Incident Response: Playbooks, Forensics, and Why Preparation Wins

The quality of an incident response is decided before the incident. Playbooks, forensics, and the preparation habits that separate the two.

Preparation is the response

The quality of an incident response is largely decided before the incident begins. Organisations that respond well have decided in advance who does what, which decisions require which authority, and how communication flows internally and externally. Organisations that respond badly are making all of those decisions while the incident is happening.

The stages, in order

  • Preparation — playbooks, roles, tooling, and evidence handling standards agreed before anything happens
  • Detection and analysis — confirming that an event is a genuine incident and scoping it
  • Containment — stopping the incident from spreading, sometimes at the cost of availability
  • Eradication — removing the attacker and their persistence mechanisms
  • Recovery — restoring systems to operation with confidence they are clean
  • Lessons learned — unglamorous and often skipped, but where next time’s improvement lives

Playbooks, not scripts

A playbook is a documented sequence of actions for a specific scenario — ransomware, business email compromise, credential exposure. Its value is not that it removes judgement from the response. It is that it removes the questions someone would otherwise have to answer under pressure: who to notify, what to preserve, when to escalate, which legal obligations apply.

Tabletop exercises — walking through a scenario with the people who would actually respond — are the cheapest way to find out that a playbook does not work before it needs to.

Why forensics matters

Forensics answers three questions that responders and often regulators need answered: what happened, what data was affected, and how the attacker got in. Answering credibly requires evidence that has been collected and preserved to a standard that survives scrutiny — disk images, memory captures, and logs handled with documented chain of custody.

Organisations that reboot compromised machines to “get back to work” often destroy the evidence that would have told them how the attack succeeded. That decision looks reasonable in the moment and costs disproportionately afterwards, particularly if regulatory reporting is required.

Related in the Knowledge Base

Free Download

Know what an attacker sees before they do.

A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.

Free PDF · No spam · Unsubscribe anytime

Send me the checklist