Chapter 18: Building Secure and Reliable Systems
To avoid service disruptions for your users, you need to be able to quickly recover from security- and reliability-related incidents. However, there’s a key difference when you are recovering from a security incident: your attacker. A persistent attacker can leverage ongoing access to your environment or reengage at any moment, even while you’re executing a recovery. In this chapter, we take a deep dive into what people designing, implementing, and maintaining systems need to know about recovering from attacks. The people performing recovery efforts often aren’t security professionals—they’re the people who build the affected systems and operate them every day. The lessons and examples in this chapter highlight how to keep your attacker at bay while you’re recovering. We walk through the logistics, timeline, planning, and initiation of the recovery phases. We also discuss key tradeoffs, like when to disrupt an attacker’s activity versus allowing them to remain on your systems so you ca
Chapter 18: Building Secure and Reliable Systems Chapter 18 Recovery and Aftermath By Alex Perry, Gary O’Connor, and Heather Adkins with Nick Soda To avoid service disruptions for your users, you need to be able to quickly recover from security- and reliability-related incidents. However, there’s a key difference when you are recovering from a security incident: your attacker. A persistent attacker can leverage ongoing access to your environment or reengage at any moment, even while you’re executing a recovery. In this chapter, we take a deep dive into what people designing, implementing, and
related reading
- Security incident disclosure — July 2026huggingface.co
- Postmortem Culture: Learning from Failuresre.google
- On rebooting: the unreasonable effectiveness of turning computers off and on again - Keunwoo Lee's Minimum Viable Homepagekeunwoo.com
- Rebuilding Threat Detection and Incident Response at LinkedInlinkedin.com
- The Letter - Stop Hacklore!hacklore.org
- Keeping Oxford secure: what we can all do to protect the University from cyber threatsweb.archive.org
- Automated Incident Response: Streamlining Your SecOps | Prophet Securityprophet.security
- Security Principles | Computer Securitytextbook.cs161.org
- Mediumblog.palantir.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- Robust to what? - by torchbearercommunity and Luke McNallytorchbearercommunity.substack.com
- Notes/interview-study-notes-for-security-engineering.md at master · gracenolan/Notesgithub.com