Saltar al contenido
03 · SOC Gestionado03 · Managed SOC

Recuperación y Reconstrucción Post-IncidentePost-Incident Recovery and Rebuild

Reconstrucción limpia del entorno tras un incidente mayor.Clean rebuild of the environment following a major incident.

Rebuild seguroSecure rebuild 3.2 · Gestión de Incidentes3.2 · Incident Management

¿Qué es este servicio?What is this service?

Es la reconstrucción del entorno después de un incidente mayor: levantar los sistemas críticos en un orden definido, reconstruir desde base limpia lo que estuvo comprometido, rotar todas las credenciales y validar que el atacante no dejó una puerta abierta antes de reconectar.

Rebuilding the environment after a major incident: bringing critical systems back in a defined order, rebuilding from a clean base whatever was compromised, rotating every credential and validating that the attacker left no door open before reconnecting.

¿Para qué se usa?What is it used for?

Sirve para no volver a caer en dos semanas. El error clásico es restaurar rápido sobre la misma infraestructura sin haber cerrado la puerta de entrada ni haber rotado las credenciales que el atacante ya tiene: el resultado es un segundo cifrado, esta vez con la organización agotada y sin respaldos limpios. Si el controlador de dominio cayó, no se limpia. Se reconstruye.

It stops the organisation falling over again a fortnight later. The classic mistake is restoring fast onto the same infrastructure without having closed the entry point or rotated the credentials the attacker already holds: the result is a second encryption, this time with the organisation exhausted and no clean backups left. If the domain controller fell, it does not get cleaned. It gets rebuilt.

Qué beneficios traeBenefits it delivers

  • Reduce el riesgo de reinfección, que es alto cuando la recuperación se hace con prisa y sin erradicación previa.
  • Prioriza el orden de restauración por impacto de negocio y no por facilidad técnica, que es como se restaura mal.
  • Aprovecha la ventana para cerrar deuda técnica: segmentación, autenticación reforzada, mínimo privilegio.
  • Deja un entorno documentado y con línea base conocida, cosa que muchas organizaciones nunca habían tenido.
  • Reduces reinfection risk, which is high when recovery is rushed with no prior eradication.
  • Prioritises restoration order by business impact rather than by technical convenience, which is how recovery goes wrong.
  • Uses the window to clear technical debt: segmentation, stronger authentication, least privilege.
  • Leaves a documented environment with a known baseline, something many organisations never had.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal específica en Costa Rica.
  • El Acuerdo CONASSIF 5-24 espera de las entidades supervisadas capacidades de continuidad y recuperación de los servicios tecnológicos críticos.
  • La reconstrucción es lo que da sustento al reporte histórico de seguridad que pide la clase de datos 56 del perfil tecnológico.
  • There is no specific legal obligation in Costa Rica.
  • CONASSIF Agreement 5-24 expects supervised entities to hold continuity and recovery capabilities for critical technology services.
  • The rebuild is what substantiates the historical security report required by data class 56 of the technology profile.

InternacionalInternational

  • PCI-DSS exige que el plan de respuesta cubra la recuperación y la continuidad del negocio.
  • ISO 22301 exige planes de recuperación con objetivos de tiempo definidos y probados.
  • DORA exige políticas de continuidad y planes de recuperación de TIC con pruebas periódicas.
  • PCI-DSS requires the response plan to cover recovery and business continuity.
  • ISO 22301 requires recovery plans with defined, tested time objectives.
  • DORA requires continuity policies and ICT recovery plans with periodic testing.

Requisitos mínimosMinimum requirements

  • Haber cerrado la causa raíz antes de reconectar. Restaurar sin erradicar es repetir el incidente con calendario.
  • Respaldos verificados como limpios: hay que comprobar que la copia elegida es anterior al compromiso, no solo anterior al cifrado.
  • Un entorno de recuperación aislado del comprometido, con red separada mientras se valida.
  • Rotación completa de credenciales, incluidas cuentas de servicio y claves de aplicaciones, que es la parte que casi siempre se olvida.
  • The root cause closed before reconnecting. Restoring without eradicating is repeating the incident on a schedule.
  • Backups verified as clean: the chosen copy has to be confirmed as predating the compromise, not merely the encryption.
  • A recovery environment isolated from the compromised one, on a separate network while validation runs.
  • Full credential rotation, service accounts and application keys included, which is the part almost always forgotten.

Plazo típico de entregaTypical delivery time

2 a 12 semanas 2 to 12 weeks rango habitual del mercado usual market range

El rango habitual va de dos a doce semanas y es el más variable de todos. Con respaldos limpios, probados y un entorno acotado, se resuelve en dos o tres semanas. Cuando cayó el directorio activo completo y hay que reconstruir la identidad desde cero, o cuando los respaldos también estaban cifrados, se va a tres meses sin dificultad.

The usual range runs from two to twelve weeks and is the most variable of all. With clean, tested backups and a contained environment, it resolves in two or three weeks. Where the entire directory fell and identity has to be rebuilt from scratch, or where the backups were encrypted too, three months is easily reached.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

RebuildRebuild
Reconstruir el sistema desde cero en vez de limpiarlo. Es la única forma segura si hubo acceso de administrador. Rebuilding the system from scratch instead of cleaning it. The only safe option where administrator access occurred.
RTORTO
Objetivo de tiempo de recuperación: cuánto puede estar caído un servicio antes de que duela de verdad. Recovery time objective: how long a service can stay down before it genuinely hurts.
RPORPO
Objetivo de punto de recuperación: cuánta información se acepta perder, medida en tiempo hacia atrás. Recovery point objective: how much data is acceptable to lose, measured backwards in time.
Línea baseBaseline
La configuración segura y conocida sobre la que se reconstruyen los sistemas. The known, secure configuration systems are rebuilt upon.
Rotación de credencialesCredential rotation
Cambiar todas las contraseñas y claves que el atacante pudo haber visto, no solo las obvias. Changing every password and key the attacker could have seen, not only the obvious ones.