Skip to main content
Institute of Advanced Technological and Commercial Studies

Resources

Responding to a security incident

Incident response follows five stages: detect, contain, eradicate, restore, capture. The decisions are prepared in calm, in a written procedure, because the moment of an incident leaves little room for improvisation.

Five stages, prepared in calm

Detection rests on what was instrumented beforehand: centralised logs, threshold alerts, user reports. Containment isolates the affected systems and halts propagation, while preserving traces. Eradication removes the cause and closes the entry route. Restoration brings the service back from a verified backup. Capture, finally, turns the event into an improved procedure: the stage that makes the next one shorter.

  • A written procedure, known to the on-call team before any incident
  • Centralised, retained logs that make detection possible
  • A containment order that preserves usable traces
  • Restoration from a backup whose test is dated
  • A circulated post-incident report, with actions and owners

What each stage produces

This progression is that of the incident response block in the cybersecurity programme. Each row carries a deliverable, which makes the simulation exercise assessable as a professional task.

StageThe decision takenThe deliverable
DetectionQualify the alert and trigger the procedureA time-stamped incident record
ContainmentIsolate without destroying tracesAn isolated perimeter and a copy of the logs
EradicationRemove the cause and close the entry routeA fix applied and verified
RestorationChoose the recovery pointA service restored from a tested backup
CaptureDecide on durable actionsA post-incident report and an action plan

The volume devoted to response

Detection, containment, digital forensics, reporting.

taught hours on incident response
180

Knowing the attack makes defence concrete.

hours of penetration testing
220

Continuing-education base, real count.

modules in the cybersecurity field
18

Operational questions

Who decides to take a service down?

The procedure names them before the incident: an appointed manager, with a deputy and a way to reach them. It is the most expensive decision to take under pressure, so the one that gains most from being prepared in calm.

How long should logs be retained?

Long enough to cover the delay between an intrusion and its detection, which leads most organisations to keep several months. The chosen duration goes into the governance table, with the associated volume and storage cost.

Should an incident be simulated?

Yes, at least once a year: the drill reveals the numbers that go unanswered, the missing access rights and the decisions nobody feels authorised to take. It costs half a day and makes the procedure genuinely applicable.

Responding to a security incident — Resources | IHETC — IHETC