- Prepare: the plan, the contacts, the tooling, the authority to act, and the rehearsal that turns a document into a habit.
- Detect and analyse: decide whether the alert is an incident, what kind, how far it has spread, and how bad it is. This phase is where most time is lost.
- Contain: stop it getting worse. Isolate the machine, disable the account, block the address, without destroying the evidence you will need.
- Eradicate: remove the cause: the malware, the credential, the flaw that let it in.
- Recover: restore systems from known-good state, watch for the attacker's return, and lift the restrictions in order.
- Learn: the review that turns this incident into the reason the next one is smaller. The phase organisations skip because everyone is tired.
The cycle is standardised and the standard's authors are blunt that the phases overlap and repeat: containment reveals a second compromised system, analysis resumes, containment widens. What the cycle mainly provides is a shared vocabulary under pressure, so that when someone says we are still in containment, everybody knows what that permits and forbids. The forbidden part matters: wiping a machine before its memory is captured destroys the evidence that would have shown how the attacker got in, and an eager administrator does that in the first hour of most poorly run incidents.
The decisions that cause the most damage are not technical. Who may take the payment system offline on a Saturday, and do they know it? Who tells the regulator, by when, and who tells customers? Who talks to the press, and who is forbidden to? Does the company pay a ransom, and who decides? Those questions have answers in a good plan, worked out calmly in advance, and no answers in a bad one, which is why the management-tier security credentials treat incident response as a matter of accountability and the analyst credentials examine it as a matter of triage. Both are right about their half.
What a rehearsal looks like
A tabletop exercise: a facilitator reads out a scenario in stages, the people who would actually respond say what they would do, and the gaps appear in the room rather than in the incident. A ransomware note on a Friday evening; the backup server is also encrypted; the regulator's deadline is seventy-two hours; the chief executive is on a plane. Two hours of that, twice a year, finds more problems in a plan than any review of the document.
