Resources
Responding to a security incident
Incident response follows five stages: detect, contain, eradicate, restore, capture. The decisions are prepared in calm, in a written procedure, because the moment of an incident leaves little room for improvisation.
Five stages, prepared in calm
Detection rests on what was instrumented beforehand: centralised logs, threshold alerts, user reports. Containment isolates the affected systems and halts propagation, while preserving traces. Eradication removes the cause and closes the entry route. Restoration brings the service back from a verified backup. Capture, finally, turns the event into an improved procedure: the stage that makes the next one shorter.
- A written procedure, known to the on-call team before any incident
- Centralised, retained logs that make detection possible
- A containment order that preserves usable traces
- Restoration from a backup whose test is dated
- A circulated post-incident report, with actions and owners
What each stage produces
This progression is that of the incident response block in the cybersecurity programme. Each row carries a deliverable, which makes the simulation exercise assessable as a professional task.
| Stage | The decision taken | The deliverable |
|---|---|---|
| Detection | Qualify the alert and trigger the procedure | A time-stamped incident record |
| Containment | Isolate without destroying traces | An isolated perimeter and a copy of the logs |
| Eradication | Remove the cause and close the entry route | A fix applied and verified |
| Restoration | Choose the recovery point | A service restored from a tested backup |
| Capture | Decide on durable actions | A post-incident report and an action plan |
The volume devoted to response
- taught hours on incident response
- 180
- hours of penetration testing
- 220
- modules in the cybersecurity field
- 18
Detection, containment, digital forensics, reporting.
Knowing the attack makes defence concrete.
Continuing-education base, real count.
Operational questions
Who decides to take a service down?
The procedure names them before the incident: an appointed manager, with a deputy and a way to reach them. It is the most expensive decision to take under pressure, so the one that gains most from being prepared in calm.
How long should logs be retained?
Long enough to cover the delay between an intrusion and its detection, which leads most organisations to keep several months. The chosen duration goes into the governance table, with the associated volume and storage cost.
Should an incident be simulated?
Yes, at least once a year: the drill reveals the numbers that go unanswered, the missing access rights and the decisions nobody feels authorised to take. It costs half a day and makes the procedure genuinely applicable.
Explore next
- Service continuityAcceptable downtime, acceptable data loss, backups, switchover, power and drills: building a verifiable continuity plan.
- Networks and cloudAddressing, routing, segmentation, virtualisation, containers and cloud architectures: the fundamentals of a controlled infrastructure.
- Industrial maintenancePreventive plan, vibration analysis, thermography, alert thresholds, spare parts and availability indicators: organising a site's maintenance.
- OHADA accountingChart of accounts, journal, ledger, trial balance, financial statements, value added tax and fixed assets: OHADA accounting applied.
- Reading financial statementsBalance sheet, income statement, cash flow statement: the profitability, structure and liquidity ratios that support a reasoned diagnosis.
- Forecast budgetVolume and price assumptions, cost structure, break-even point, seasonality and variance tracking: building a budget that serves steering.