Incident Response
A planned process of identifying, containing, eradicating, and recovering from cyber incidents.
Term
description · examples · notesA planned process of identifying, containing, eradicating, and recovering from cyber incidents.
Description
Defined by an IR plan with roles, communication chains, and procedures.
Covers phases: preparation, identification, containment, eradication, recovery, lessons learned.
Tabletop exercises test team readiness before an actual incident.
Regulatory requirements (GDPR, NIS2) mandate having an IR plan.
What people often say
- An IR plan that is not tested is just a document — regular exercises are mandatory.
- Incident response is not just an IT task — it involves legal, PR, and management.
Covers / does not cover
Covers
- Coordinated incident response
- Communication procedures (internal and external)
- Post-incident analysis and improvements
Does not cover
- Attack prevention (other controls do that)
- Automated detection (that is SIEM/EDR)
- In-depth digital forensics (that is a separate discipline)
Mentioned in the news
Threats
reduces 7Threats it reduces. Select one to open its page.
Techniques
neutralizes 4Techniques it neutralizes. Select one to open its page.