Module 10

Cyber Incident Response and Recovery

Build a practical incident-response checklist for recognition, containment, recovery and continuous improvement.

Learning Objectives

  • Recognise signs of a cyber incident early.
  • Take safe initial containment steps.
  • Reset compromised credentials and restore from backups.
  • Capture lessons learned for future resilience.

Why This Matters

Even mature environments can experience incidents. Fast, organised response reduces damage and downtime.

Prepared teams recover faster and preserve trust.

Plain-Language Explanation

Incident response is a structured process: identify, contain, communicate, recover, and improve. Initial actions may include disconnecting affected systems safely, preserving useful logs, and changing exposed credentials from a trusted device. Recovery should prioritise known-clean restoration sources and clear ownership of decisions.

Reporting context: depending on incident type and impact, reporting channels and advisory support relevant to NZ organisations may be appropriate.

Practical Examples

  • Unexpected mass account lockouts trigger immediate review.
  • Ransom note appears and affected endpoint is isolated.
  • Compromised password is reset and sessions revoked.

Common Mistakes

  • Delaying response while trying to confirm every detail.
  • Overwriting evidence before collecting key information.
  • Restoring systems without identifying root cause.

Security Checklist

Module checklist progress0%

Short Knowledge Check

Question 1: What is one safe first action during active compromise?

Isolate affected systems according to your response procedure.

Question 2: Why preserve incident information?

It supports analysis, reporting, and future prevention improvements.

Question 3: What should happen after technical recovery?

Conduct a lessons-learned review and update controls and checklists.

Key Takeaways

  • Prepared response steps reduce uncertainty and panic.
  • Containment, communication and recovery must be coordinated.
  • Improvement after incidents is essential for long-term resilience.
← PreviousModule 10 of 10Next →