incident response
The structured process for detecting, containing, and recovering from security incidents — breaches, ransomware, data leaks, service outages. Incident response plans define roles, escalation paths, communication templates, and evidence-preservation procedures before an incident occurs, so teams aren't inventing the process under pressure.
When you'd see it: Security team documentation, SOC 2 audits, business continuity planning, post-mortem reports.
Why it matters: The cost of an incident is heavily determined by how quickly and effectively the response happens. A practiced playbook dramatically reduces mean time to recovery and limits regulatory exposure.
Common mistakes: Confusing incident response with disaster recovery. IR covers security events specifically; DR covers the broader category of service disruption from any cause.
Study this in BizTech Primer →