Most organisations will face a security incident at some point. What separates a contained event from a prolonged crisis is rarely the attacker's skill; it is whether the defender has decided in advance who does what, which systems can be isolated, who may speak to the press, and how evidence will be kept. A plan written for the first time during an incident is not a plan. This article outlines the elements of a response capability that holds up under stress.
Use a recognised lifecycle
NIST SP 800-61 describes incident handling as a cycle: preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. ISO/IEC 27001 also expects documented incident management procedures. Adopting one of these structures gives your teams a shared vocabulary and makes audits and regulator conversations simpler. The cycle matters because lessons from the final stage must feed back into preparation.
Define roles and authority
Decide, in writing, who leads the response and who can approve disruptive actions such as disconnecting a data centre link or suspending a customer-facing service. A typical structure includes:
- An incident commander with authority to make decisions quickly.
- Technical leads for investigation, containment and recovery.
- A communications lead for internal messages, customers, media and partners.
- Legal and compliance representatives, and a business owner for each critical service.
- A scribe who records every action and decision with timestamps.
Keep an up-to-date contact list that works when email and corporate chat are unavailable, and include key suppliers and external responders.
Write playbooks for the likely scenarios
A short, tested playbook is worth more than a long policy. Prepare playbooks for ransomware, business email compromise, compromised privileged account, data leakage, denial of service and loss of a critical supplier. Each should state detection triggers, severity criteria, first actions, containment options and their business impact, escalation points and recovery criteria. Map the steps to the techniques in MITRE ATT&CK so that analysts know what to look for next.
Preserve evidence from the first minute
Well-meaning rebuilds and reboots destroy the traces needed to understand what happened. Train responders to:
- Record who touched which system and when, and maintain a chain of custody for collected items.
- Capture volatile data such as memory and active connections before powering anything off, where it is safe to do so.
- Take forensic images or snapshots, and work on copies rather than originals.
- Protect logs from deletion by forwarding them to a central platform with restricted access.
Sound evidence handling supports root-cause analysis, insurance and legal processes, and any later dispute with a supplier or attacker.
Communicate deliberately, including with regulators
Prepare message templates in advance for staff, customers, partners and media, and agree who approves them. Be factual, avoid speculation, and update at defined intervals. For banks and government bodies, identify which supervisory authorities, central bank departments or national security contacts must be informed, and in what timeframe. Because obligations vary by institution and sector, confirm them with your legal and compliance teams rather than assuming. Do not rely on a claim that a particular data-protection law applies unless counsel has confirmed it.
Test, then improve
Run tabletop exercises at least annually, with executives present, using realistic scenarios and injects such as a journalist's call or a failed backup. Follow with technical drills that test isolation, log access and restoration. After every exercise or real incident, hold a blameless review, assign corrective actions with owners and dates, and update the plan.
How Wethaq ICT helps
Wethaq ICT helps organisations build and rehearse incident response capabilities: writing plans and playbooks aligned with NIST SP 800-61, facilitating executive tabletop exercises, preparing forensic readiness, and providing experienced responders and investigators when an incident occurs. We work with your legal, compliance and communications teams so that technical action and institutional obligations stay in step.
Let’s build a secure foundation for your digital future
It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.

