Incident Response Basics

Beginner ~6 min read
Sooner or later something goes wrong — a breach, a lost laptop, a login that wasn't you. What separates a minor scare from a disaster is having a plan before the panic. That plan has a name, and it's simpler than you'd think.

What is a Cybersecurity Incident?

A cybersecurity incident is any event that threatens the confidentiality, integrity, or availability of information or systems. Examples include a data breach, ransomware infection, unauthorized access, or a DDoS attack.

The Incident Response Lifecycle

Organizations follow a structured process to handle incidents. NIST defines six phases:

Preparation

Have plans, tools, and trained teams ready.

Detection

Identify that an incident has occurred.

Containment

Limit the spread and impact of the incident.

Eradication

Remove the threat from affected systems.

Recovery

Restore systems to normal operation.

Lessons Learned

Review what happened and improve defenses.

Who Responds to Incidents?

SOC (Security Operations Center) → The team that monitors systems 24/7 for threats and triages alerts.

IR Team (Incident Response Team) → Specialized responders who investigate and contain confirmed incidents.

CISO (Chief Information Security Officer) → The executive responsible for an organization's overall security strategy and incident communication.

What YOU Should Do If You Think You've Been Hacked

1. 🔌 Disconnect from the internet immediately
2. 🔐 Change your passwords FROM A CLEAN DEVICE
3. 📢 Notify your IT/security team (or school's IT helpdesk)
4. 🚫 Don't delete anything — preserve evidence
5. 📝 Document what happened and when
🎯 Key Takeaway

When something goes wrong, don't improvise — follow the lifecycle: Prepare, Identify, Contain, Eradicate, Recover, and capture Lessons learned. A calm, repeatable process beats panic every time.

// Knowledge Check