Incident Response
Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
Incident Response covers all steps an organisation takes to detect, contain, eradicate, and learn from a security incident. The goal is to minimise damage and keep recovery times short.
How it works
A phased approach following the classic model from NIST SP 800-61 Rev. 2 is common practice. It covers preparation, detection and analysis, containment, eradication and recovery, and post-incident activity.
The preparation phase is crucial. This includes having a plan, contact lists, and pre-approved actions. It also involves practising the procedures.
During an incident, one person coordinates the response effort. Technical, communication, legal, and management teams work in parallel.
For example, ransomware starts encrypting file servers on a Sunday morning. The SOC isolates the affected systems and blocks the compromised admin account. An incident response team then takes over the investigation. They secure evidence and plan the recovery process. Senior management decides on communications and on notifications to the authorities.
What to look out for
- Keep an incident response plan ready and available offline.
- Define in advance who decides on system shutdowns, notifications, and communications.
- Clarify which services your SOC provider includes and which are billed separately.
- Practise your plan at least once a year with a tabletop exercise.
- Review every major incident and implement the lessons learned.
Switzerland and regulation
Reporting obligations vary depending on the industry. Since 1 April 2025, operators of critical infrastructure must report cyberattacks meeting certain criteria to the National Cyber Security Centre (NCSC) within 24 hours of discovery. FINMA-supervised institutions report cyberattacks to FINMA within 24 hours of discovery.
The revFADP (revised Federal Act on Data Protection) requires notification to the FDPIC. This applies if a data security breach is likely to result in a high risk to data subjects.
Typical mistakes
A common mistake is rebuilding systems too quickly before securing evidence. This makes it unclear how the attacker got in, and they often return. Another error is poor communication with employees, who may then seek their own solutions.
How we implement it
Response and containment actions within the agreed mandate are included in our Flat Fee. Incident Response for a major incident is billed separately. Ransomware is excluded from the Incident Response covered by our Flat Fee. For this, we recommend the Halcyon add-on: it stops ransomware, secures decryption keys and includes Halcyon's Ransomware Warranty.