Educatifu
Open menu

Detection and incident response

Prevention fails eventually, so mature security assumes breach: detect fast, respond calmly, recover cleanly. Meet logging, SIEM, the SOC and the incident lifecycle.

ExpertCyber Security~14 min

Before this lesson

  • Lesson: Network security — attack and defend

Here is the mindset shift that separates mature security from naïve security. A beginner asks "how do I keep attackers out?" An expert knows that, given enough time and a determined adversary, prevention will eventually fail — and asks instead "how fast can I detect a breach and contain it before it becomes a catastrophe?" This is the assume-breach philosophy, and it reshapes everything.

Detection: you can't respond to what you can't see

If an attacker is moving through your systems (the lifecycle lesson), the only way to stop them mid-campaign is to notice. That requires two things:

  • Logging — systems must record what happens: logins, privilege changes, network connections, file access. Without logs, an intrusion is invisible and, afterwards, un-investigable.
  • A SIEM — a Security Information and Event Management system collects logs from across the organisation, correlates them, and raises alerts when patterns look malicious (a login from a new country followed by mass file access, say). It turns an ocean of raw events into a manageable stream of signals.

Watching that stream is the job of a SOC — a Security Operations Centre — the people (and increasingly automation) who triage alerts, separate false alarms from real intrusions, and pull the alarm when something is genuinely wrong. Good detection is the difference between catching an attacker at "initial access" and discovering them months later after the data is long gone.

Response: a calm, repeatable process

When an incident is confirmed, panic is the enemy. Mature teams follow a pre-planned lifecycle (codified in standards like NIST SP 800-61):

  1. Prepare — before anything happens: build the plan, the tools and the runbooks.
  2. Detect & analyse — confirm it's real, and scope it: what's affected?
  3. Contain — stop the bleeding — isolate affected systems, revoke credentials — without tipping off the attacker prematurely or destroying evidence.
  4. Eradicate — remove the attacker's foothold entirely (a half-cleaned system just gets re-compromised).
  5. Recover — restore clean systems and services, and watch for the attacker's return.
  6. Learn (post-mortem) — a blameless review: how did they get in, what did we miss, what do we change? This is where an incident makes the organisation stronger.

The teams that survive incidents well are the ones who practised this before the real thing — with drills and tabletop exercises — just as fire crews train before the fire.

Detection and response are largely technical and procedural. But the most common way attackers get in isn't technical at all — it's people. The final lesson is about the human layer.

Key takeaways

  • Mature security assumes breach — the goal shifts from "never get in" to "detect and contain fast, before real damage".
  • Detection rests on comprehensive logging fed into a SIEM, watched by a SOC that turns signals into investigated alerts.
  • Incident response follows a repeatable lifecycle — prepare, detect, contain, eradicate, recover, learn — practised before it's needed.

← All Cyber Security lessons

Bring us the problem, not a perfect specification

Tell us what needs to change, who it affects and any important deadline. We will review the context and reply with useful next questions.

  1. 01Share contextDescribe the workflow, constraint or risk.
  2. 02Clarify togetherWe identify missing facts and useful options.
  3. 03Choose a startAgree a focused assessment or delivery step.
Start a conversation