# What is Incident Response (IR)?

> Incident response is the organized way an organization prepares for, detects, analyzes, contains, recovers from, and learns from cybersecurity incidents.

- Canonical URL: https://yellowcube.eu/glossary/incident-response/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It is a continuing risk-management capability, not merely the forensic work performed after a breach.

Effective response connects technical actions with business leadership, legal and regulatory duties, communications, safety, continuity, and recovery. Preparation matters because an incident is a poor time to discover who can authorize containment, where evidence is stored, or how critical services can be restored.

Most programs organize the work around a recognized lifecycle — preparation; detection and analysis; containment, eradication, and recovery; and post-incident learning — and rehearse it through tabletop and functional exercises. Organizations without internal depth often buy a response retainer so external help arrives under a pre-agreed contract rather than being negotiated during the worst hours of a breach.

### Key points

- **Before an incident:** Define roles, escalation paths, communications, evidence handling, external support, and exercise-tested plans.
- **During an incident:** Establish facts, assess impact, contain harm, preserve evidence, communicate decisions, and adapt as knowledge changes.
- **After containment:** Eradicate remaining access, restore safely, monitor for recurrence, and turn lessons into control improvements.
- **Important limitation:** Fast containment is not always the safest first action; poorly coordinated changes can destroy evidence or disrupt essential operations.

### Related terms

[Security operations center (SOC)](<https://yellowcube.eu/glossary/security-operations-center/>) · [Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/>) · [Tactics, techniques, and procedures (TTPs)](<https://yellowcube.eu/glossary/tactics-techniques-and-procedures/>) · [Root cause analysis](<https://yellowcube.eu/glossary/root-cause-analysis/>) · [Crisis management](<https://yellowcube.eu/glossary/crisis-management/>) · [Security incident](<https://yellowcube.eu/glossary/security-incident/>) · [Cyber kill chain](<https://yellowcube.eu/glossary/cyber-kill-chain/>) · [Persistence](<https://yellowcube.eu/glossary/persistence/>)

### Sources

[NIST SP 800-61r3: Incident Response Recommendations](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [NIST Cybersecurity Framework 2.0 (NIST CSWP 29)](https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

