Incident Response
When Prevention Fails
No defence is perfect. Sooner or later something gets through: a phishing email is clicked, a server is compromised, a laptop is stolen. Incident response (IR) is the organised way to handle that moment, so the damage is small, the recovery is quick and the organisation learns from it.
A security incident is an event that threatens the confidentiality, integrity or availability of information or systems. A ransomware infection, a leaked customer database and a compromised admin account are all incidents.
Having a plan before the incident matters: in a crisis people panic, and a tested plan replaces panic with steps.
The IR Lifecycle (NIST)
The widely used NIST SP 800-61 model has four phases (SANS breaks it into six, but the ideas are the same):
1. Preparation
Build the team, the IR plan, contact lists, playbooks, logging, backups and tools before anything happens. Run tabletop exercises: discuss a made-up incident together to find gaps. Know who can approve taking a system offline.
2. Detection and Analysis
Spot the incident (SIEM alerts, EDR, staff reports, customers) and confirm it. Decide the scope (which systems and data?), the type and the severity. Start a timeline and keep notes of every action.
3. Containment, Eradication and Recovery
- Containment: stop the spread. Short-term: isolate the machine from the network, disable the account, block the IP. Long-term: temporary fixes while you clean up.
- Eradication: remove the cause: malware, backdoors, malicious accounts, and fix the vulnerability that let them in.
- Recovery: restore from clean backups, rebuild systems, reset passwords, monitor closely for re-infection, then return to normal service.
4. Post-Incident Activity (Lessons Learned)
Within days, hold a blameless review: what happened, what worked, what did not and what will change. Write the report and update the plan. This phase is what makes the organisation stronger.
Preparation -> Detection & Analysis -> Containment / Eradication / Recovery -> Lessons Learned
^______________________________________________________________|
Containment: Common Decisions
| Situation | Typical first move |
|---|---|
| Ransomware on one workstation | Disconnect it from the network (do not just shut down), alert the SOC, check for spread |
| Stolen employee credentials | Disable or reset the account, revoke sessions and tokens, check what it accessed |
| Malicious cron job or web shell on a server | Isolate the server, capture evidence, then remove and rebuild |
| Data leak in a cloud bucket | Restrict public access immediately, review access logs |
Containment is always a balance: acting fast to limit damage versus keeping systems running and preserving evidence.
Forensics Basics
Digital forensics collects and analyses evidence in a way that keeps it reliable, in case of disciplinary, legal or regulatory action.
- Order of volatility: collect the most fragile data first: memory (RAM), running processes and network connections, then disk, then logs and backups.
- Chain of custody: document who handled each piece of evidence, when and why.
- Preserve the original: work on a copy (a forensic image) and verify it with a hash (SHA-256) to prove it was not altered.
- Timeline analysis: combine log entries, file timestamps and network records to reconstruct what happened.
- Do not wipe or "clean up" before evidence is captured.
Common tools: Autopsy, FTK Imager, Volatility (memory analysis), Wireshark, and KAPE.
Communication and the Law
Technical work is only half of IR:
- Internal: keep leadership, legal, HR and communications informed with clear, factual updates.
- Customers and regulators: many laws require breach notification. For example, the Nigeria Data Protection Act 2023 and the GDPR expect notification of a personal-data breach within about 72 hours where individuals are at risk. Financial institutions also have reporting duties to their regulators, such as the Central Bank of Nigeria.
- National CERTs: in Nigeria you can report incidents to ngCERT, and similar bodies exist in other countries.
- Do not speculate publicly. Share confirmed facts through one authorised spokesperson.
A Nigerian and Global Scenario
A Lagos fintech's finance officer opens an email attachment. The EDR quarantines a file, but an hour later the SOC sees the account logging in from an unfamiliar country. The team disables the account and revokes sessions (containment), finds a mailbox rule forwarding payment approvals to an external address (analysis), removes it and forces password resets with MFA (eradication), checks that no transfers were altered (recovery) and reviews email filtering and staff training (lessons learned). The same pattern is played out daily in companies from Abuja to Amsterdam.
Try It: Make the Call
In the editor on the right, you are the incident handler in a ransomware scenario. At each step choose the best next action and see the reasoning.
Try it yourself
Key Takeaways
- Incident response is the organised handling of security incidents. The NIST lifecycle is preparation, detection and analysis, containment, eradication and recovery, and post-incident review.
- Preparation decides how well an incident goes: plans, playbooks, backups, logging, contact lists and tabletop exercises.
- Containment limits damage (isolate hosts, disable accounts, block IPs). Eradication removes the cause, and recovery restores from clean backups with close monitoring.
- Forensics preserves evidence: collect volatile data first, keep a chain of custody, work on hashed copies and never wipe before capturing.
- Communicate carefully. Breach notification rules such as the Nigeria Data Protection Act 2023 and GDPR use short deadlines. Hold a blameless lessons-learned review.
Quick Quiz
1.Which is the correct order of the NIST incident response phases?
2.A workstation shows signs of ransomware. What is the best immediate containment step?
3.Why is the 'order of volatility' important in forensics?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx