Organised approach to detecting, containing, eradicating, and recovering from security incidents.
Incident response is the organised approach to handling security incidents—breaches, malware infections, data theft, and other cyber attacks. Effective incident response minimises damage, reduces recovery time, and enables learning. The NIST incident response lifecycle includes preparation, detection and analysis, containment/eradication/recovery, and post-incident activity. Incident response requires prepared plans, trained teams, and practiced procedures.
Why It Matters
The DSC Perspective:
Incidents will happen. Your response determines the outcome. Have documented plans, trained staff, and tested procedures before incidents occur. Poor response turns minor incidents into major breaches.
