A CISO learns that an attacker exfiltrated 500GB of sensitive data before the intrusion was detected. Which gap in the incident response program most directly contributed to this outcome?
-
A
Lack of a formal incident response policy
-
B
Insufficient data loss prevention and egress monitoring controls
-
C
Failure to conduct annual tabletop exercises
-
D
Absence of a bug bounty program