Skip to main content
Guidance

Incident management

How to effectively detect, respond to and resolve cyber incidents.

Page 2 of 7

Introduction: Incident Response overview

iStock.com/z_wei
A high level introduction to incident response processes, including the important issues of detection and notification

Cyber incident response (IR) is complicated by two factors. Firstly, no two incidents are ever the same. Secondly, all responses require people, process and technical elements to work together in order to be successful.

Planning your incident response ahead of time is essential. This will be a major determining factor in the final outcome of any real world incident.

You should produce IR plans and guidance, exercise your response and review your capabilities (including those of any 3rd party service providers). This will give you the best chance of minimising the impact of any attack and recovering quickly.

Note: GDPR

It's worth noting that preparation and mitigation for data breaches are both explicitly required by the ICO, as part of your GDPR-related measures.

They state that you should, "Have well-defined and tested incident management processes in place in case of personal data breaches."


Incident Response vs Incident Management

In this guidance both incident management and incident response are referred to.

The two terms are very often used interchangeably. However, there are some differences:

Incident Management (IM) sits within and across any response process, ensuring all stages are handled. IM deals with any communications, media handling, escalations and any reporting issues, pulling the whole response together, coherently and holistically. Blue channel in Fig 1.

Incident Response (IR) This includes triage, in-depth analysis, technical recovery actions and more. Green channel in Fig 1.


Reviewed

Version

1.0