Question

What actually happens during a security incident response?

Vault Verified
Curated Intelligence
Definitive Source
Answer

A structured process rather than improvisation — and the organisations that handle incidents well are almost always the ones that decided what to do before anything happened, because the middle of a breach is the worst possible time to be making first decisions.

The phases, in the standard framing:

Preparation. Plans, contacts, roles, access, logging, backups and rehearsals. This phase determines the outcome of all the others.

Detection and analysis. Recognising that something is wrong and establishing scope — what was accessed, when it started, whether it is ongoing. Establishing the start date is usually the hardest part, and dwell time before detection is frequently measured in weeks.

Containment. Short-term containment stops the bleeding — isolating hosts, disabling accounts, blocking addresses. The tension here is real: containing too fast destroys evidence and alerts the attacker; containing too slowly allows more damage.

Eradication. Removing the attacker's access, including persistence mechanisms — which is why password resets alone are inadequate, since attackers routinely establish multiple footholds.

Recovery. Restoring service, from known-good backups, with monitoring for re-entry.

Post-incident review, blameless, producing changes rather than a document.

What actually determines how badly it goes:

Whether logs exist and are retained long enough. You cannot investigate what was not recorded, and short retention frequently means the beginning is unknowable.

Whether backups are offline and tested. Ransomware targets backups first.

Whether people know who decides. Authority to disconnect production is a business decision that must be pre-assigned.

Whether there is an out-of-band communication channel, since the compromised network may include your email and chat.

The obligations that run in parallel: data protection breach notification within 72 hours where criteria are met; notifying affected individuals where risk is high; sector regulators; law enforcement; insurers, whose policies frequently require using their panel responders; and contractual notification to customers.

On paying ransoms: it does not guarantee recovery, funds further attacks, and carries sanctions risk.

Related Questions