Browse
Incident Response Basics
The standard phases of handling a security incident, from detection through lessons learned.
What it is
Incident response is the structured process for handling a security breach or attack, minimizing damage and recovery time and cost.
Key points
- Standard phases: preparation, detection & analysis, containment, eradication, recovery, and post-incident review.
- Containment comes before full eradication — the immediate priority is stopping the bleeding (isolating affected systems) before doing deeper forensic cleanup.
- Chain of custody matters for evidence if the incident may involve legal or regulatory follow-up — don't destroy logs or artifacts while investigating.
- A blameless post-incident review (see also: postmortems) is what turns an incident into an improvement to detection, containment, or prevention rather than just a fire that got put out.
