What Is Incident Response?

Incident response (IR) is the organized process an organization follows to detect, contain, and recover from a cybersecurity event that threatens the confidentiality, integrity, or availability of its systems and data. An event is any observable occurrence; an incident is an event (or series of events) that actually harms — or imminently threatens to harm — the business.

Why does a written plan matter? When ransomware is encrypting file servers at 3 a.m., nobody has time to invent a process. A tested incident response plan (IRP) defines who does what, who decides, who to call (legal, regulators, insurers, law enforcement), and how to communicate — before the pressure is on. Improvised response wastes the most valuable resource during an attack: time.<