Incident Response
The organised approach to preparing for, detecting, containing, eradicating and recovering from cybersecurity incidents, and to learning from them so that future incidents are less likely and less damaging.
Incident response follows a defined life cycle. NIST SP 800-61 long described four phases: preparation; detection and analysis; containment, eradication and recovery; and post-incident activity. Its 2025 revision aligns incident response with the functions of the NIST Cybersecurity Framework 2.0. Preparation includes an incident response plan, defined roles, contact lists, playbooks, logging and forensic tools, while the response itself balances stopping the attack with preserving evidence.
Every organisation needs an incident response capability, whether in-house, retained from a specialist provider or both. Regulations often impose notification deadlines: GDPR requires notifying the supervisory authority of a personal data breach within 72 hours where feasible, NIS2 sets staged reporting that starts with an early warning within 24 hours, and directions issued by CERT-In in 2022 require specified incidents in India to be reported within six hours of being noticed.
Exercises such as tabletop simulations test plans and decision-making before a real incident occurs. Recovery should consider legal advice, communication with customers and regulators, and the integrity of backups. In industrial environments, containment actions are coordinated with operations and safety staff so that isolating systems does not create hazards. ISO/IEC 27035 provides international guidance on information security incident management.
Key points
- NIST SP 800-61 is a widely used incident response reference.
- Preparation, including tested plans and playbooks, shapes outcomes.
- GDPR, NIS2 and CERT-In directions set incident reporting deadlines.
- Post-incident reviews feed lessons back into security controls.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Security Operations Centre (SOC)Cybersecurity & Compliance
- RansomwareCybersecurity & Compliance
- Security Orchestration, Automation and Response (SOAR)Cybersecurity & Compliance
- NIS2 DirectiveCybersecurity & Compliance
- General Data Protection Regulation (GDPR)Cybersecurity & Compliance
- Digital Personal Data Protection Act, 2023 (DPDP Act)Cybersecurity & Compliance
Terms that refer to Incident Response
- Distributed Denial of Service (DDoS)Cybersecurity & Compliance
- Endpoint Detection and Response (EDR)Cybersecurity & Compliance
- Health Insurance Portability and Accountability Act (HIPAA)Cybersecurity & Compliance
- NIST Cybersecurity Framework (CSF)Cybersecurity & Compliance
- Security Awareness TrainingCybersecurity & Compliance
- Security Information and Event Management (SIEM)Cybersecurity & Compliance
- Threat IntelligenceCybersecurity & Compliance