Skip to content
../services/security

RISK · CRISIS MANAGEMENT

Incident response

Knowing who does what in the first two hours changes everything after it.

What it is

Most of the damage from a security incident does not come from the attack itself, but from what happens next: hours lost working out who to call, evidence destroyed by powering off a server, clumsy communication that deepens the loss of trust, a notification obligation discovered three weeks too late. Incident response means deciding all of that calmly, while nobody is under pressure.

The phases of a response

  1. 01

    Detection and triage

    Telling a false positive from a real incident, and a minor incident from a broad compromise. This triage governs everything that follows.

  2. 02

    Containment

    Stop the spread without destroying evidence. Isolate from the network rather than power off: volatile memory often holds what matters.

  3. 03

    Eradication

    Close the entry point, revoke compromised access and remove whatever the attacker left behind. Restoring before this step simply restarts the cycle.

  4. 04

    Recovery

    Progressive return to service, with heightened monitoring on affected systems for the following weeks.

  5. 05

    Lessons learned

    What was missing, what worked and what changes in the plan. It is the most frequently skipped phase, and the most profitable.

What is almost always missing

We find these same gaps in most organisations that have never lived through an incident.

  • No up-to-date list of who to call, in what order, outside business hours
  • No decision made in advance about who may cut a production service
  • No pre-established contact with the insurer or legal counsel
  • Logs retained too briefly to reconstruct what happened
  • No communication templates ready for clients and employees

What must be decided beforehand

01

A named response team

Who decides, who communicates, who executes, and who replaces each of them when absent. Names, not job titles.

02

Escalation thresholds

What justifies waking someone at night, and what can wait for morning. Without thresholds, everything is urgent or nothing is.

03

Sufficient log retention

Reconstructing an incident takes weeks of history. Seven-day retention makes the investigation impossible.

04

Prepared communications

Templates for clients, employees and partners, to adapt rather than to draft under pressure.

05

The regulatory track built in

Under privacy law, a confidentiality incident must be recorded and, depending on the risk of serious harm, notified. That decision path is prepared in advance.

The first two hours

This sequence fits on one page, and that page must be reachable without network and without a computer.

  1. 01Note the time and what was observed, before any corrective action
  2. 02Isolate without powering off, and do not start by reinstalling
  3. 03Activate the response team and explicitly name the person who decides
  4. 04Notify the insurer: many policies impose a deadline and an approved responder
  5. 05Open a timestamped crisis log, which later serves the insurer and the review

Five questions to place yourself

Ask them at a leadership meeting. The silence that follows is usually the answer.

  • Who do you call first, on a Sunday at six in the morning?
  • Who has the authority to cut a customer-facing service?
  • How long do you retain your system logs?
  • Does your insurance cover a cyber incident, and under what conditions?
  • Have you ever simulated an incident, even for one hour?

What we put in place

The plan is written beforehand. During, you only apply it.

We build your procedure with the people involved, then test it against a realistic scenario.

Prepare our procedure