forumNew topic

Who does what when a cyberattack hits? Should I set up an Incident Response Team?

ÜÜmit P***ExpertCommunity member
Joined
May 2022
Message
1
#1

When an attack happens, people panic. Who defines the roles? If nobody is responsible, nobody knows what to do. What is an Incident Response Team?

Who should be on the IR team? IT head, software developer, legal counsel, HR... all of them?

Is training necessary? Should we run fake attack simulations (tabletop drills)?

BBanu Ş***Member
Job title
Pharmacist
Joined
Mar 2024
Message
81
Most Helpful#2

Incident Response Team (IR Team): A structured team for responding quickly to cyber incidents. Roles: 1) IR Lead/Coordinator (overall management, escalation), 2) Technical analyst (vulnerability detection, log analysis, containment), 3) Legal/Compliance (KVKK notification, insurance notification, regulatory correspondence), 4) Communications/PR (customer notification, media handling, internal messaging), 5) Forensic specialist (external hire, evidence collection, investigation). Optional: HR (insider threat), Management executive (decisions, resource allocation). For SMEs without one: Head + IT management + legal counsel + PR person = 4 people. Process: Hour 1 (team assembly, incident confirmation), Hour 2-4 (scoping, initial containment), Hour 4-24 (investigation, start of remediation, notification prep), Day 2-7 (finish investigation, customer/regulator notification, long-term fix). Rehearsal: Tabletop drill (simulation, 2-3 hours annually) → tests the process, clarifies roles, establishes decision authority. Documentation: Runbook (who, what, when, who approves), contact list (24/7 access), decision tree (scenario-based), post-incident review template (lessons learned).

MMustafa S***Member
Job title
Human Resources Manager
Sector
Jewelry
Organization type
two-branch business
Joined
May 2024
Message
43
#3

4-5 people is enough for an ir team. it lead, technical, legal pr. define roles upfront write down the chain of command. when an attack happens, run a fake simulation to test the mechanism... you need to do a tabletop drill once a year...

DDamla Ö***MemberCommunity member
Joined
Jan 2022
Message
70
#4

IR playbook structure: 1) contact list (email + phone, escalation authority), 2) incident classification (severity = response level: critical→immediate, high→1 hour, medium→4 hours), 3) initial response checklist (isolate systems, preserve evidence, notify management), 4) investigation workflow (log collection, timeline, root cause), 5) remediation (patching, config changes, process fixes), 6) communication templates (customer notification, internal employee memo), 7) post-incident review (what happened, why, how to prevent). Tabletop exercise mechanics: scenario (ransomware attack, data breach), timeline (realistic complexity), participants role-play, decisions documented, debrief notes highlight improvement areas. Tools: incident ticketing (Jira/GitHub), secure comms (private Slack channel, encrypted), playbook storage (wiki, git repo).

BBurak A***MemberCommunity member
Joined
Dec 2023
Message
39
#5

set up an ir team. head, it management legal, pr — 4 people is enough. write down roles, contact list. test if the mechanism works when an attack happens by doing a tabletop. preparing for an annual drilll is very beneficial...

edit: fixed a few typos.

ZZerrin T***Member
Job title
Quality control inspector
Sector
Healthcare services
Organization type
cooperative
Joined
Oct 2023
Message
389

Doki · Interface design · 2024

#6

IR team maturity levels: Level 1 (ad-hoc: no formal team, reactive), Level 2 (defined: team + runbook + training), Level 3 (managed: automated playbooks, metrics tracked), Level 4 (optimized: continuous learning, predictive). Tabletop exercise agenda: opening (scenario briefing, 10 mins), execution (participants resolve 5-6 scenario escalations, 90 mins), debrief (what went well/poorly, action items for improvement, 20 mins). Post-exercise metrics: MTTD (Mean Time to Detect), MTTR (Mean Time to Respond), recall accuracy (did the team follow the runbook correctly), decision cycle (how quickly was escalation approved). Annual training: new team members (onboarding), refresher (annual recertification), specialized (forensics, legal updates).

BBeren V***Member
Job title
Technical service technician
Sector
Advertising and promotion
Organization type
120-person company
Joined
Mar 2024
Message
123
#7

I've been dealing with this for a long time. like people defend habits, not processes. Resistance comes from there.

I'm also curious if anyone does it differently.

OOsman D***Expert
Job title
Supply chain manager
Sector
Construction
Organization type
120-person company
Joined
Mar 2025
Message
43
#8

If you're going this route, sort this out first. Everyone rushing into setting up an incident response team gets stuck at the same point.

If I were you, I'd go this route.

ZZeynep A***MemberCommunity member
Joined
Sep 2023
Message
1
#9

if I understood correctly, youre saying: Just because everyone does it doesnt mean its right.

BBeyza K***MemberCommunity member
Joined
Dec 2022
Message
3
#10

three different views emerged, they all complement each other. btw if 2FA is on a stolen password alone is useless.

if you scold false alarms nobody will report again... correct me if I'm wrong.

ZZerrin D***New memberCommunity member
Joined
May 2026
Message
140
#11

I'm a small business, let me explain from my side. Payment information changes are never verified through the channel they came from.

Proven by experience.

TTolga Y***MemberCommunity member
Joined
Dec 2023
Message
14
#12

This is exactly what we experienced. honestly solutions that work at a small scale collapse when you grow; I learned this late.

Just leaving this note it might be useful.

FFiliz Ö***Member
Job title
Operations manager
Sector
Seafood
Organization type
8-person team
Joined
Sep 2024
Message
383
#13

there are three things to check when doinng this but i mean when making a decision first look at what data you have on hand.

if you post the result here, it will help others too.

VVildan Ö***Member
Job title
Secretary
Sector
Retail
Organization type
family business
Joined
Dec 2024
Message
66
#14

thanks, that was the answer I was looking for.

YYiğit A***VeteranCommunity member
Joined
Jan 2025
Message
2
#15

The opposite happened to me, that's why I'm writing. Payment information changes are never verified through the channel they came from.

If I were you, I'd go this route.

FFiliz S***MemberCommunity member
Joined
Jun 2023
Message
3
#16

Thanks a lot, I'll try it today.

IIrmak Ö***Member
Job title
Company Owner
Sector
Security services
Organization type
two-branch business
Joined
Apr 2023
Message
53
#17

If I understood correctly, you're saying: Everything goes well for the first three months; problems arise in the fourth.

This is my opinion, I'm not claiming it's absolute truth.

ZZeynep B***Member
Job title
Marketing manager
Sector
Leather
Organization type
a company within a holding
Joined
May 2025
Message
254
#18

absolutely.. and if I were to add anything: Most incidents start with a leaked password, not a vulnerability.

people defend habits, not processes. resistance comes from there. anyway that's all, sorry if I went on too long.

KKemal T***Member
Job title
Accounting clerk
Sector
Accounting & advisory
Organization type
8-person team
Joined
Jan 2025
Message
347
#19

I'm a small business, let me explain from my side. Trying to do this alone is the most expensive way.

Correct me if I'm wrong.

HHakan Ş***New memberCommunity member
Joined
Aug 2026
Message
2
#20

I'm in the same situation, that's why I'm asking. Start with a small trial; don't commit to everything at once.

Proven by experience.

Reply