Skip to content
- On-call rota, comms channels, and incident commander role defined.
- Runbooks for common failures and data breaches.
- Detect: monitoring alerts, stakeholder reports, anomaly detection.
- Triage: classify severity, assign roles, start incident doc.
- Contain: disable risky flows, rotate keys, block exfil paths.
- Eradicate/Recover: fix root cause, restore, validate integrity.
- Notify: legal/compliance review; stakeholder and user comms as required.
- Postmortem: blameless review, action items, owners, and deadlines.
- MTTR within target; actions prevent recurrence; comms timely and clear.
- Role confusion: pre-assign and drill quarterly.
- Hours to days depending on scope; protects trust and compliance.