What is Incident Response?
Incident Response (IR) is the structured approach a company takes when a cyberattack or security breach occurs. The goal is to handle the situation quickly to limit damage and reduce recovery time and costs.
The 6 Phases (SANS Institute Model)
- Preparation: Having a plan, training staff, and ensuring backups exist before an attack happens.
- Identification: Detecting the breach and determining its scope. (Is it a false alarm or a real attack?)
- Containment: Stopping the bleeding. This means isolating infected computers from the network so the attack doesn’t spread.
- Eradication: Finding the root cause and removing the malware, hacker access, or vulnerabilities from the systems.
- Recovery: Restoring systems from clean backups and carefully bringing them back online while monitoring for any signs of return.
- Lessons Learned: Analyzing what went wrong and updating the preparation phase so it doesn’t happen again.
Knowledge Check
Question 1 of 1In which phase of incident response do you disconnect infected computers from the network to stop the attack from spreading?
Continue Learning
Guide
AI Security and Deepfake Scams
How scammers are using Artificial Intelligence to clone voices, generate fake videos, and steal corporate data.
GuideAuthentication vs. Authorization
Understanding the difference between who you are and what you can do.
GuideBrowser Security and Extensions
Your web browser is the gateway to the internet. Learn how to secure it against tracking and malicious extensions.