Incident Response Guide
Incident response is the structured process an organisation follows when a breach happens. The widely used model has six phases: preparation, identification, containment, eradication, recovery and lessons learned. The phase that decides the outcome is preparation, done before anything goes wrong, because you cannot improvise a good response mid crisis.
Why a process matters
During an active breach, people panic and make things worse: they tip off the attacker, destroy evidence, or restore from an infected backup. A defined process removes improvisation from the worst possible moment. That is the entire point of incident response.
The six phases
| Phase | Goal |
|---|---|
| Preparation | Have the plan, tools and access ready before anything happens |
| Identification | Confirm this is a real incident and its scope |
| Containment | Stop it spreading without destroying evidence |
| Eradication | Remove the attacker and the foothold |
| Recovery | Restore to normal, verified clean |
| Lessons learned | Fix what let it happen |
The first hour
What you do first shapes everything after. In order: confirm it is real, avoid tipping off the attacker, preserve evidence before changing anything, and decide containment. The ransomware specific version of this is worth its own read.
Containment is a decision, not a reflex
The instinct is to pull the plug immediately. But abrupt containment can destroy forensic evidence and tip off an attacker who then burns their access faster. Containment balances stopping the spread against preserving what you need to understand the breach. This is the judgement that separates senior responders.
Preserve evidence
Before you change anything, capture it: memory, logs, disk images where relevant. Once you start cleaning, the evidence is gone. This is where incident response overlaps with digital forensics.
Building a playbook
A playbook is a pre written response for a specific scenario: ransomware, account compromise, data exfiltration. It removes decisions from the crisis. A good playbook names who does what, in what order, with what authority. Write them in calm, use them in chaos.
Lessons learned, the phase everyone skips
After recovery, the temptation is to move on. The teams that improve run a blameless review: what let this happen, what detection missed it, what would have caught it sooner. That review feeds new detections back to the SOC. Skip it and the same incident recurs.
The core truth: incident response is won or lost in preparation. The plan, the access, the playbooks and the backups all have to exist before the incident, because you cannot build them during one.
Practise this
Run a tabletop exercise: walk through a scenario step by step and find where your process breaks. It costs nothing and reveals the gaps. Structured path in the SOC analyst syllabus.
Enroll in SOC
Live instructor led training with hands on labs and a verifiable certificate. Or start free on Hacklido.
Enroll in SOC