Incident Response Team (IR Team): A structured team for responding quickly to cyber incidents. Roles: 1) IR Lead/Coordinator (overall management, escalation), 2) Technical analyst (vulnerability detection, log analysis, containment), 3) Legal/Compliance (KVKK notification, insurance notification, regulatory correspondence), 4) Communications/PR (customer notification, media handling, internal messaging), 5) Forensic specialist (external hire, evidence collection, investigation). Optional: HR (insider threat), Management executive (decisions, resource allocation). For SMEs without one: Head + IT management + legal counsel + PR person = 4 people. Process: Hour 1 (team assembly, incident confirmation), Hour 2-4 (scoping, initial containment), Hour 4-24 (investigation, start of remediation, notification prep), Day 2-7 (finish investigation, customer/regulator notification, long-term fix). Rehearsal: Tabletop drill (simulation, 2-3 hours annually) → tests the process, clarifies roles, establishes decision authority. Documentation: Runbook (who, what, when, who approves), contact list (24/7 access), decision tree (scenario-based), post-incident review template (lessons learned).