
When Every Second Counts: A Practical Guide to Cyber Incident Response
A cyberattack does not announce itself. When one hits, organisations without a tested response plan often make decisions under pressure that turn a manageable incident into a catastrophic one. Here is what good incident response actually looks like, and why it starts long before the breach.
David Taylor
Managing Director

The Cost of Hesitation
The first fifteen minutes of a cyber incident are often the most consequential. Organisations that have rehearsed their response contain breaches faster, communicate more clearly, and recover with significantly less damage. Those that have not tend to improvise, and improvisation under pressure rarely ends well.
Incident response is not a technical function alone. It is a business function. And it deserves the same planning rigour as any other operational risk.
What Is Incident Response?
Incident response (IR) is the structured process an organisation follows when a cybersecurity event occurs or is suspected. It covers everything from initial detection and triage through to containment, eradication, recovery, and post-incident review.
The goal is straightforward: minimise damage, reduce recovery time, and limit the blast radius of whatever has happened.
Most mature frameworks organise the process into phases. The names vary slightly, but the logic is consistent.
The Six Phases
1. Preparation
This is where most organisations underinvest. Preparation means having a documented IR plan, knowing who is responsible for what, maintaining an asset inventory, and testing your response through tabletop exercises or simulations before a real incident forces you to find out what you missed.
It also means having the right tools in place: endpoint detection, centralised logging, and clear escalation paths.
Preparation also means knowing who you will call before an incident occurs. Aruga's Incident Response Assurance provides organisations with access to expert incident response support when they need it, rather than trying to find help for the first time during an active attack.
2. Identification
Something has been flagged. Is it a genuine incident or a false positive? This phase is about confirming whether a security event is actually occurring, understanding its initial scope, and beginning to classify it by severity.
Speed matters here, but so does accuracy. Misclassifying an incident early can send your entire response in the wrong direction.
3. Containment
Once confirmed, the priority is stopping the spread. Short-term containment might mean isolating an affected system from the network. Longer-term containment involves ensuring the threat cannot re-establish itself while the investigation continues.
Containment decisions carry risk. Taking a system offline affects operations. Leaving it connected risks further compromise. Good IR planning means these trade-offs have been thought through in advance.
4. Eradication
The threat needs to be fully removed. This means identifying the root cause, closing the vulnerability that was exploited, and ensuring no artefacts of the attack remain. This phase requires forensic care. Rushing it is how organisations end up dealing with the same threat twice.
5. Recovery
Systems are restored, validated, and returned to normal operation in a controlled and monitored way. This is not the moment to relax. Attackers sometimes lie dormant and wait for exactly this point to re-engage.
6. Lessons Learned
The post-incident review is where organisations either grow or stagnate. A structured debrief, conducted within days of resolution, should examine what happened, how the response performed, and what changes are needed. Skipping this phase is one of the most common and most costly mistakes in IR.
The Human Factor
Technical capability only gets you so far. Some of the most damaging failures in incident response come down to communication breakdowns, unclear authority, and people making high-stakes decisions without the context they need.
Who declares an incident? Who decides to take a system offline? Who notifies regulators, customers, or the board? These questions need answers before the incident happens, not during it.
Under the UK GDPR, organisations may need to notify the ICO of a personal data breach within 72 hours of becoming aware of it where the breach is likely to result in a risk to people's rights and freedoms. That clock does not pause while you work out who is supposed to make the call.
Why Tested Plans Beat Perfect Plans
An IR plan that has never been tested is a document, not a capability. Tabletop exercises, red team simulations, and full-scale response drills reveal gaps that no amount of theoretical planning will surface. They also build the muscle memory that helps people stay calm and make better decisions when pressure is highest.
The organisations that handle incidents well are rarely those with the most sophisticated tools. They are the ones that have practised.
For larger organisations, and those operating internationally, in regulated sectors or critical infrastructure, a more tailored Incident Response Retainer can provide the preparation, familiarity and response arrangements needed before an incident occurs.
Where Aruga Cyber Can Help
Building an incident response capability from scratch is a significant undertaking. Aruga Cyber works with organisations to assess their current readiness, stress-test their existing plans, and develop the practical frameworks that make the difference when an incident occurs.
Aruga provides different levels of incident response support, from preparation and assurance through to retained response arrangements and emergency support during an active cyber incident.
Whether you are starting from zero or pressure-testing a plan you already have, the time to act is now, not after the alert fires.
Keep reading
Get practical cybersecurity thinking in your feed.
Subscribe to Aruga's LinkedIn Newsletter for practical insight on cyber risk, incident response and security operations.

David Taylor
Managing Director
Keep reading
Related posts


What Happens in the First Hour of a Cyber Attack
Read article →
