Skip to content

Glossary · Cybersecurity

Incident response

Also called: IR, Cyber incident response, Breach response

Incident response is the structured process for detecting, containing, investigating and recovering from a security incident. The legally consequential part is not containment but scope: establishing what data was accessed or taken, because notification duties, regulatory deadlines and litigation exposure all follow from that finding.

The tension nobody warns you about

The operational instinct is to restore service as fast as possible. The legal requirement is to be able to say afterwards what happened. These conflict directly in the first hours, and the conflict is usually resolved badly because the operations team is in the room and counsel is not yet.

Reimaging a compromised server restores service and destroys the artifacts that would have established what the attacker reached. Rotating credentials before capturing authentication logs removes the record of which accounts were used. Neither is wrong as an instinct; both need to happen in an order that preserves the evidence first where it is feasible.

Preserve, then contain

The artifacts that establish scope have the shortest lives:

  • Volatile memory on affected systems, which is gone at reboot and often contains the clearest evidence of what was executed.
  • Endpoint and EDR telemetry, typically retained for weeks rather than months.
  • Firewall, VPN and proxy logs, the primary record of data leaving the environment, and frequently rotated within days.
  • Cloud audit logs, where default retention is short and configurable retention is usually not configured.

An hour spent capturing these is the difference between an investigation that establishes scope and one that cannot, and the second forces worst-case notification.

Privilege, honestly stated

Engaging the forensic firm through counsel is standard practice intended to bring the investigation within privilege. It is worth being precise about how well that works, because the case law is not uniformly favourable and the outcome tends to depend on facts the organisation controls.

What has fared poorly: reports distributed widely inside the business, investigations that would have been commissioned identically for ordinary operational reasons, and firms already engaged under a pre-existing business contract simply re-papered after the incident. What has fared better: engagement by counsel for the purpose of legal advice, a defined and limited distribution, and a clear separation between the remediation work the business needs and the analysis counsel commissioned.

Planning this before an incident is considerably easier than arguing it afterwards.

Scope is the deliverable

Everything that follows depends on one determination: what data was accessed or exfiltrated, and whose it was. Notification obligations vary by jurisdiction and data type; several regimes now run on very short clocks measured from determination rather than from discovery.

An investigation that answers "we cannot rule it out" produces the most expensive possible outcome — notification to every individual whose data was in the affected system rather than to those actually involved. The gap between those two populations is frequently an order of magnitude, and closing it is where forensic work pays for itself several times over.

Before it happens

The organisations that handle incidents well have done three unremarkable things in advance: named who decides, pre-engaged counsel and a forensic firm so nobody is negotiating a retainer at 2am, and confirmed that their logging retains long enough to reconstruct an intrusion that began weeks before it was noticed. The third is the one most commonly discovered to be false during the incident itself.

From our work

Dealing with incident response in a live matter?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.