How incident response works in a real company
£1.9 billion is the estimated cost of the Jaguar Land Rover cyberattack to the UK economy. Behind numbers like that there is always a room full of people making hard decisions with incomplete information. That room is incident response.
Here is how it actually works, in plain English.
The phases
Most teams follow a lifecycle described in NIST's incident handling guide (SP 800-61). The names vary between companies, but the shape is the same.
- Preparation. Everything you do before the bad day. A written plan, contact lists, backups that actually work, logs switched on, people who know their roles. Most incidents are won or lost here.
- Detection and analysis. Something looks wrong. Is it real? What happened, when, and how far has it spread? This is where the SOC and forensics work happens.
- Containment. Stop it getting worse. Isolate a laptop, disable an account, block a connection.
- Eradication and recovery. Remove the attacker properly, fix the hole they used, and bring systems back safely.
- Lessons learned. An honest review. What went well, what didn't, what changes now. The step everybody wants to skip, and the one that stops the next incident.
The hard part is not technical
Switching off a server is easy. Knowing whether to switch it off is hard. Every containment action has a cost:
- Isolate the wrong machine and the factory stops for nothing.
- Wipe a machine too early and the evidence is gone forever.
- Reset one password and the attacker simply uses the other one they stole.
- Wait too long and the damage spreads.
Good responders preserve evidence first, find the root cause, and contain the identity or access the attacker is using, not just the noisy symptom.
The people in the room
- The incident lead. Keeps everyone focused and makes the calls.
- Analysts and forensics. Find out what actually happened.
- IT and engineering. Make the changes and keep the business running.
- Leadership and legal. Decide on money, regulators and contracts.
- Communications. Staff, customers and the press need clear, honest updates.
Practise the decisions, not just the commands
You can't rehearse a real incident at work. But you can rehearse it here.
- OP-01: Line Down. You are Head of Cyber Operations at a UK carmaker on the day an intrusion is discovered. A budget, six analysts, stakeholders who can overrule you, and a factory losing money every hour.
- GL-04: Market Blackout. A hands-on technical response to rogue AI agents at a stock exchange, scored on containment, evidence, cost and speed.
If you run a business: when did you last test your incident response plan? If the answer is "never" or "what plan", this is the right week to start.
CyberLearner.org is a free cybersecurity training platform, built on the curriculum of the International Cybersecurity Olympiad (ICO). Every lab is hands-on and runs in your browser. It is open to everyone, regardless of skill level.