Incident Management and Response
Incident Response Planning
Last Updated: March 18, 2026The Incident Response Plan A well-constructed incident response plan is one of the most valuable investments an organisation can make in its security programme. When...
OODA Loop Mapping to Incident Response
Last Updated: March 18, 2026The OODA Loop, originally developed by military strategist John Boyd, translates naturally into the security operations environment. Boyd designed it to describe how decision-makers process...
Diamond Model for Intrusion Analysis
Last Updated: March 18, 2026The Diamond Model provides a structured framework for investigating and understanding cyber intrusions. Where the Cyber Kill Chain describes the sequential stages of an attack...
Develop an Incident Response Plan
Last Updated: March 18, 2026An incident response plan is not a bureaucratic document produced to satisfy an audit requirement. It is the operational backbone that allows an organisation to...
Playbooks and Runbooks in Incident Response
Last Updated: March 18, 2026A Security Operations Centre without structured playbooks is operationally dependent on the experience and judgment of whoever is on shift at the moment an incident...
Managing Initial Incident Reporting
Last Updated: March 18, 2026Incident reporting is the point at which a potential security issue first enters the formal management process. Everything that follows, the investigation, the containment, the...
Incident Triage
Last Updated: March 18, 2026Incident registration and triage are the two steps that convert a raw report into a structured, prioritised case ready for investigation. Together they form the...
Incident Resolution: Containment, Eradication, and Recovery
Last Updated: March 18, 2026Incident resolution is where the response becomes tangible. Reporting identified the problem. Registration created the record. Triage established the priority. Resolution is where the SOC...
Incident Resolution Categorization
Last Updated: March 18, 2026Moving Beyond True and False Positives The binary classification of alerts as true positives or false positives is a starting point, not an endpoint. It...
Post-Incident Analysis
Last Updated: March 18, 2026Closing an incident ticket does not mean the work is finished. The post-incident analysis phase is where the organisation extracts the intelligence that makes the...
Incident Reporting and Documentation
Last Updated: March 18, 2026Structured incident documentation is not a bureaucratic obligation that competes with the real work of incident response. It is an integral part of that work....
Enhancing Incident Management
Last Updated: March 18, 2026Every organisation that operates in a digital environment will experience security incidents. The question is not whether incidents will occur but how prepared the organisation...
Crisis Management
Last Updated: March 18, 2026Security incidents become crises when they exceed the capacity of normal incident response procedures to contain them. The distinction matters because the response to a...
Incident Closure
Last Updated: December 30, 2025After an incident has been resolved, the final step in the incident management process is incident closure. This phase involves formally closing the incident, documenting...
Information Disclosure Management in Incident Response
Last Updated: March 18, 2026During an incident, the security team handles some of the most sensitive information the organisation possesses: details of compromised systems, the nature and scope of...
