0 / 7
Incident Response Process
A security incident is an event in which an attacker breaks into an information system through hacking or malware and causes damage. In the rush after an incident, it is easy to destroy evidence or start fixing the wrong place. So the work from pre-incident preparation to resolution is split into 7 steps with a fixed order. Each step builds on the results of the step before it.
Example: the incident from the Cyber Kill Chain, where a single quote email led to a customer data leak, is followed here from the response side.
1 / 7
1. Pre-incident preparation
Before any incident, the company forms a computer emergency response team (CERT) and decides who handles what. It writes down an emergency contact list and response procedures. It installs detection tools to catch anomalies and sets systems to keep logs. Without this preparation, every later step is slower.
2 / 7
2. Detection of incidents
At 2:10 a.m., the detection system raises an alarm as large amounts of data flow from an employee PC to an unknown server outside the company. The on-duty administrator checks the alarm. Normal work never produces such a transfer, so the administrator judges it to be a security incident.
3 / 7
3. Initial response
The administrator reports to the response team and gathers its members through the emergency contact list. The team runs an initial check and records the basics, such as when the incident was found, which systems are involved, and what symptoms appear. To keep evidence intact, nobody powers off the PC or deletes files. Data is still leaking out, though, so how to stop it is decided in the very next step.
4 / 7
4. Formulate response strategy
The team weighs how critical the attacked system is, how sensitive the leaked data is, whether the incident is public, and how much a shutdown would hurt the business, then picks the best strategy. In this example, the team decides to cut only the network connection and keep the PC powered on, so evidence in memory is not lost. Because customer data leaked, it also decides to bring in law enforcement for a joint investigation. The strategy is carried out after management approves it.
5 / 7
5. Investigate the incident
The team copies the PC's memory and disk, and gathers traffic logs from the mail server and detection system along with database access logs. Analyzing this data reveals when the incident happened, who caused it, and how. On September 28, an employee opened the attachment in the quote email, which installed the backdoor. The backdoor had been connected to the attacker server since October 1, and customer data left through that channel early on October 5. The attacker server's address is handed to law enforcement.
6 / 7
6. Reporting
The team turns its findings into a report that decision makers such as executives can easily understand. It records the course of events, the scope of damage, the response, and remaining risks accurately. The report is submitted to law enforcement and becomes the basis for the plan to prevent recurrence.
7 / 7
7. Resolution
The team fixes the root causes. It removes the backdoor and updates the document program that still had the weakness. It also adds a system that scans mail attachments. It changes security policies and procedures so the same trick does not work again, and assigns an owner who follows the improvements through to the end.