Cybersecurity

Incident Response Guide

September 24, 2026 ·9 min ·by Chitra Karanam

Incident response is the structured process an organisation follows when a breach happens. The widely used model has six phases: preparation, identification, containment, eradication, recovery and lessons learned. The phase that decides the outcome is preparation, done before anything goes wrong, because you cannot improvise a good response mid crisis.

Why a process matters

During an active breach, people panic and make things worse: they tip off the attacker, destroy evidence, or restore from an infected backup. A defined process removes improvisation from the worst possible moment. That is the entire point of incident response.

The six phases

PhaseGoal
PreparationHave the plan, tools and access ready before anything happens
IdentificationConfirm this is a real incident and its scope
ContainmentStop it spreading without destroying evidence
EradicationRemove the attacker and the foothold
RecoveryRestore to normal, verified clean
Lessons learnedFix what let it happen

The first hour

What you do first shapes everything after. In order: confirm it is real, avoid tipping off the attacker, preserve evidence before changing anything, and decide containment. The ransomware specific version of this is worth its own read.

Containment is a decision, not a reflex

The instinct is to pull the plug immediately. But abrupt containment can destroy forensic evidence and tip off an attacker who then burns their access faster. Containment balances stopping the spread against preserving what you need to understand the breach. This is the judgement that separates senior responders.

Preserve evidence

Before you change anything, capture it: memory, logs, disk images where relevant. Once you start cleaning, the evidence is gone. This is where incident response overlaps with digital forensics.

Building a playbook

A playbook is a pre written response for a specific scenario: ransomware, account compromise, data exfiltration. It removes decisions from the crisis. A good playbook names who does what, in what order, with what authority. Write them in calm, use them in chaos.

Lessons learned, the phase everyone skips

After recovery, the temptation is to move on. The teams that improve run a blameless review: what let this happen, what detection missed it, what would have caught it sooner. That review feeds new detections back to the SOC. Skip it and the same incident recurs.

The core truth: incident response is won or lost in preparation. The plan, the access, the playbooks and the backups all have to exist before the incident, because you cannot build them during one.

Practise this

Run a tabletop exercise: walk through a scenario step by step and find where your process breaks. It costs nothing and reveals the gaps. Structured path in the SOC analyst syllabus.

Enroll in SOC

Live instructor led training with hands on labs and a verifiable certificate. Or start free on Hacklido.

Enroll in SOC