# Incident response

> The plan and the practice for what happens between noticing something is wrong and being back to normal.

The value of a plan is almost entirely in having decided things in advance: who declares an incident, who can take production offline, who talks to customers, where the notes go, which regulator has to be told and within how long. None of those are decisions to make at two in the morning with an audience.

The part most often missing is the capacity to reconstruct what happened. If the logs were not kept, or were kept somewhere the attacker could reach, the honest report is that the scope is unknown — and "we cannot rule it out" is a far more expensive sentence than the storage it would have cost to avoid it.

## Related terms

- https://dfieldsolutions.com/en/glossary/blue-team.md
- https://dfieldsolutions.com/en/glossary/threat-model.md
- https://dfieldsolutions.com/en/glossary/data-exfiltration.md

---

Source: https://dfieldsolutions.com/en/glossary/incident-response
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
