What is Incident Response?
Incident response, told as a story about the book you open when a thief gets in.
The bell rang, and everyone is running around.Who locks the doors? Who chases the thief? Who do we tell?
Moving without an order makes it worse.The diary gets erased, the wrong door gets locked, and the thief is still inside.
Incident response is following the order you wrote down in advance.When the bell rings, open the book. Who does what is already written down.
Contain, remove, restore.First lock the room so it can't spread. Then clear the bug, change the keys, and restore from the spare chest. Never erase the diary.
Afterwards, everyone gathers and writes down what happened.How they got in, why it took so long to notice, what to fix in the book. And an unpracticed book is just paper — ring a fake bell now and then.
Incident response = when the bell rings, follow the book: confirm → contain → remove → restore → learn.
The six steps of NIST SP 800-61 — preparation, detection & analysis, containment, eradication, recovery, lessons learned. The book is a playbook; the fake bell is a tabletop exercise.
When grown-ups say it
- Playbook
- The book. One per kind of incident: ransomware, fake letters, a lost laptop.
- Detection & analysis
- Cat or thief? First check whether the bell was real. → the guard room
- Containment
- Lock the door so it can't spread. Lose one room, keep the castle. → locking the room
- Eradication
- Clearing out the bug and the thief. Change the keys too — the thief will have copied them. → reforging the key
- Recovery
- Restoring from the spare chest. And keep watching for a while after. → the spare chest far away
- Lessons learned
- Gathering to write it down. Not a blame session — a session for fixing the book.
- Forensics
- Reading the diary for footprints. Which is why the diary must never be erased. → the one-line diary
- Tabletop exercise
- Ringing a fake bell. Walking through the book without a real thief.