Incident response
The planned process followed when a security incident is detected: limiting the impact, preserving evidence, cleaning up and restoring systems, and finding the cause.
- 01
Why it matters
In a security incident, the decisions made in the first hours set the size of the damage: which system to shut down, how to preserve evidence, whom to inform? A response plan prepared in advance reduces panicked mistakes. Because there are legal notification deadlines, the incident must be recorded and a timeline kept.
- 02
Example
Ransomware is spotted on a server. The team disconnects it from the network but does not switch it off, so traces in memory are preserved. They confirm the backups are unaffected, restore the system from a clean build and investigate how the attacker got in.
- 03
Common mistake
Wiping and rebuilding systems in a panic, or telling nobody about the incident. If the evidence is gone, nobody learns how the attacker got in and they can return the same way; late notification can also cause legal trouble.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.