Incident Response
What is Incident Response?
Incident ResponseThe organised process of preparing for, detecting, analysing, containing, eradicating, and recovering from cyber security incidents, then capturing lessons learned.
Incident response (IR) is the structured handling of events that compromise — or threaten to compromise — the confidentiality, integrity or availability of information assets.
Frameworks. NIST SP 800-61 Rev. 2 defined a four-phase lifecycle: Preparation; Detection & Analysis; Containment, Eradication & Recovery; and Post-Incident Activity. In April 2025 NIST released Rev. 3, which drops the rigid phase model and instead maps IR activity onto the six CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover). The SANS PICERL model breaks the work into six named steps — Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned — and remains popular for training and runbooks.
Timelines matter. Regulation increasingly fixes hard clocks: the SEC requires U.S. public companies to disclose material cyber incidents within four business days, the EU's GDPR mandates notifying a supervisory authority within 72 hours of becoming aware of a personal-data breach, and PCI DSS requires an immediately invocable response plan. Missing these windows creates legal exposure independent of the technical damage.
Practice. Effective IR depends on tested playbooks, on-call rotations, out-of-band communication trees (attackers often watch corporate email), early legal and PR engagement, evidence preservation for later forensics, and tooling such as SIEM, SOAR, EDR/XDR, and triage suites. The final phase feeds concrete improvements back into detection and prevention so the same intrusion cannot recur.
flowchart LR A[Preparation: playbooks, tooling, drills] --> B[Detection & Analysis: triage alerts, scope] B --> C[Containment: isolate hosts, revoke tokens] C --> D[Eradication: remove malware, close vector] D --> E[Recovery: restore, monitor for reinfection] E --> F[Post-Incident: lessons learned] F --> A
● Examples
- 01
Containing a confirmed business email compromise by revoking tokens, resetting credentials, and notifying impacted parties.
- 02
Coordinating eradication and recovery of a ransomware-infected ERP system across IT, legal, and executive teams.
● Frequently asked questions
What is Incident Response?
The organised process of preparing for, detecting, analysing, containing, eradicating, and recovering from cyber security incidents, then capturing lessons learned. It belongs to the Forensics & IR category of cybersecurity.
What does Incident Response mean?
The organised process of preparing for, detecting, analysing, containing, eradicating, and recovering from cyber security incidents, then capturing lessons learned.
How do you defend against Incident Response?
Defences for Incident Response typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for Incident Response?
Common alternative names include: IR, Cyber incident response.