Chapter 18: Building Secure and Reliable Systems
To avoid service disruptions for your users, you need to be able to quickly recover from security- and reliability-related incidents. However, there’s a key difference when you are recovering from a security incident: your attacker. A persistent attacker can leverage ongoing access to your environment or reengage at any moment, even while you’re executing a recovery. In this chapter, we take a deep dive into what people designing, implementing, and maintaining systems need to know about recovering from attacks. The people performing recovery efforts often aren’t security professionals—they’re the people who build the affected systems and operate them every day. The lessons and examples in this chapter highlight how to keep your attacker at bay while you’re recovering. We walk through the logistics, timeline, planning, and initiation of the recovery phases. We also discuss key tradeoffs, like when to disrupt an attacker’s activity versus allowing them to remain on your systems so you ca
Chapter 18: Building Secure and Reliable Systems Chapter 18 Recovery and Aftermath By Alex Perry, Gary O’Connor, and Heather Adkins with Nick Soda To avoid service disruptions for your users, you need to be able to quickly recover from security- and reliability-related incidents. However, there’s a key difference when you are recovering from a security incident: your attacker. A persistent attacker can leverage ongoing access to your environment or reengage at any moment, even while you’re executing a recovery. In this chapter, we take a deep dive into what people designing, implementing, and
Explore this link on the map →related reading
- Security incident disclosure — July 2026huggingface.co
- How Complex Systems Failhow.complexsystems.fail
- On rebooting: the unreasonable effectiveness of turning computers off and on again - Keunwoo Lee's Minimum Viable Homepagekeunwoo.com
- Rebuilding Threat Detection and Incident Response at LinkedInlinkedin.com
- Automated Incident Response: Streamlining Your SecOps | Prophet Securityprophet.security
- Security Principles | Computer Securitytextbook.cs161.org
- Mediumblog.palantir.com
- Wiz Security Graph offers root cause analysis for cloud IR | Wiz Blogwiz.io
- Shifting detection left for more effective threat detectionpushsecurity.com
- Perspectives - What’s next for business and technology innovators.paloaltonetworks.com
- The Letter - Stop Hacklore!hacklore.org
- Persistence, Tactic TA0003 - Enterprise | MITRE ATT&CK®attack.mitre.org