the companies must have previously defined how to act in the face of a cyber crisis, especially in terms of decision-making, team coordination and legal and contractual obligations. This is one of the issues that were addressed this week in a session ofActinn&Talksthe knowledge dissemination space of the Andorran technology and innovation cluster.
The conference, titled When the attack has already taken placehas analyzed the management of a cybercrisis from a strategic point of view. The session was conducted by the director of ACTINN, Nacho Martinand has had the intervention of Yobany Barbosa, head of cyber security at Var Group Andorra.
Barbosa has focused on the decisions that management teams must make during a cybercrisisa scenario that is characterized by pressure, short reaction time and the possibility of not initially having all the necessary information. In this context, he pointed out the importance of organizations establishing before any incident who must take the decisions and which actions correspond depending on the type of incident.
The session also discussed the composition of the crisis tables, the legal and contractual obligations and the different phases involved in the management of an incident, from its identification to the closure of the crisis and the recovery of operational capacity. Among the measures proposed during the conference is the realization of cybercrisis simulation exercises, such as tabletop or table formats. These types of exercises make it possible to test the response capacity of organizations before a real incident occurs.
The day concluded with the need for companies to havea response framework defined in advancewhich establishes the criteria for making decisions, the obligations to be fulfilled and the coordination of the different teams during a crisis situation.
















