Thumbnail for DFIR Hierarchy of Needs
Photo by Matt Swann
field notes / artifacts · Repo

DFIR Hierarchy of Needs

I reference this non-stop when it comes to measuring and prioritizing cybersecurity efforts.

Open Repo

The first time I went to Blue Hat, Microsoft, I saw this in a presentation and have not stopped referencing it since.

The IR/DFIR Hierarchy of Needs is something that has helped me communicate how to measure effective cybersecurity and prioritize cybersecurity maturity efforts. It has made me a better consultant, and it will make you one too.

A Quick Breakdown

When it comes to my purposes of consulting, I focus on the first four levels.

  1. I tell companies that we need to start with getting an asset inventory - understanding what’s in scope, and what we need to protect.
  2. Then we focus on getting some telemetry or some visibility into those assets that we’ve identified as in-scope.
  3. If something went wrong, would we be able to detect it? How are our alerting capabilities?
  4. And then, especially as a pen tester, the problem isn’t whether or not you could detect that I did something bad. Instead, the question becomes, “Can you stop me?” - and that’s where triaging comes into play.

I strongly focus on these first four levels, and this allows me to provide organizations with a measuring stick to help identify where they are in their cybersecurity maturity and what we should work on next.