Incident response
Sometimes, despite deploying the best technology and exerting our best efforts, the bad guys still manage to penetrate our security defenses and cause damage in some form or fashion to our information resources. It’s not something any of us want to happen on our watch but the fact of the matter is the day will come when it will. When it does, those of us who are most passionate about the field of cybersecurity tend to take it personally while others might become engaged in a finger-pointing contest. The truth is neither of those mindsets is helpful and, more likely than not, the actual root cause or success of the breach will have nothing to do with any specific analyst. When a security breach, or other unauthorized activity, occurs, we refer to it as an incident. To keep our heads screwed on straight and operate smoothly with an organized and proper reaction, there is a subset of cybersecurity that has evolved, known as security incident response (SIR).
...