22/02/2024
Cybersecurity Advisory:
Actions to be Taken when the PNP Information System is compromised: stay calm and follow these steps:
1. Isolate the compromised system from the network to prevent further unauthorized access and limit the attacker's lateral movement.
2. The Data Breach Response Team (DBRT) shall notify the Compliance to Privacy Officer (CPO) within 24 hours.
3. Monitor and disable any rogue connections, unauthorized accounts, and unusual ports.
4. Shutdown access points: Disable compromised accounts, change passwords, and revoke access credentials related to the affected system.
5. Preserve all relevant evidence related to the incident, including timestamps, and logs, for forensic analysis.
6. Notify the Data Protection Officer (DPO) within 48 hours by CPO.
7. Plan and implement security improvements based on the investigation findings.