Skip to main content

Incident Response

practice

Incident response is the coordinated process for detecting, analysing, containing, eradicating, recovering from, and learning from cybersecurity incidents.

Status: published
Last reviewed: 2026-09-12

Technical explanation

An incident-response capability defines roles, severity, evidence handling, communications, legal and regulatory escalation, containment options, recovery criteria, and post-incident improvement. NIST integrates incident response into broader cybersecurity risk management rather than treating it as an isolated sequence.

Business relevance

Prepared response reduces downtime, data loss, confusion, and notification delays. It helps organisations make defensible decisions under pressure and restore trusted operations.

Implementation example

After detecting stolen credentials, a response team disables sessions, preserves logs, scopes affected systems, rotates secrets, communicates with stakeholders, restores services, and tracks corrective actions.

Limitations and common misconceptions

A written plan is insufficient without exercises, telemetry, authority, supplier coordination, and tested recovery. Premature containment can destroy evidence, while delayed action can increase impact.

Discuss your systems

Need help implementing or evaluating this concept? Keenfunnel designs connected AI, automation, and data systems.

Book a discovery session