Incident Response
The organized process an organization follows to detect, contain, and recover from a cybersecurity incident.
Incident response↗ is the organized process an organization follows to detect, contain, and recover from a cybersecurity↗ incident, a breach, an infection, a data leak, or any event that threatens the confidentiality, integrity, or availability of its systems. Having a plan in place before an incident happens is what separates a controlled, fast recovery from a chaotic, costly one.
A typical incident response process moves through phases: detecting that something is wrong, containing the damage so it doesn't spread further, eradicating the cause, recovering normal operations, and finally reviewing what happened to prevent a repeat. Organizations that rehearse this process through drills tend to respond far faster and with much less damage than those improvising for the first time during a real incident.