Skip to content
Getting Digital

Cybersecurity · Security operations

Incident response and forensics

Detection ends where the hardest decisions begin: whether to pull a server offline, whom to tell, which evidence to secure before it disappears. Incident response is the discipline of making those calls under pressure in an order agreed beforehand, and forensics is the patient work of reconstructing afterwards what really happened. Teams that have practised make the first calls in minutes; teams that have not spend those minutes arranging a meeting.

Why this topic exists: What happens after detection has its own standard (NIST SP 800-61), its own NICE work roles (Incident Response and Digital Forensics under Protection and Defense, evidence work under Investigation) and its own exams (CySA+, CHFI): containment, eradication, recovery, evidence.

Incident response begins when an alert raised by the security operations centre is confirmed as real and ends, formally, with a written account of what changed afterwards. In between, a response team limits the damage, removes the intruder, restores service and keeps evidence intact enough to support a later investigation, an insurance claim or a court case. Forensics is the evidential half of that work: imaging disks, preserving logs and memory, and rebuilding a timeline that survives scrutiny. Both halves depend on decisions taken long before the day they are needed: who may order a system offline, who speaks to customers, and which outside firm is called in.

The sequence the CISSP examines

  1. Detection: confirming that something happened and judging how serious it is.
  2. Response: assembling the people named in the plan and opening a record of every action taken.
  3. Mitigation: containing the spread, for instance by isolating hosts or disabling compromised accounts.
  4. Reporting: informing management, and regulators or customers where law or contract requires it.
  5. Recovery: returning systems to service from a state known to be clean.
  6. Remediation: closing the weakness that let the attacker in.
  7. Lessons learned: a blameless review that updates the plan, the detections and the controls.

NIST's SP 800-61 changed course in its third revision, published in April 2025. The 2012 edition it replaced was a stand-alone handling guide; the new one places response recommendations inside the wider risk management activities of the Cybersecurity Framework 2.0, so that preparation and recovery become part of how an organisation is governed rather than a separate playbook kept by the security team. The NICE Workforce Framework mirrors the split in the job market: Incident Response and Digital Forensics are separate work roles under Protection and Defense, while digital evidence analysis and cybercrime investigation sit in the Investigation category. Small teams usually combine the roles; larger ones keep them apart so that the people restoring service are not also the ones judged on the evidence.

Rebuilding before recording

Under pressure, the instinct is to wipe the affected machine and restore from backup straight away. That can end the visible problem and destroy the only record of how it began, leaving the entry point open for a second visit. Contain first, capture what you will need, then rebuild. Ransomware plans deserve particular rehearsal on this point, because restoring files does nothing about the access the attacker used to plant the malware.

Credentials follow the same lines. CySA+ gives incident response and management a domain of its own and is aimed at people who have worked as analysts for some years. On Microsoft's stack, SC-200 examines incident handling, where Microsoft Sentinel and Defender XDR are where an investigation usually starts. The CISSP covers the process from the manager's side within Security Operations. Readers new to the area should begin with the parent topic, security operations, and with threats and attacks, since recognising a technique is what makes the first containment call quick.

Next to this topic

Concepts to know

Glossary entries with the reason each one matters here.

  • Incident Response

    The lifecycle this topic follows.

  • Ransomware

    The incident type most response plans are rehearsed against.

  • SOC

    Response starts from the SOC's escalation.

Certifications that test it

Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.

Tools of the trade

Frequently asked

How does incident response differ from forensics?
Response aims to stop harm and restore service quickly; forensics aims to establish what happened with evidence that can be defended. The two pull in different directions, speed against preservation, which is why mature teams agree in advance which evidence is captured before any system is rebuilt.
Does a small organisation need an incident response plan?
Yes, even one that fits on two pages. It should say who decides, whom to call (including any outside responder or insurer), where contact details are kept offline, and which systems matter most. The worst moment to look for a phone number is when email is down.
Is digital forensics a good way into security?
It is more a specialism than an entry route. Most forensic analysts arrive from system administration, SOC work or law enforcement, because interpreting artefacts demands a firm sense of how systems normally behave.

Courses in the directory

63 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.

Browse the directory shelf

Last reviewed 26 September 2026 · Getting Digital