Incident response (IR) is the organized approach to addressing and managing the aftermath of a cybersecurity incident, with the goals of limiting damage, reducing recovery time and costs, and learning from the event to prevent future occurrences.
Incident Response Phases (NIST Framework)
1. Preparation
Establishing incident response plans, playbooks, communication protocols, tools, and team training before incidents occur.
2. Detection & Analysis
Identifying and validating security incidents through alert triage, log analysis, and forensic investigation to determine scope and impact.
3. Containment, Eradication & Recovery
- Containment: Isolating affected systems to prevent lateral movement and data loss
- Eradication: Removing the threat actor's presence from the environment
- Recovery: Restoring systems to normal operations and verifying they are clean
4. Post-Incident Activity
Conducting lessons-learned reviews, updating detection rules, improving playbooks, and documenting findings for future reference.
Incident Severity Levels
| Level | Description | Response Time |
|---|---|---|
| Critical | Active data breach, ransomware, critical system compromise | Immediate |
| High | Confirmed compromise, active lateral movement | < 1 hour |
| Medium | Suspicious activity requiring investigation | < 4 hours |
| Low | Minor policy violations, failed attack attempts | < 24 hours |
Key IR Capabilities
- Forensic Tools: Disk imaging, memory analysis, log analysis
- Communication Plans: Internal escalation, executive notification, legal/regulatory requirements
- Playbooks: Step-by-step procedures for common incident types (phishing, ransomware, data exfiltration)
- Coordination: Integration with legal, PR, management, and law enforcement
Building IR Readiness
- Develop and document incident response plans and playbooks
- Build a skilled IR team (internal or retainer-based)
- Conduct regular tabletop and live exercises
- Ensure forensic tooling and access are ready before incidents
- Establish relationships with legal counsel and law enforcement
Related Terms
- SOC
- Digital Forensics
- Threat Hunting