コンテンツに移動
Shared - Banner with Media - Background

Incident response

We realize that security incidents are inevitable, so properly preparing for such incidents is a big part of what makes for good security. Powered by SophosLabs — a global threat intelligence and data science team — Sophos’ cloud-native and AI-powered solutions secures the company against cyberattacks.

Sophos is one of the 600,000 organizations protected by Sophos products. Our plans focus on how we communicate securely and reliably during an incident, what roles we need to respond effectively, how we will respond to various types of incidents, analyzing severity levels, and notifying customers and regulatory bodies as appropriate.

We have developed our plans with guidance from the NIST 800-61 Computer Security Incident Handling Guide and we frequently review these plans for compliance with industry standards.

Our highly skilled cybersecurity professionals develop and operate world-class incident response capabilities, including comprehensive monitoring, advanced detections, response automation, incident management, forensic analysis, and access to external experts. We believe that by being the first and most frequent users of Sophos products, coupled with our access to the product teams and SophosLabs, we are in a uniquely effective position to respond to cybersecurity incidents.

Overview of our incident response program

Our mission at Sophos is to protect people from cybercrime by developing powerful and intuitive products and services that provide the world’s most effective cybersecurity for organizations of any size. Effectively responding to a broad range of potential security incidents is critical to the success of the Sophos mission. Simply put: To protect our customers, our incident response program needs to protect our products and our company.

Sophos uses the NIST 800-61 definition of a security incident: “a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.” This is an intentionally broad definition so that we can optimize for rapid response time, identifying areas for improvement and customer transparency. This definition also supports identifying any data leaks, which might not be included in a definition focused on confirmed attacks.

How we identify incidents

There are many ways Sophos identifies or becomes aware of security incidents. These include:

  • Security monitoring capabilities, often in our products, or complimentary methods we have developed.
  • Bug bounty reports.
  • Penetration test findings.
  • Vulnerability analysis.
  • Code and application analysis.
  • Research and threat intelligence analysis.
  • Customer notifications.

To report a potential security incident, please see our Responsible Disclosure Program.

Investigation and analysis

Following the detection or verified report of an incident, we initially leverage established communications channels to facilitate information-sharing among the incident response team.

A standard minimum agenda for an incident response investigation and analysis meeting is as follows:

  • Establish current facts.
  • Update on action status.
  • Agree on next actions.
  • Confirm assessment of the incident severity status: Sev1/2/3.
  • Agree on the timing of the next meeting.
  • Document minutes on the incident timeline, including actions and decisions.

Severity assessment

We have four incident severity levels.

Incident Severity Levels

SeverityDescription
0Critical incident with maximum impact.
1Very serious incident with very high impact.
2Major incident with significant impact.
3Minor incident with low impact.