Incident response
What an incident response plan actually needs to cover
19 April 2023 · 3 min read
Incident response is an organisation's process and tooling for detecting and responding to security breaches, cyberattacks and other threats. The goal isn't only to prevent attacks — it's to minimise the cost and disruption of the ones that get through, because some will.
A security incident is any digital or physical event that threatens the confidentiality, integrity or availability of information systems or data. That covers a wide range: a deliberate attack by an outside actor, but also an unintentional policy violation by someone with legitimate access. Both need a response, even though only one is malicious.
Who owns the response
Incident response plans are typically executed by a computer security incident response team (CSIRT) drawn from across the organisation — not just the CISO and SOC, but IT, legal, HR, compliance and executive leadership. Response is as much a coordination problem as a technical one: someone needs to decide what gets disclosed, to whom, and by when, while the technical team is still working out what happened.
That's why the plan has to exist before the incident does. Deciding roles and communication lines in the middle of a live breach costs time you don't have.