Move from triage to containment, eradication, recovery, and lessons learned.
Preserve evidence while reducing harm.
Assign roles and communications before a crisis.
Preparation establishes contacts, authority, tooling, playbooks, legal guidance, and exercises. Identification validates an event and its scope. Containment limits impact while preserving evidence; eradication removes persistence; recovery restores trusted operation and monitors for recurrence. Lessons learned turn an incident into control improvement.
Do not destroy evidence through hurried reimaging without a plan. Record decisions, timestamps, actions, uncertainty, and chain of custody. Communications should be accurate, need-to-know, timely, and coordinated with legal and business owners.
Exercises
Write a ransomware first-hour playbook.
Identify containment choices and their business trade-offs.
Define evidence handling fields.
Self-check
Why scope before eradication?
What is containment?
Who approves public communication?
Self-Check Quiz
1. What is the goal of containment?
AnswerLimit ongoing harm and attacker movement while preserving the ability to investigate and recover.
2. Why document uncertainty?
AnswerIt prevents assumptions from becoming facts and supports defensible decisions and later learning.
Homework
Create an incident-response plan for stolen credentials.
Define roles, evidence, containment, recovery, and notification.
Run a tabletop exercise and record gaps.
Sample answerDisable or scope the credential, revoke sessions, preserve identity and access logs, identify use and affected resources, rotate secrets, verify persistence is removed, recover service, notify appropriate stakeholders, and conduct a lessons-learned review.