insights](https://towerwall.com/resources/?resources_category=MTU%3D&focusarea=0&industries=0&search=)
                  - [Webinars](https://towerwall.com/resources/?resources_category=MTg%3D&focusarea=0&industries=0&search=)
                  - [Whitepapers](https://towerwall.com/resources/?resources_category=MTY%3D&focusarea=0&industries=0&search=)
                  - [View All](https://towerwall.com/resources/)
- [Company](https://towerwall.com/company/) 
    - - Our Company 
                  - We are the industry’s leading cybersecurity preparedness partner.
          - - [Who We Are](https://towerwall.com/company/)
                  - [Our Team](https://towerwall.com/company/our-team/)
                  - [Our Approach](https://towerwall.com/our-approach/)
                  - [Our Values](https://towerwall.com/company/our-values/)
          - - [Awards & Recognition](https://towerwall.com/company/awards-recognition/)
                  - [Certifications & Affiliations](https://towerwall.com/company/certifications-affiliations/)
                  - [Community Involvement](https://towerwall.com/company/community-involvement/)
                  - [Careers](https://towerwall.com/company/careers/)
                  - [Contact Us](https://towerwall.com/company/contact-us/)

Topics  Phishing, GDPR, Coronavirus, malware, ransomware, HIPAA, Compliance, COVID-19, cannabis, Enterprise

# Tips For Setting Up A Cybersecure Response Plan

[By Michelle Drolet](https://blog.towerwall.com/author/towerwall2020)

[Read More](https://blog.towerwall.com/author/towerwall2020)

 3 Minute Read

April 01, 2020

As the novel coronavirus (which causes COVID-19) continues to spread around the world, businesses must do what they can to prepare for absent staff and possible periods of enforced closure.  
 In general, it’s vital that companies of all sizes and types draft a distinct crisis response plan because existing disaster recovery plans or business continuity plans might not suffice.  
 The Centers for Disease Control (CDC) offers [various resources](https://www.cdc.gov/flu/pandemic-resources/archived/business-planning.html) to help businesses and employers plan responses to a pandemic of any kind, and the World Health Organization (WHO) publishes [daily situation reports](https://www.who.int/emergencies/diseases/novel-coronavirus-2019/situation-reports) on the novel coronavirus detailing its global impact by nation.  
 However, crafting an effective strategy when it comes to crisis response means also thinking about IT infrastructure, secure remote working and clear communication to ensure everyone is kept abreast of the latest developments. Staff must be trained, and the groundwork must be laid quickly to ensure the best chance of mitigating the impact.  
 As a veteran of IT consultancy with more than two decades of experience advising companies on effective cybersecurity strategies and how to assess different technologies, I know how important it is to create a thorough plan. Here are some practical tips on drawing up your own crisis response plan.

### 1. Establish leadership.

The first thing you need to do is to pick a small team to be responsible for crafting your plan and keeping it up to date.  
 You’ll want department heads to be involved alongside representatives from each corner of your business, from HR to finance. Technical questions are sure to arise, so be sure to include IT and other technical experts.  
 Leadership should consult with all key stakeholders in the business and work closely with information security professionals to develop policies that minimize disruption but ensure data security is maintained and regulatory requirements are observed.  
 Depending on the nature of your business, leaders may also need to consult contractors and other third-parties essential to the smooth running of your company. Make the provision for alternates in case leaders fall ill or are otherwise unable to carry out their roles.

### 2. Plan for every eventuality.

When drawing up policies to cope with a crisis and the different levels of response that may be required, planners should consider how to keep critical company functions going. What’s considered critical may differ from business to business, but some questions are universal:

- How will people get paid?
- Where will people work?
- How will people complete their tasks?

It’s important to work out contingencies for different scenarios. If people are going to be absent for long periods and unable to work, will the government assist with paid sick leave? If people are at home but able to work, they’ll need the right equipment and secure access via a virtual private network (VPN) or zero trust remote access. With workspaces and applications moving to the cloud, desktop virtualization (VDI) is poised to become a strategic initiative in the workspace.  
 Make provisions to protect employees who must come into work for critical tasks, and work out what you can afford to discontinue. Ensure endpoint licenses cover employees both as on-site and remote workers (i.e., endpoint security, encryption, filtering, etc.).  
 Communication channels are paramount here, so establish a system to disseminate the latest information. A central webpage with the latest news, regular emails and text messages, and a clear list of contacts is a solid foundation, but you may also want to consider a crisis management mobile app that has gone through rigorous vulnerability testing. For customer-facing businesses, social media channels are a good way to keep customers informed.

### 3. Train and assess employees.

Understanding key personnel for every business-critical function and ensuring their usual responsibilities can be taken on by replacements is very important. This may require significant training and documentation.  
 Having a clear plan with step-by-step instructions they can refer to in different situations is a great way to reduce stress for your employees. It’s also vital to maintain your usual cybersecurity hygiene. Remind your employees that everyone is part of the cybersecurity team and that no one is immune to attacks (e.g., vishing, phishing and possibly smishing).  
 You’ll need to make time to allow employees to train up for role cover and to familiarize themselves with the procedures should the worst happen. While it’s not practical to ensure they are versed in the details of every plan, they must be clear on where to turn for instructions and real-time information.

### 4. Work remotely.

Thankfully, it’s relatively easy nowadays to facilitate telecommuting for many roles. Consider how to secure remote workers with VPN services or [zero trust](https://www.forbes.com/sites/forbestechcouncil/2020/01/31/why-zero-trust-should-be-the-top-security-initiative-for-2020/#41dd1bb21c1a) remote access. Plan for the increased demand on bandwidth, and make sure employees have the hardware they need at home in terms of laptops, desktops and the necessary software. Switch to video conferencing for meetings whenever possible, and make sure you have tools for easy document sharing and communication online.  
 In setting up remote working capability where possible, you should also identify the tasks that cannot be completed remotely and prioritize them so that whatever staff is available on-site can focus on the most important things.

### 5. Test and enforce rules.

No plan is truly trustworthy until you test it. Create exercises suitable for testing out your processes, and identify any problem areas that require further thought. Build in a regular review process so that your plan is continually updated to account for changes in personnel and business systems. It may also be necessary to create a process for assessing and allowing exceptions to your plan in certain circumstances.  
 Crises are inevitable, so planning for the worst is a sensible precaution to take to reduce the potential negative impact on your business.

[This article was originally posted on Forbes.com. Click here to read more >](https://www.forbes.com/sites/forbestechcouncil/2020/04/01/tips-for-setting-up-a-cybersecure-response-plan/#7b4214643b5d)

#### Tips For Setting Up A Cybersecure Response Plan

Back to Top

×

## Talk with us now about:

#### Your security needs.

- ![Phone](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/phone-icon.svg "Phone")
  
  [Call 774.204.0700](tel:774.204.0700)
- ![Mail](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/mail-icon.svg "Mail")
  
  [Email Us](mailto:info@towerwall.com)

### The front line of cybersecurity.™

For over 23 years, Towerwall, a woman-owned business, has helped scores of companies safeguard their data and leverage their investment in IT with advanced information security technology solutions and services. Our experience in all facets of information security coupled with serving in the CIO/CISO/ISO roles provides a unique first-hand understanding of the security challenges organizations face daily.

### Connect

- <https://blog.towerwall.com/info@towerwall.com>
- <https://www.linkedin.com/company/towerwall-inc.?trk=pro_other_cmpy>
- <https://twitter.com/Towerwall>
- <https://www.facebook.com/Towerwall>

- [Career Opportunities](https://towerwall.com/company/careers/)
- [Contact Us](https://towerwall.com/company/contact-us/)

© Towerwall, Inc. and its licensees. All rights reserved [Privacy Policy](http://towerwall.com/privacy-policy/) Sitemap [Created by Howbridge](https://meethowbridge.com/)

[![Towerwall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/footer-logo.svg "Towerwall")](https://towerwall.com/)