Incident Response Journey
Use this lifecycle for all incident types. Click a stage to learn more.
Stage
What happens
Minimum record to keep
Detect and report
Staff, alerts or systems identify suspicious activity and report via approved channels.
Who reported, when, what was observed, attached evidence.
Triage
Assess whether confidentiality, integrity or availability may be affected and determine severity.
Systems, users, data, initial risk level.
Contain
Limit further damage by isolating systems, disabling accounts or blocking malicious indicators.
Containment time, action owner, decision approvals.
Recover and learn
Remove root cause, restore operations, document lessons and track improvements.
Recovery steps, residual risk, corrective actions.
Audience Guide
All staff and partners
Quick actions, incident categories, reporting form
Know when and how to report, even when unsure.
Managers
Roles, escalation prompts and communication rules
Support staff and maintain a healthy reporting culture.
ICT / Incident handlers
Lifecycle, playbook cards, severity matrix and review template
Respond consistently, document actions and learn.