Skip to content

Incident Response

Security Incident Response Readiness Checklist

A NIST-aligned IR checklist for preparation, detection, containment, eradication, recovery, and lessons learned.

Estimated time
4–10 Weeks
Audience
SOC, CISO, and Legal Teams
Last updated

Operational reference for incident-response capability. Notification clocks under GDPR, NIS2, or sector rules still require legal assessment.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Prepare

Phase 2: Detect & Analyze

Phase 3: Contain, Eradicate, Recover

Phase 4: Post-Incident

FAQ

Which NIST publication covers IR?+

NIST SP 800-61 is the common IR lifecycle reference.

Is a tabletop enough?+

It is necessary but not sufficient. Technical failover and phishing-response drills add coverage.

Do we notify in 72 hours always?+

GDPR has a 72-hour supervisory clock when a personal-data breach is likely to risk rights. Other laws differ.

Should we pay ransomware?+

That is a legal, insurance, and sanctions decision—not a checklist item to pre-authorize here.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer