Star 0

Abstract

Many customers we work with have a hard time understanding how large (or small) their Incident Response team should be. Which functions should be included? Do the resources need to be dedicated or can they be loaned from another team within InfoSec or across IT? Let's explore some common approaches together and discuss the pros and cons of a few typical approaches to staffing the IR function.