For the complete documentation index, see llms.txt. This page is also available as Markdown.

Incident Response and Crisis Management

Purpose

Incident response ensures that security events are detected, assessed, contained, eradicated, recovered and learned from.

Severity Model

Severity
Description
Response expectation

SEV1 Critical

Confirmed major compromise, material data exposure, loss of critical service or active threat.

Immediate mobilisation, executive escalation, customer notification assessment and crisis cadence.

SEV2 High

Serious incident affecting sensitive data, privileged access, production service or supplier boundary.

Same day escalation, containment plan and formal incident record.

SEV3 Medium

Limited incident, suspicious activity or contained vulnerability exploitation.

Managed through security operations with tracked actions.

SEV4 Low

Minor policy breach, unsuccessful attack or low-impact anomaly.

Record, triage and close with evidence.

Response Phases

  1. Detect and report.

  2. Triage and classify.

  3. Preserve evidence.

  4. Contain the threat.

  5. Eradicate root cause.

  6. Recover service.

  7. Validate integrity.

  8. Notify stakeholders where required.

  9. Conduct post-incident review.

  10. Track corrective actions to closure.

Evidence

  • incident record;

  • timeline;

  • logs and indicators;

  • decisions and approvals;

  • notifications;

  • containment actions;

  • recovery validation;

  • lessons learned;

  • corrective action plan.

Rule

Never sacrifice evidence preservation, legal notification obligations or customer trust for speed unless there is a clear safety, operational or security reason to act immediately.

Last updated

Was this helpful?