Learning Objectives
- Recognise signs of a cyber incident early.
- Take safe initial containment steps.
- Reset compromised credentials and restore from backups.
- Capture lessons learned for future resilience.
Build a practical incident-response checklist for recognition, containment, recovery and continuous improvement.
Even mature environments can experience incidents. Fast, organised response reduces damage and downtime.
Prepared teams recover faster and preserve trust.
Incident response is a structured process: identify, contain, communicate, recover, and improve. Initial actions may include disconnecting affected systems safely, preserving useful logs, and changing exposed credentials from a trusted device. Recovery should prioritise known-clean restoration sources and clear ownership of decisions.
Isolate affected systems according to your response procedure.
It supports analysis, reporting, and future prevention improvements.
Conduct a lessons-learned review and update controls and checklists.