Dabish Digital
Security

Three myths about incident response

There is no clever trick in this one, just a handful of decisions worth making deliberately. A few things about incident response that get repeated more often than they get checked.

The cheapest security work is the boring kind done on a schedule. Assume whoever inherits this will have half your context and none of your patience.

“It only matters for big sites”

Decide who does what before something happens. None of that requires a large budget, only a decision and someone to own it. If it only works because one person remembers to do something, it does not work yet.

“We can deal with it after launch”

Sometimes true, usually expensive. That sounds obvious written down. It is still the thing most often skipped.

“Our platform handles it”

Write up what happened while it is fresh. In practice this is a scheduling problem more than a technical one. Most teams find the first pass takes an afternoon and the maintenance takes minutes a month.

What this looks like day to day

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about incident response before you move on:

  • Someone can say what the current setup is without going to look
  • Decide who does what before something happens — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If you want a second opinion on how yours is set up, ask.