Incident Response (Respond)

"Don't panic."

Incident Response (IR) is the organized approach to addressing and managing the aftermath of a security breach or cyberattack.

Core Phases (PICERL)

  1. Preparation: Plan, train, tool up.
  2. Identification: Detect and determine scope.
  3. Containment: Stop the bleeding.
  4. Eradication: Remove the infection.
  5. Recovery: Restore services.
  6. Lessons Learned: Improve for next time.

Section Contents