An urgent warning called for Kiteworks users to shut down their servers in response to a reported credible threat of a coordinated cyberattack. Kiteworks is used for secure file sharing, transfers, and movement of sensitive data.
Taking a production server offline is a serious operational action, but so is leaving potentially exposed infrastructure running during an active threat. The discussion highlights the tension security teams face during a Sev 1 incident: move immediately, while still maintaining authorization and change control.
When an urgent vendor warning calls for shutdown, how much process should remain before security teams pull the plug?