Glossary term

incident response

The structured process for detecting, containing, and recovering from security incidents — breaches, ransomware, data leaks, service outages. Incident response plans define roles, escalation paths, communication templates, and evidence-preservation procedures before an incident occurs, so teams aren't inventing the process under pressure.

conceptSecurity & ComplianceIntermediate

When you'd see it: Security team documentation, SOC 2 audits, business continuity planning, post-mortem reports.

Why it matters: The cost of an incident is heavily determined by how quickly and effectively the response happens. A practiced playbook dramatically reduces mean time to recovery and limits regulatory exposure.

Common mistakes: Confusing incident response with disaster recovery. IR covers security events specifically; DR covers the broader category of service disruption from any cause.

Study this in BizTech Primer →