Detecting and Responding · Lesson 10 of 11
Responding to an incident
When something goes wrong
Even good defences fail sometimes. What separates a small problem from a disaster is how you respond. Security teams follow a simple plan:
- Detect: notice something is wrong (often from the logs).
- Contain: stop it spreading. Disconnect the affected device, lock the account.
- Eradicate: remove the cause, the malware or the stolen access.
- Recover: restore from clean backups and watch closely.
- Learn: write down what happened and fix the weakness so it cannot happen again.
The calmest teams are the ones who decided these steps before an incident, not during one.
Practice
Imagine a staff laptop is infected with ransomware. Write the first two actions you would take, in order. (Hint: which step stops it spreading to other machines?)
You’re reading for free. Sign in to keep your progress and earn a certificate when you finish.Sign in to keep my progress →