Cyber Incident Response Guide (Personal): Difference between revisions

Monitor: added little snitch to monitoring
bullet echelons
 
(2 intermediate revisions by the same user not shown)
Line 84: Line 84:
* '''Did you receive an email or message asking for personal or financial information?'''
* '''Did you receive an email or message asking for personal or financial information?'''


** If '''YES''':
* If '''YES''':
** Do not respond or click on any links.
** Do not respond or click on any links.
** Mark the email as spam and delete it.
** Mark the email as spam and delete it.
** Proceed to [[#Secure Your Devices and Network]] if you've interacted with the message.
** Proceed to [[#Secure Your Devices and Network]] if you've interacted with the message.


** If '''NO''', remain vigilant against suspicious communications.
* If '''NO''', remain vigilant against suspicious communications.


** If you're '''UNSURE''', verify the sender's identity through another communication channel before taking action.
* If you're '''UNSURE''', verify the sender's identity through another communication channel before taking action.


'''Financial Scams'''
'''Financial Scams'''
Line 99: Line 99:
* '''Did someone request money or your banking information?'''
* '''Did someone request money or your banking information?'''


** If '''YES''':
* If '''YES''':
** Be cautious. Scammers often pressure you using fear or urgency.
** Be cautious. Scammers often pressure you using fear or urgency.
** Read about [http://www.consumerfinance.gov/ask-cfpb/what-are-some-common-types-of-scams-en-2092/ common financial scams].
** Read about [http://www.consumerfinance.gov/ask-cfpb/what-are-some-common-types-of-scams-en-2092/ common financial scams].
** Proceed to report the incident if necessary.
** Proceed to report the incident if necessary.


** If '''NO''', stay alert for unusual requests for money or information.
* If '''NO''', stay alert for unusual requests for money or information.


** If you're '''UNSURE''', consult with someone trustworthy before proceeding with any requests.
* If you're '''UNSURE''', consult with someone trustworthy before proceeding with any requests.


===== Accidents =====
===== Accidents =====
Line 114: Line 114:
* '''Has your device been lost or stolen?'''
* '''Has your device been lost or stolen?'''


** If '''YES''':
* If '''YES''':
** Change passwords for your accounts and enable two-factor authentication.
** Change passwords for your accounts and enable two-factor authentication.
** Try to locate the device using a tracking app or service.
** Try to locate the device using a tracking app or service.
** Consider remotely wiping the device to protect your data.
** Consider remotely wiping the device to protect your data.
    
    
** If '''NO''', ensure that tracking features are enabled on all devices as a precaution.
* If '''NO''', ensure that tracking features are enabled on all devices as a precaution.


** If you're '''UNSURE''', check recent locations if tracking was enabled previously.
* If you're '''UNSURE''', check recent locations if tracking was enabled previously.


* '''Did you accidentally delete important files or information?'''
* '''Did you accidentally delete important files or information?'''
Line 127: Line 127:
** If '''YES''', proceed to [[#Restore]] for data recovery steps.
** If '''YES''', proceed to [[#Restore]] for data recovery steps.


** If '''NO''', consider setting up regular backups to prevent future data loss issues.
* If '''NO''', consider setting up regular backups to prevent future data loss issues.


** If you're '''UNSURE''', check if the files are in the recycle bin or use recovery software as needed.
* If you're '''UNSURE''', check if the files are in the recycle bin or use recovery software as needed.


===== Log File Analysis =====
===== Log File Analysis =====