When incident response is worth the effort
The advice here is unglamorous, which is probably why it gets skipped. Incident response is not free, and pretending otherwise leads to bad decisions.
Security is a maintenance habit rather than a purchase, which is why it drifts. The version that survives contact with a real deadline is the simple one.
When it is worth it
Decide who does what before something happens. Small and consistent beats large and occasional here. Write the reasoning down alongside the decision, because the reasoning is what changes first.
When it is not
If nothing downstream depends on it and nobody is complaining, it can wait. It is worth being explicit about, because assumptions differ quietly.
How to decide
Write up what happened while it is fresh. It is worth being explicit about, because assumptions differ quietly. If it only works because one person remembers to do something, it does not work yet.
What this looks like day to day
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about incident response before you move on:
- Someone can say what the current setup is without going to look
- Decide who does what before something happens — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Most of the value here comes from doing the first two things, not all of them.