{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/",
        "slug": "build-an-incident-channel-you-can-trust-when-collaboration-is-compromised",
        "url": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/"
        },
        "title": "Build an incident channel you can trust when collaboration is compromised",
        "summary": "An alternate chat room is not enough when attackers can monitor normal tools or impersonate responders. Pre-provision independent communications, verify identities through trusted records, and exercise degraded-mode operations.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "An out-of-band incident communications channel remaining trusted while primary collaboration is compromised.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/posts/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised-card.webp?v=1.8.2",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/posts/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised-hero.webp?v=1.8.2",
            "social_url": "https://update.dsesecurity.com/assets/editorial/posts/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised-social.jpg?v=1.8.2",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-04T22:53:02+00:00",
        "modified_at": "2026-08-04T22:53:02+00:00",
        "reviewed_on": "2026-08-04",
        "reading_minutes": 4,
        "word_count": 700,
        "potentially_affected": "Incident response, IT operations, security operations, executives, legal, communications, identity administrators, business continuity teams, and external responders.",
        "dse_recommendation": "Establish an independently accessible incident channel, offline contact and authority records, multi-step responder verification, operating rules, and recurring failover exercises.",
        "primary_source": {
            "name": "CISA Cyber Storm IX After-Action Report",
            "url": "https://www.cisa.gov/sites/default/files/2024-10/Cyber%20Storm%20IX%20After-Action%20Report%20v00%2020241001_508.pdf",
            "published_on": "2024-10-01",
            "authority": "Cybersecurity and Infrastructure Security Agency"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: normal collaboration can become an incident dependency</h2>\r\n<p>CISA&#8217;s <a href=\"https://www.cisa.gov/stopransomware/ransomware-guide\">StopRansomware Guide</a> warns that malicious actors may monitor an organization&#8217;s communications and recommends coordinated isolation using out-of-band methods such as phone calls when necessary to avoid tipping them off. The lesson is broader than ransomware: email, chat, identity, endpoint management, directories, or network access may be unavailable, observed, or manipulated during an incident.</p>\r\n<p>The <a href=\"https://www.cisa.gov/sites/default/files/2024-10/Cyber%20Storm%20IX%20After-Action%20Report%20v00%2020241001_508.pdf\">CISA Cyber Storm IX After-Action Report</a> found that ordinary communication methods could be suboptimal during a cyber incident and identified the need for consolidated out-of-band capability and established primary and alternate methods. The Cyber Safety Review Board&#8217;s <a href=\"https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf\">review of Lapsus$</a> describes out-of-band communication as an alternative separate from the primary channel and says it is best established before an attack.</p>\r\n<h2>DSE recommendation: separate availability from identity assurance</h2>\r\n<p><strong>DSE recommendation:</strong> design two related controls. The first is an alternate communications plane that does not rely on the systems most likely to fail together. The second is a responder-verification process that establishes who is in the channel and what authority that person holds. A working alternate chat tool solves availability; it does not prove that a display name belongs to an authorized responder.</p>\r\n<h2>Pre-provision the alternate communications plane</h2>\r\n<ol>\r\n<li><strong>Map shared dependencies.</strong> Document whether the alternate service relies on the same identity provider, email inbox, phone, managed device, password vault, DNS, network, cloud tenant, administrator, or supplier as the normal service. Independence is a design claim to test, not a product label.</li>\r\n<li><strong>Create and protect access in advance.</strong> Establish accounts, strong authentication, administrators, recovery methods, license capacity, rooms, retention settings, and external-participant rules. Limit standing access while ensuring the incident commander can activate the channel without the compromised system.</li>\r\n<li><strong>Keep essential records offline or separately controlled.</strong> Maintain current contact methods, incident roles, delegation and approval authorities, supplier escalation paths, and instructions for finding the alternate service. Protect this material according to its sensitivity and test that authorized users can retrieve it.</li>\r\n<li><strong>Define activation and fallback.</strong> State who can declare normal communications untrusted, how the activation message is distributed, which channel becomes authoritative, and what to do if that channel also fails.</li>\r\n</ol>\r\n<h2>Verify people before granting incident authority</h2>\r\n<p>Current threat reporting shows why channel access is not enough. A joint FBI and CISA <a href=\"https://www.fbi.gov/file-repository/cyber-alerts/scattered-spider-072925.pdf\">advisory on Scattered Spider</a> describes actors impersonating employees or IT staff to persuade help desks to reset passwords or multifactor authentication. Incident activation is an attractive setting for the same social engineering because urgency and unfamiliar participants weaken routine checks.</p>\r\n<p>Use a trusted roster and a known contact path that the arriving person did not supply. Call a pre-recorded number, use a separately established organizational identity, or obtain confirmation from an accountable manager through another verified route. Require two authorized people to approve the addition of a participant who will receive sensitive evidence, administrative access, or decision authority. Confirm role and authority separately from personal identity. A code word shared widely or presented in the same suspicious conversation is not strong proof.</p>\r\n<h2>Operate the channel deliberately</h2>\r\n<p>Assign an incident identifier, channel owner, participant recorder, decision log, and regular roll call. Mark authoritative instructions and require recipients to acknowledge high-impact actions. Record joins, departures, role changes, approvals, and handoffs. Share the minimum necessary secrets and evidence; an alternate channel should not become an uncontrolled repository for credentials, customer data, or malware samples. Give external counsel, insurers, vendors, and law enforcement a planned route appropriate to their role.</p>\r\n<h2>Exercise failure, then retire access safely</h2>\r\n<p>Test loss or compromise of the normal identity provider, email, chat, phones, devices, and directory in different combinations. Ask responders to activate the alternate plane, authenticate one another, add an outside party, issue a verified instruction, and preserve a decision record. After an actual incident, revalidate the participant list, export required records under policy, rotate exposed credentials, remove temporary access, and decide when normal communications can again be trusted. The outcome is not merely that a message was sent; it is that an authorized decision reached the correct operator through a channel both available and trustworthy.</p>\r\n<h2>Official sources</h2>\r\n<ul>\r\n<li><a href=\"https://www.cisa.gov/stopransomware/ransomware-guide\">CISA: StopRansomware Guide</a></li>\r\n<li><a href=\"https://www.cisa.gov/sites/default/files/2024-10/Cyber%20Storm%20IX%20After-Action%20Report%20v00%2020241001_508.pdf\">CISA: Cyber Storm IX After-Action Report</a></li>\r\n<li><a href=\"https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf\">Cyber Safety Review Board: Review of the Attacks Associated with Lapsus$</a></li>\r\n<li><a href=\"https://www.fbi.gov/file-repository/cyber-alerts/scattered-spider-072925.pdf\">FBI and CISA: Scattered Spider Cybersecurity Advisory</a></li>\r\n</ul>",
        "content_text": "Source fact: normal collaboration can become an incident dependency\r\nCISA’s StopRansomware Guide warns that malicious actors may monitor an organization’s communications and recommends coordinated isolation using out-of-band methods such as phone calls when necessary to avoid tipping them off. The lesson is broader than ransomware: email, chat, identity, endpoint management, directories, or network access may be unavailable, observed, or manipulated during an incident.\r\nThe CISA Cyber Storm IX After-Action Report found that ordinary communication methods could be suboptimal during a cyber incident and identified the need for consolidated out-of-band capability and established primary and alternate methods. The Cyber Safety Review Board’s review of Lapsus$ describes out-of-band communication as an alternative separate from the primary channel and says it is best established before an attack.\r\nDSE recommendation: separate availability from identity assurance\r\nDSE recommendation: design two related controls. The first is an alternate communications plane that does not rely on the systems most likely to fail together. The second is a responder-verification process that establishes who is in the channel and what authority that person holds. A working alternate chat tool solves availability; it does not prove that a display name belongs to an authorized responder.\r\nPre-provision the alternate communications plane\r\n\r\nMap shared dependencies. Document whether the alternate service relies on the same identity provider, email inbox, phone, managed device, password vault, DNS, network, cloud tenant, administrator, or supplier as the normal service. Independence is a design claim to test, not a product label.\r\nCreate and protect access in advance. Establish accounts, strong authentication, administrators, recovery methods, license capacity, rooms, retention settings, and external-participant rules. Limit standing access while ensuring the incident commander can activate the channel without the compromised system.\r\nKeep essential records offline or separately controlled. Maintain current contact methods, incident roles, delegation and approval authorities, supplier escalation paths, and instructions for finding the alternate service. Protect this material according to its sensitivity and test that authorized users can retrieve it.\r\nDefine activation and fallback. State who can declare normal communications untrusted, how the activation message is distributed, which channel becomes authoritative, and what to do if that channel also fails.\r\n\r\nVerify people before granting incident authority\r\nCurrent threat reporting shows why channel access is not enough. A joint FBI and CISA advisory on Scattered Spider describes actors impersonating employees or IT staff to persuade help desks to reset passwords or multifactor authentication. Incident activation is an attractive setting for the same social engineering because urgency and unfamiliar participants weaken routine checks.\r\nUse a trusted roster and a known contact path that the arriving person did not supply. Call a pre-recorded number, use a separately established organizational identity, or obtain confirmation from an accountable manager through another verified route. Require two authorized people to approve the addition of a participant who will receive sensitive evidence, administrative access, or decision authority. Confirm role and authority separately from personal identity. A code word shared widely or presented in the same suspicious conversation is not strong proof.\r\nOperate the channel deliberately\r\nAssign an incident identifier, channel owner, participant recorder, decision log, and regular roll call. Mark authoritative instructions and require recipients to acknowledge high-impact actions. Record joins, departures, role changes, approvals, and handoffs. Share the minimum necessary secrets and evidence; an alternate channel should not become an uncontrolled repository for credentials, customer data, or malware samples. Give external counsel, insurers, vendors, and law enforcement a planned route appropriate to their role.\r\nExercise failure, then retire access safely\r\nTest loss or compromise of the normal identity provider, email, chat, phones, devices, and directory in different combinations. Ask responders to activate the alternate plane, authenticate one another, add an outside party, issue a verified instruction, and preserve a decision record. After an actual incident, revalidate the participant list, export required records under policy, rotate exposed credentials, remove temporary access, and decide when normal communications can again be trusted. The outcome is not merely that a message was sent; it is that an authorized decision reached the correct operator through a channel both available and trustworthy.\r\nOfficial sources\r\n\r\nCISA: StopRansomware Guide\r\nCISA: Cyber Storm IX After-Action Report\r\nCyber Safety Review Board: Review of the Attacks Associated with Lapsus$\r\nFBI and CISA: Scattered Spider Cybersecurity Advisory",
        "content_markdown": "## Source fact: normal collaboration can become an incident dependency\n\nCISA’s [StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide) warns that malicious actors may monitor an organization’s communications and recommends coordinated isolation using out-of-band methods such as phone calls when necessary to avoid tipping them off. The lesson is broader than ransomware: email, chat, identity, endpoint management, directories, or network access may be unavailable, observed, or manipulated during an incident.\n\nThe [CISA Cyber Storm IX After-Action Report](https://www.cisa.gov/sites/default/files/2024-10/Cyber%20Storm%20IX%20After-Action%20Report%20v00%2020241001_508.pdf) found that ordinary communication methods could be suboptimal during a cyber incident and identified the need for consolidated out-of-band capability and established primary and alternate methods. The Cyber Safety Review Board’s [review of Lapsus$](https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf) describes out-of-band communication as an alternative separate from the primary channel and says it is best established before an attack.\n\n## DSE recommendation: separate availability from identity assurance\n\nDSE recommendation: design two related controls. The first is an alternate communications plane that does not rely on the systems most likely to fail together. The second is a responder-verification process that establishes who is in the channel and what authority that person holds. A working alternate chat tool solves availability; it does not prove that a display name belongs to an authorized responder.\n\n## Pre-provision the alternate communications plane\n\n- Map shared dependencies. Document whether the alternate service relies on the same identity provider, email inbox, phone, managed device, password vault, DNS, network, cloud tenant, administrator, or supplier as the normal service. Independence is a design claim to test, not a product label.\n\n- Create and protect access in advance. Establish accounts, strong authentication, administrators, recovery methods, license capacity, rooms, retention settings, and external-participant rules. Limit standing access while ensuring the incident commander can activate the channel without the compromised system.\n\n- Keep essential records offline or separately controlled. Maintain current contact methods, incident roles, delegation and approval authorities, supplier escalation paths, and instructions for finding the alternate service. Protect this material according to its sensitivity and test that authorized users can retrieve it.\n\n- Define activation and fallback. State who can declare normal communications untrusted, how the activation message is distributed, which channel becomes authoritative, and what to do if that channel also fails.\n\n## Verify people before granting incident authority\n\nCurrent threat reporting shows why channel access is not enough. A joint FBI and CISA [advisory on Scattered Spider](https://www.fbi.gov/file-repository/cyber-alerts/scattered-spider-072925.pdf) describes actors impersonating employees or IT staff to persuade help desks to reset passwords or multifactor authentication. Incident activation is an attractive setting for the same social engineering because urgency and unfamiliar participants weaken routine checks.\n\nUse a trusted roster and a known contact path that the arriving person did not supply. Call a pre-recorded number, use a separately established organizational identity, or obtain confirmation from an accountable manager through another verified route. Require two authorized people to approve the addition of a participant who will receive sensitive evidence, administrative access, or decision authority. Confirm role and authority separately from personal identity. A code word shared widely or presented in the same suspicious conversation is not strong proof.\n\n## Operate the channel deliberately\n\nAssign an incident identifier, channel owner, participant recorder, decision log, and regular roll call. Mark authoritative instructions and require recipients to acknowledge high-impact actions. Record joins, departures, role changes, approvals, and handoffs. Share the minimum necessary secrets and evidence; an alternate channel should not become an uncontrolled repository for credentials, customer data, or malware samples. Give external counsel, insurers, vendors, and law enforcement a planned route appropriate to their role.\n\n## Exercise failure, then retire access safely\n\nTest loss or compromise of the normal identity provider, email, chat, phones, devices, and directory in different combinations. Ask responders to activate the alternate plane, authenticate one another, add an outside party, issue a verified instruction, and preserve a decision record. After an actual incident, revalidate the participant list, export required records under policy, rotate exposed credentials, remove temporary access, and decide when normal communications can again be trusted. The outcome is not merely that a message was sent; it is that an authorized decision reached the correct operator through a channel both available and trustworthy.\n\n## Official sources\n\n- [CISA: StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide)\n\n- [CISA: Cyber Storm IX After-Action Report](https://www.cisa.gov/sites/default/files/2024-10/Cyber%20Storm%20IX%20After-Action%20Report%20v00%2020241001_508.pdf)\n\n- [Cyber Safety Review Board: Review of the Attacks Associated with Lapsus$](https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf)\n\n- [FBI and CISA: Scattered Spider Cybersecurity Advisory](https://www.fbi.gov/file-repository/cyber-alerts/scattered-spider-072925.pdf)"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/",
                "url": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-04"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Build an incident channel you can trust when collaboration is compromised",
                        "item": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/#article",
                "identifier": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/",
                "url": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/",
                "headline": "Build an incident channel you can trust when collaboration is compromised",
                "description": "An alternate chat room is not enough when attackers can monitor normal tools or impersonate responders. Pre-provision independent communications…",
                "abstract": "An alternate chat room is not enough when attackers can monitor normal tools or impersonate responders. Pre-provision independent communications, verify identities through trusted records, and exercise degraded-mode operations.",
                "articleBody": "Source fact: normal collaboration can become an incident dependency\r\nCISA’s StopRansomware Guide warns that malicious actors may monitor an organization’s communications and recommends coordinated isolation using out-of-band methods such as phone calls when necessary to avoid tipping them off. The lesson is broader than ransomware: email, chat, identity, endpoint management, directories, or network access may be unavailable, observed, or manipulated during an incident.\r\nThe CISA Cyber Storm IX After-Action Report found that ordinary communication methods could be suboptimal during a cyber incident and identified the need for consolidated out-of-band capability and established primary and alternate methods. The Cyber Safety Review Board’s review of Lapsus$ describes out-of-band communication as an alternative separate from the primary channel and says it is best established before an attack.\r\nDSE recommendation: separate availability from identity assurance\r\nDSE recommendation: design two related controls. The first is an alternate communications plane that does not rely on the systems most likely to fail together. The second is a responder-verification process that establishes who is in the channel and what authority that person holds. A working alternate chat tool solves availability; it does not prove that a display name belongs to an authorized responder.\r\nPre-provision the alternate communications plane\r\n\r\nMap shared dependencies. Document whether the alternate service relies on the same identity provider, email inbox, phone, managed device, password vault, DNS, network, cloud tenant, administrator, or supplier as the normal service. Independence is a design claim to test, not a product label.\r\nCreate and protect access in advance. Establish accounts, strong authentication, administrators, recovery methods, license capacity, rooms, retention settings, and external-participant rules. Limit standing access while ensuring the incident commander can activate the channel without the compromised system.\r\nKeep essential records offline or separately controlled. Maintain current contact methods, incident roles, delegation and approval authorities, supplier escalation paths, and instructions for finding the alternate service. Protect this material according to its sensitivity and test that authorized users can retrieve it.\r\nDefine activation and fallback. State who can declare normal communications untrusted, how the activation message is distributed, which channel becomes authoritative, and what to do if that channel also fails.\r\n\r\nVerify people before granting incident authority\r\nCurrent threat reporting shows why channel access is not enough. A joint FBI and CISA advisory on Scattered Spider describes actors impersonating employees or IT staff to persuade help desks to reset passwords or multifactor authentication. Incident activation is an attractive setting for the same social engineering because urgency and unfamiliar participants weaken routine checks.\r\nUse a trusted roster and a known contact path that the arriving person did not supply. Call a pre-recorded number, use a separately established organizational identity, or obtain confirmation from an accountable manager through another verified route. Require two authorized people to approve the addition of a participant who will receive sensitive evidence, administrative access, or decision authority. Confirm role and authority separately from personal identity. A code word shared widely or presented in the same suspicious conversation is not strong proof.\r\nOperate the channel deliberately\r\nAssign an incident identifier, channel owner, participant recorder, decision log, and regular roll call. Mark authoritative instructions and require recipients to acknowledge high-impact actions. Record joins, departures, role changes, approvals, and handoffs. Share the minimum necessary secrets and evidence; an alternate channel should not become an uncontrolled repository for credentials, customer data, or malware samples. Give external counsel, insurers, vendors, and law enforcement a planned route appropriate to their role.\r\nExercise failure, then retire access safely\r\nTest loss or compromise of the normal identity provider, email, chat, phones, devices, and directory in different combinations. Ask responders to activate the alternate plane, authenticate one another, add an outside party, issue a verified instruction, and preserve a decision record. After an actual incident, revalidate the participant list, export required records under policy, rotate exposed credentials, remove temporary access, and decide when normal communications can again be trusted. The outcome is not merely that a message was sent; it is that an authorized decision reached the correct operator through a channel both available and trustworthy.\r\nOfficial sources\r\n\r\nCISA: StopRansomware Guide\r\nCISA: Cyber Storm IX After-Action Report\r\nCyber Safety Review Board: Review of the Attacks Associated with Lapsus$\r\nFBI and CISA: Scattered Spider Cybersecurity Advisory",
                "datePublished": "2026-08-04T22:53:02+00:00",
                "dateModified": "2026-08-04T22:53:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/posts/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised-social.jpg?v=1.8.2",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/posts/build-an-incident-channel-you-can-trust-when-collaboration-is-compromised-social.jpg?v=1.8.2",
                    "width": 1200,
                    "height": 630,
                    "caption": "Build an incident channel you can trust when collaboration is compromised"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT",
                    "Playbook",
                    "Important priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 700,
                "timeRequired": "PT4M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "CISA Cyber Storm IX After-Action Report",
                    "url": "https://www.cisa.gov/sites/default/files/2024-10/Cyber%20Storm%20IX%20After-Action%20Report%20v00%2020241001_508.pdf",
                    "datePublished": "2024-10-01"
                }
            }
        ]
    }
}