How to get incident response right
The gap between knowing this and actually doing it is where most teams lose ground. The short answer to incident response is that it is mostly a sequence of small decisions, not one big one.
Security is a maintenance habit rather than a purchase, which is why it drifts. If two people in the business would answer this differently, that gap is the actual problem.
What it costs to ignore
Decide who does what before something happens. The reasoning matters more than the rule, because the rule has exceptions. Write the reasoning down alongside the decision, because the reasoning is what changes first.
The steps
- Establish what you have today before changing anything
- Communicating early beats communicating perfectly
- Write up what happened while it is fresh
- Write down the decision so the next person does not re-litigate it
Write up what happened while it is fresh. Getting it slightly wrong is survivable. Ignoring it entirely is not. Check it against what you would want a competitor's site to get wrong.
Turning this into a decision
How to tell if yours is fine
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about incident response before you move on:
- Someone can say what the current setup is without going to look
- Write up what happened while it is fresh — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Most of the value here comes from doing the first two things, not all of them.