Incident response
What you do once it has already happened, and what you wish you had done first.
50 sketches
RPOThe gap you agreed to lose
RTOThe number you wrote, the number you ran
Chain of custodyAs good as its paperwork
ContainmentThe mop is not the repair
Crisis managementThe bridge cannot answer these
Decision authorityAllowed to say stop
Forensic preservationIt evaporates from the top
Incident communicationsA second string
Incident response lifecycleNever in that order
Lessons learnedWhat came out of the bottom
PlaybooksA floor, not a script
Ransom decisionsThe receipt you get
Restoration testingOpen it before you need it
Root causeThe hole is not the pressure
Security eventsWhere response begins
Short-term containmentThe quick bit is not the job
Tabletop exercisesThe blanks show up in the room
Incident severity can change as facts emergeThe needle moves as facts land
A timeline should separate observation from inferenceTwo rows, not one
Credential reset order mattersWhile someone still holds the pen
Recovery needs clean dependenciesA clean glass, the same pipe
Incident roles reduce decision collisionsOne hand on the switch
Reporting clocks can start before certaintyThe clock starts before the answers
Post-incident actions should fix systems, not just peopleNobody fixed the leak
Forensic copies protect original evidenceMark the copy, never the original
Hashes can show evidence stayed unchangedThe same short string, twice
Timestamps need interpretationOne moment, three different times
Memory can reveal what disk cannotIt has to unwrap itself to run
Forensic tooling can change the thing examinedYou leave prints of your own
Deleted does not always mean goneThe card, not the book
Cloud forensics depends on provider evidenceYou get what comes through the hatch
Forensics should answer specific questionsA torch, not a floodlight
Offline copies break attacker reachabilityReach ends at the last plug
Immutable backups trade flexibility for protectionSet in concrete
RPO and RTO answer different questionsTwo different clocks
Restoring data can restore malware tooThe newest jar is the spoiled one
Backup credentials deserve separate protectionNot on the same switch
Recovery order follows dependenciesBottom crate first
Backup retention determines how far back you can restore to escape corruption or compromiseAs far back as the rope goes
Recovery tests include people and permissionsThe drill that only restored the data
Snapshots and backups solve different failure modesTwo different accidents
Equifax: knowing about a vulnerability is not knowing it is patchedThe list said five
Target: supplier access showed why third-party portals need strong segmentation from sensitive systemsThe partitions stop short
Colonial Pipeline: business shutdown can follow IT compromiseNothing touched the pipe
Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transferThree answers, and it moves
British Library: recovery can outlast initial disruptionThe outage was the short part
Hawaii false missile alert: test and live alert paths need separation because confirmation prompts cannot correct a convinced operatorA hand apart
CrowdStrike 2024: trusted security software can be concentration riskOne roller, every machine
LastPass: protecting vaults includes developer and backup pathsThree of the same thing
Okta support compromise: support artefacts can contain session powerThe log had a wristband in it
