GlossarySOC and monitoring

Incident response

Short answer

Incident response is the organised process a company follows to detect, contain, investigate and recover from a security incident, such as ransomware or an account takeover, and to learn from it. It is usually documented in an incident response plan.

The phases

Most frameworks describe the same cycle: preparation (plan, roles, tools and contacts in place before anything happens), detection and analysis (confirming that an alert is a real incident and understanding its scope), containment, eradication and recovery (stopping the spread, removing the attacker and restoring systems), and lessons learned. NIST SP 800-61 and ISO 27035 are the usual references.

What an incident response plan includes

Who leads the response and who takes decisions, how to reach them outside office hours, how incidents are classified by severity, playbooks for common scenarios such as ransomware, BEC or a lost laptop, how evidence is preserved, and who must be notified: management, customers, insurers and authorities.

Detection comes first

A plan only works if incidents are spotted early. Tools such as EDR and SIEM, operated by a SOC, shorten the time between the first sign of an attack and the response.

Where it shows up in compliance

ISO 27001 covers incident management in Annex A 5.24 to 5.28, and the ENS includes specific incident management measures. NIS2 and DORA add mandatory reporting to authorities within tight deadlines, explained in our guide to NIS2 and DORA incident reporting. Testing the plan with a tabletop exercise at least once a year is a good way to find gaps before a real incident does.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, 24/7 SOC operations, detection engineering and incident handling.

Go to the topic hub