The intrusion was first identified as a major incident at 07:35 on 28 October 2023 when a member of the Technology Team was unable to access the Library’s network. Initial escalation and investigation of the incident within the Technology Team as per the Technology Major Incident Management Plan confirmed the likelihood that the incident was the result of a cyber-attack; and at 09:15 the Library’s Crisis Management Plan was invoked by the Business Continuity Manager. Great that they had a process in place! Not everywhere has proper Business Continuity procedures. Although, it turns out they were on unsteady footing.
I'll also note that this "initial detection" was when users tried to log in in the morning. Forensics may later find that there were ignored security alerts to indicate an issue, but so far, no detective capacity in sight.
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Taggart :donor: (mttaggart@infosec.town)'s status on Saturday, 09-Mar-2024 18:53:06 JSTTaggart :donor: