SANS Incident Response Survey
How quickly are we detecting, responding to and resolving incidents?As you read, we challenge you to examine the issues presented and determine whether your organization shares the same concerns.
Report Snap Shot
This year’s survey shows crucial improvement in incident response (IR). We love some of this year’s increases:
- Containment and remediation—two of the most important phases of incident response—saw shorter times.
- Incidents were detected internally at a much higher ratio.
- False positives declined, which we hope means organizations have gotten better at classifying their incidents