The set of processes and capabilities mobilized to detect, contain, eradicate and recover from a security incident; the quality of the response largely determines loss severity.
Incident response refers to the set of processes, procedures and technical capabilities mobilized by an organization to detect, contain, eradicate and recover from a cybersecurity incident. Reference frameworks, notably NIST SP 800-61 and ISO 27035, break this cycle into four to six phases: preparation, which involves defining roles, staffing a response team (CSIRT or SOC), testing plans and establishing relationships with forensic providers; detection and analysis, aimed at identifying, qualifying and classifying the incident; containment and eradication, consisting of isolating compromised systems, removing the threat and cleaning the environment; and finally remediation and lessons learned, covering full service restoration and defense improvement. For cyber insurance, incident response is structuring in several respects. First, the quality and speed of the response are among the main determinants of loss severity: an organization that detects and contains ransomware within hours will suffer a much smaller loss than one that discovers it after several weeks of latency, by which time all backups may also be encrypted. Second, most cyber policies explicitly cover incident response costs: forensic team fees, notification costs for affected individuals, system restoration costs and crisis management assistance. Third, the existence and maturity of an incident response plan are a central assessment factor at underwriting, as the insurer seeks to ensure that the insured can contain a loss before it becomes catastrophic.
Following a ransomware attack detected in the middle of the night, an incident response team contains the incident in four hours by isolating the affected servers. This speed limits propagation and allows full restoration within 72 hours, where a similar uncontained incident could have paralyzed the company for several weeks.
incident response, IR, réponse à incident, gestion de crise cyber, CSIRT