Precursor Security
Glossary

Incident Response

Incident response is the organised process an organisation follows to prepare for, detect, contain, eradicate and recover from a cyber security incident, then learn from it. A structured incident-response process, often based on frameworks from NIST or SANS, limits the damage of a breach and speeds recovery.

Incident response is the structured approach an organisation takes when a security incident occurs, from the moment a threat is detected through to full recovery and the lessons learned afterwards. Its purpose is to limit damage, restore normal operations quickly, preserve evidence, and reduce the chance of the same thing happening again. A well-run incident-response capability is often the difference between a contained event and a business-threatening crisis.

The most widely used models describe a lifecycle of distinct phases. In the NIST formulation these are preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. The SANS model is similar, with preparation, identification, containment, eradication, recovery and lessons learned. The names differ slightly but the logic is the same: get ready in advance, understand what is happening, stop it spreading, remove it, restore services, and improve.

Preparation is the phase that most determines the outcome, yet it is the one done under least time pressure. It includes having an incident-response plan, defined roles and decision authority, tested backups, logging that will actually support an investigation, and rehearsed playbooks for likely scenarios such as ransomware or business email compromise. Organisations that prepare respond calmly; those that do not improvise during the worst possible moment.

Containment, eradication and recovery are the active phases during a live incident. Containment stops the spread, for example by isolating affected systems or disabling compromised accounts. Eradication removes the attacker’s presence, including any persistence they established. Recovery restores systems to normal operation and verifies they are clean before returning them to service. Throughout, careful handling preserves the evidence needed for later analysis and any legal or regulatory obligations.

The final phase, often skipped under the relief of resolution, is where lasting value is created. A post-incident review examines what happened, how well the response worked, and what should change, feeding improvements back into detection, preparation and controls. Many organisations retain an incident-response provider in advance so that expert help is available immediately when an incident strikes, rather than being sourced under pressure.

Retaining incident-response support in advance, rather than sourcing it during a crisis, materially improves outcomes. A retainer means experienced responders already understand the environment, contracts and access are in place, and help arrives in hours rather than days. Given that the cost of an incident rises with every hour it continues, the difference between a rehearsed, retained capability and an improvised scramble is often the difference between a contained event and a business-threatening one.

The final phase, learning from the incident, is the one most often skipped under the relief of resolution, yet it is where lasting value is created. A structured review of what happened, how the response performed and what should change feeds improvements back into detection, preparation and controls, so that each incident makes the organisation harder to compromise the next time rather than simply being survived and forgotten.

For incident response, Precursor provides retained readiness and hands-on support during an active incident, and feeds the findings back into detection and testing so the same weaknesses are not exploited twice.