I keep hearing people talk about incident response like it is some magical process that will save them when things go wrong. But when I ask them what the actual goal of their incident response effort is, I get blank stares.
So let me spell it out.
The primary goal
The goal of an incident response effort is to minimize damage and reduce recovery time and costs. That is it. Everything else is secondary.
You are not trying to catch the bad guy. You are not trying to write a research paper. You are trying to stop the bleeding, figure out what happened, make sure it does not happen again, and get the business back to normal as fast as possible.
The phases
NIST breaks incident response into four phases, and understanding them helps clarify the goal at each stage:
- Preparation – Build your team, document your plan, set up your tools. The goal here is to be ready before something happens. Most organizations skip this and then panic when an incident occurs.
- Detection and Analysis – Identify that an incident has occurred and understand its scope. How bad is it? What systems are affected? Is it still ongoing? The goal is to get an accurate picture as fast as possible so you can make informed decisions.
- Containment, Eradication, and Recovery – Stop the attack from spreading, remove the threat, and restore systems. The goal is to limit the blast radius and get back to business.
- Post-Incident Activity – Figure out what happened, why it happened, and how to prevent it from happening again. The goal is to learn and improve. This is the phase that almost everyone skips, which is why the same organizations keep getting hit by the same types of attacks.
What incident response is NOT
It is not a substitute for good security practices. If your security program is a mess, no amount of incident response capability will save you. Incident response is your safety net, not your first line of defense.
It is also not just an IT problem. Legal, communications, management, and sometimes law enforcement all need to be involved. If your incident response plan does not include these stakeholders, it is incomplete.
Get your incident response plan together. Test it. Update it. Then test it again.