The phases
Most frameworks describe the same cycle: preparation (plan, roles, tools and contacts in place before anything happens), detection and analysis (confirming that an alert is a real incident and understanding its scope), containment, eradication and recovery (stopping the spread, removing the attacker and restoring systems), and lessons learned. NIST SP 800-61 and ISO 27035 are the usual references.
What an incident response plan includes
Who leads the response and who takes decisions, how to reach them outside office hours, how incidents are classified by severity, playbooks for common scenarios such as ransomware, BEC or a lost laptop, how evidence is preserved, and who must be notified: management, customers, insurers and authorities.
Detection comes first
A plan only works if incidents are spotted early. Tools such as EDR and SIEM, operated by a SOC, shorten the time between the first sign of an attack and the response.
Where it shows up in compliance
ISO 27001 covers incident management in Annex A 5.24 to 5.28, and the ENS includes specific incident management measures. NIS2 and DORA add mandatory reporting to authorities within tight deadlines, explained in our guide to NIS2 and DORA incident reporting. Testing the plan with a tabletop exercise at least once a year is a good way to find gaps before a real incident does.




