{"id":146718,"date":"2021-11-16T04:30:44","date_gmt":"2021-11-16T12:30:44","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=146718"},"modified":"2021-11-17T14:20:59","modified_gmt":"2021-11-17T22:20:59","slug":"cloud-incident-response-services","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2021\/11\/cloud-incident-response-services\/","title":{"rendered":"Don\u2019t Panic: Unit 42 Doubles Down on Cloud Incident Response Services"},"content":{"rendered":"<p>When organizations rapidly moved workloads to the cloud in response to the global health crisis, security teams struggled to stay ahead of the risk and safeguard cloud assets. This led to an explosion of security incidents. In our <a href=\"https:\/\/www.paloaltonetworks.com\/prisma\/unit42-cloud-threat-research-1h21\">Unit 42 Cloud Threat Report, 1H 2021<\/a>, we saw a 400% increase in cloud incidents in the retail industry, and an over 200% increase in manufacturing and government sectors.<\/p>\n<p>We are pleased to announce the enhancement of our Cloud Incident Response (IR) practice to provide an optimized approach for each stage of the cloud incident lifecycle, so organizations can recover faster.<\/p>\n<p>Because cloud environments are inherently designed to be dynamic and scalable, even <a href=\"https:\/\/unit42.paloaltonetworks.com\/iam-misconfigurations\/\">simple mistakes<\/a> can lead to expensive, complicated incidents with outsized impact.<\/p>\n<p>The <a href=\"https:\/\/start.paloaltonetworks.com\/asm-report\">2021 Cortex Xpanse Attack Surface Threat Report<\/a> shows that global enterprises found new serious issues in their cloud infrastructure every 12 hours \u2013 twice a day! Some common issues include misconfigurations, insecure remote access, exposed account credentials and unpatched vulnerabilities.<\/p>\n<p>And just in the past three years, Unit 42 has seen a 188% increase in cloud IR cases, with more than a third of our incident response matters touching cloud assets in one way or another.<\/p>\n<p>This highlights the ephemeral nature of today\u2019s IT infrastructure, where not only the infrastructure changes, but so does the vulnerability footprint.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Rapid Response Is Crucial for a Speedy Recovery From a Cloud Incident<\/strong><\/h2>\n<p>Time is of the essence when a cloud breach happens. You must work as quickly as possible to contain the incident, determine \u201chow it happened\u201d and identify the optimal path to respond and recover. The longer this takes, the worse the potential consequences become.<\/p>\n<p>Many Incident Response teams continue to use traditional Digital Forensics and Incident Response (DFIR) methods for their cloud environments. The challenge is, traditional DFIR was not designed for dynamic cloud-based incidents.<\/p>\n<p>And if you don't get it right and determine the root cause, the adversary will be back in your environment again in no time \u2013 or potentially never leave in the first place.<\/p>\n<p>It\u2019s easy to get stuck in a reactive state when you\u2019re running to the next fire drill.<\/p>\n<p>Now with the growing importance of and dependence on the cloud, and the growing number of cases that involve it, we are doubling down on our Cloud Incident Response capability to provide an optimized approach for each stage of the cloud incident lifecycle, so your organization can recover quickly.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Introducing a New Optimized Approach to Cloud Incident Response<\/strong><\/h2>\n<p>The <a href=\"https:\/\/www.paloaltonetworks.com\/unit42\">Unit 42<\/a> cloud incident response team is staffed with experienced cloud experts who understand the special nature of cloud security investigations. They are armed with cutting edge cloud security technology like <a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/cortex-xdr\">Cortex XDR<\/a>, <a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/cortex-xpanse\">Cortex Xpanse<\/a> and <a href=\"https:\/\/www.paloaltonetworks.com\/prisma\/cloud\">Prisma Cloud<\/a> that allows them to quickly identify attack vectors, extent of access and the data at risk, then take the appropriate remediation actions.<\/p>\n<p>In the event of a cloud incident, our teams stay involved as long as necessary to ensure it is completely contained and everything is back to normal. From there, we help develop playbooks and new processes to ensure a similar event doesn\u2019t happen again. And should you need it, we\u2019re available as an expert witness to articulate what happened, why it happened and who was impacted.<\/p>\n<p>Imagine the peace of mind of having cloud IR experts as an extension of your team on speed dial. In the event of a cloud incident, your organization won\u2019t have to manage it alone. The <a href=\"https:\/\/www.paloaltonetworks.com\/resources\/datasheets\/cybersecurity-expertise-retainer\">Unit 42 Retainer<\/a> operates under prenegotiated terms, with predefined communication channels and playbooks to get started on your investigation within hours. This avoids you having to scramble to negotiate contracts when you need to focus on responding to a breach.<\/p>\n<p>Having a retainer agreement in place with highly specialized cloud digital forensics and incident response expertise can help you <strong>reduce your incident response time<\/strong>, recover faster and resume normal business operations.<\/p>\n<p>Don\u2019t panic. We\u2019re here to help.<\/p>\n<p>&nbsp;<\/p>\n<p><em>Watch this short video of Wendi discussing Unit 42 Cloud Incident Response.<\/em><\/p>\n<div style=\"position: relative; display: block; max-width: 100%;\">\n<div style=\"padding-top: 56.25%;\"><iframe style=\"position: absolute; top: 0px; right: 0px; bottom: 0px; left: 0px; width: 100%; height: 100%;\" src=\"https:\/\/players.brightcove.net\/1050259881001\/default_default\/index.html?videoId=6282475391001\" allowfullscreen=\"allowfullscreen\" allow=\"encrypted-media\"><\/iframe><\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p><em>Learn even more about cloud incident response by watching the full version of <a href=\"https:\/\/www.ignite.paloaltonetworks.com\/panwigniteondemand\">Wendi Whitmore's Ignite '21 keynote<\/a> on demand.<\/em><\/p>\n<h3><\/h3>\n<h3><strong>Get in Touch<\/strong><\/h3>\n<p><em>Remember to ask for Unit 42 by name with your cyber insurance carriers if you need incident response services.<\/em><\/p>\n<p><em>If you are experiencing an active breach, or think you may have been impacted by a cloud security incident, please <a href=\"https:\/\/start.paloaltonetworks.com\/contact-unit42.html\">contact Unit 42<\/a><\/em><em>\u00a0to connect with a team member. The Unit 42 Incident Response team is available 24\/7\/365. You can also take preventative steps by requesting a <\/em><a href=\"https:\/\/www.paloaltonetworks.com\/unit42\/proactive-assessments\"><em>Proactive Assessment<\/em><\/a><em>. <\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cloud Incident Response Services are more vital than ever \u2013 in the past three years, we\u2019ve seen a 188% increase in cloud IR cases. <\/p>\n","protected":false},"author":663,"featured_media":146732,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[308,6717],"tags":[8155,8156,8129,6669,586],"coauthors":[7527],"class_list":["post-146718","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcement","category-products-and-services","tag-cloud-incident-response-services","tag-dfir","tag-ignite-21","tag-incident-response","tag-unit-42","sec_ops_category-must-read-articles","sec_ops_category-news-and-events"],"jetpack_featured_media_url":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2021\/11\/Collaborate-2.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/146718","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=146718"}],"version-history":[{"count":8,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/146718\/revisions"}],"predecessor-version":[{"id":329504,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/146718\/revisions\/329504"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/146732"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=146718"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=146718"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=146718"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=146718"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}