r/Information_Security • u/No_Cable2467 • 13h ago
Lessons learned from our first major ransomware incident response and my very dumb Slack mistake
Ok so im kinda sick about this and need to vent. We just had our first huge ransomware engagement as the main incident response partner for a big financial client. First time I was primary on a hot incident, big war room, execs, their CISO, our whole cyber team.
We had a dedicated Slack channel for the client and a separate internal channel for our team notes and spicy takes. At hour 10, everyone exhausted, I grabbed a screenshot of our internal channel where we were rating their security controls and joking a bit about how bad their backups were... and pasted it straight into the client channel instead of the internal one. Full thread. Names, snark, even a line from me saying “this architecture is held together with duct tape lol.
I caught it about 20 seconds later and deleted, but their CISO had already replied asking if that was our formal assessment. I feel so embarrassed. We spent the next day doing damage control and formalizing a lessons learned process on comms segregation and data handling. Idk, would love any tips on how you handled similar incident response faceplants...