{"id":1120,"date":"2026-09-09T11:11:45","date_gmt":"2026-09-09T11:11:45","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1120"},"modified":"2026-09-09T11:11:45","modified_gmt":"2026-09-09T11:11:45","slug":"incident-response","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/","title":{"rendered":"Incident Response"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: INCIDENT RESPONSE\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Incident response is the process an organisation follows once something has already gone wrong, from the moment an alert fires to the day the lessons are written down.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Operations<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Incident response is the structured handling of a confirmed or suspected security incident: detect it, work out what happened, stop it spreading, remove the attacker, restore service, and improve. It is a required control under SOC 2, ISO 27001, PCI DSS and every Indian regulator, and it runs against a clock, because breach notification deadlines start when you notice, not when you are ready.<\/p>\n<\/div>\n\n<p>Most teams write the plan and never run it. The gap between having a document and having a capability is where the cost of a breach actually accumulates.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">The incident response lifecycle<\/a><\/li>\n    <li><a href=\"#nist\">What changed at NIST<\/a><\/li>\n    <li><a href=\"#versus\">What incident response is not<\/a><\/li>\n    <li><a href=\"#plan\">What the plan has to contain<\/a><\/li>\n    <li><a href=\"#frameworks\">Where frameworks require it<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs incident response<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">The incident response lifecycle<\/h2>\n\n<p>Six stages, and the order matters. Skipping analysis to get to containment is how teams reimage a machine, lose the evidence, and watch the attacker return through the same door a week later. Stage 2 depends entirely on <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">detection coverage<\/a> that is already in place.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The six stages of incident response: prepare, detect, analyse, contain, eradicate and recover, then improve.\">\n  <defs><marker id=\"irA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"34\" width=\"112\" height=\"66\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"70\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">1. Prepare<\/text>\n  <text x=\"70\" y=\"79\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Plan, roles,<\/text>\n  <text x=\"70\" y=\"93\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">tooling, drills<\/text>\n  <line x1=\"130\" y1=\"67\" x2=\"148\" y2=\"67\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#irA)\"\/>\n\n  <rect x=\"154\" y=\"34\" width=\"112\" height=\"66\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"210\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">2. Detect<\/text>\n  <text x=\"210\" y=\"79\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">The clock<\/text>\n  <text x=\"210\" y=\"93\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">starts here<\/text>\n  <line x1=\"270\" y1=\"67\" x2=\"288\" y2=\"67\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#irA)\"\/>\n\n  <rect x=\"294\" y=\"34\" width=\"112\" height=\"66\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"350\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">3. Analyse<\/text>\n  <text x=\"350\" y=\"79\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Scope, severity,<\/text>\n  <text x=\"350\" y=\"93\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">evidence<\/text>\n  <line x1=\"410\" y1=\"67\" x2=\"428\" y2=\"67\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#irA)\"\/>\n\n  <rect x=\"434\" y=\"34\" width=\"112\" height=\"66\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"490\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">4. Contain<\/text>\n  <text x=\"490\" y=\"79\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">Stop the<\/text>\n  <text x=\"490\" y=\"93\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">spread<\/text>\n  <line x1=\"550\" y1=\"67\" x2=\"568\" y2=\"67\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#irA)\"\/>\n\n  <rect x=\"574\" y=\"34\" width=\"172\" height=\"66\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"660\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">5. Eradicate and recover<\/text>\n  <text x=\"660\" y=\"79\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Remove the attacker,<\/text>\n  <text x=\"660\" y=\"93\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">restore service safely<\/text>\n\n  <line x1=\"660\" y1=\"106\" x2=\"660\" y2=\"124\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <line x1=\"70\" y1=\"124\" x2=\"660\" y2=\"124\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <line x1=\"70\" y1=\"124\" x2=\"70\" y2=\"142\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#irA)\"\/>\n\n  <rect x=\"14\" y=\"150\" width=\"732\" height=\"42\" rx=\"13\" fill=\"#f0e6f3\"\/>\n  <text x=\"380\" y=\"176\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">6. Improve. Findings feed back into preparation, or the same incident happens twice.<\/text>\n\n  <rect x=\"14\" y=\"202\" width=\"732\" height=\"42\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"228\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Notification deadlines run from stage 2, not stage 5. Time spent undetected is time already spent.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"nist\" class=\"c-sage\">What changed at NIST<\/h2>\n\n<p>Almost every article on this subject still teaches the four-phase lifecycle from NIST SP 800-61 Revision 2. That document was formally withdrawn on 3 April 2025 and superseded in its entirety by Revision 3.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Revision 2, withdrawn<\/th><th>Revision 3, current<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Four discrete phases: preparation, detection and analysis, containment and eradication and recovery, post-incident activity<\/td><td>Activities distributed across the six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover<\/td><\/tr>\n    <tr><td>Incident response treated as a bounded event lasting a few days<\/td><td>Incident response treated as a continuous part of cybersecurity risk management<\/td><\/tr>\n    <tr><td>Lessons learned as a meeting at the end<\/td><td>Improvement as an ongoing activity throughout, not a closing ritual<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The practical work has not changed. What has changed is the language auditors and insurers now expect to see. If your plan cites Revision 2, it is citing a withdrawn document.<\/p>\n\n<h2 id=\"versus\" class=\"c-apri\">What incident response is not<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Term<\/th><th>Covers<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Incident response<\/strong><\/td><td>Handling a security incident, from detection through recovery and improvement<\/td><\/tr>\n    <tr><td>Disaster recovery<\/td><td>Restoring systems and data after any outage, including fire, flood and hardware failure<\/td><\/tr>\n    <tr><td>Business continuity<\/td><td>Keeping the business running while something is broken, regardless of cause<\/td><\/tr>\n    <tr><td>Crisis management<\/td><td>Board-level decision authority and external communication when an incident threatens the company itself<\/td><\/tr>\n    <tr><td>Digital forensics<\/td><td>Preserving and analysing evidence, usually invoked inside the analyse stage<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"plan\" class=\"c-plum\">What the plan has to contain<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Section<\/th><th>What it answers<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Severity classification<\/td><td>Objective tiers, so nobody argues about whether this qualifies while the clock runs<\/td><\/tr>\n    <tr><td>Roles and contacts<\/td><td>Named people with named deputies, reachable outside working hours<\/td><\/tr>\n    <tr><td>Detection sources<\/td><td>Which systems feed <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the SIEM<\/a>, and what an alert is expected to trigger<\/td><\/tr>\n    <tr><td>Containment options<\/td><td>What can be isolated, who is authorised to do it, and what breaks if they do<\/td><\/tr>\n    <tr><td>Evidence handling<\/td><td>What gets preserved before anything is wiped, and where it is stored<\/td><\/tr>\n    <tr><td>Notification matrix<\/td><td>Which regulator, which customer contract, which clock, and who signs<\/td><\/tr>\n    <tr><td>Recovery criteria<\/td><td>How you decide a system is safe to bring back, rather than merely working again<\/td><\/tr>\n    <tr><td>Exercise schedule<\/td><td>When the plan gets tested, and what evidence the test produces<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Untested is treated as unproven<\/p>\n  <p>Auditors do not ask whether an incident response plan exists. They ask for the tabletop exercise record: the scenario used, who attended, what broke, and whether the findings were closed. A plan with no exercise history is assessed as a document, not a control.<\/p>\n<\/div>\n\n<h2 id=\"frameworks\" class=\"c-sage\">Where frameworks require it<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Framework<\/th><th>Status<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-for-startups\/\">SOC 2<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Common Criteria covering evaluation of security events and a defined response programme, evidenced across the observation window<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Annex A controls for incident planning, assessment and decision, response, evidence collection and learning<\/td><\/tr>\n    <tr><td>PCI DSS<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>A documented plan, tested at least annually, covering payment card compromise specifically<\/td><\/tr>\n    <tr><td>CERT-In Directions<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Reporting of specified incident types within six hours of noticing them<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Intimation of a personal data breach to the Data Protection Board and to affected individuals<\/td><\/tr>\n    <tr><td>Cyber insurance<\/td><td><span class=\"pill p-ask\">Asked<\/span><\/td><td>Applications routinely ask whether an incident response programme aligned to NIST 800-61 is in place, and the answer affects terms<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The insurance line is the one teams forget. An incident response programme is not only an audit control. It is an underwriting input, and it is checked again at claim time.<\/p>\n\n<h2 id=\"osto\">How Osto runs incident response<\/h2>\n\n<p>The hardest part of incident response is not the plan. It is knowing an incident started. Osto covers detection by default rather than as a separate purchase. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">Correlated logging<\/a> sees endpoint, cloud, identity, application and API activity in one stack, so a sequence that looks unremarkable in four separate consoles surfaces as one alert. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">Endpoint detection<\/a> supplies the containment action, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture management<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> with regular <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">penetration testing<\/a> reduce how often the plan gets used at all.<\/p>\n\n<p>The evidence layer is purpose-built for the audit side. Detection records, retention and closure map to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, SOC 2, the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a> and Indian sectoral frameworks from one evidence set, so the same work answers an auditor, an enterprise buyer and an insurer.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">The clock starts when you notice<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto correlates endpoint, cloud, identity and application signals in one platform, so detection happens early and the evidence is already there. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Audit-ready in days &middot; SOC 2, ISO 27001 and DPDP mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is incident response?<\/summary>\n  <p>The structured process of handling a security incident: detecting it, analysing what happened and how far it reached, containing the damage, removing the attacker, restoring service safely, and feeding what you learned back into preparation. It is a required control under every major security framework.<\/p>\n<\/details>\n\n<details>\n  <summary>What are the stages of incident response?<\/summary>\n  <p>Operationally, six: prepare, detect, analyse, contain, eradicate and recover, and improve. NIST SP 800-61 Revision 3 now maps these activities to the six functions of the Cybersecurity Framework 2.0 rather than presenting them as a standalone lifecycle, but the order of work during a real incident is unchanged.<\/p>\n<\/details>\n\n<details>\n  <summary>Is the four-phase NIST incident response lifecycle still current?<\/summary>\n  <p>No. NIST withdrew SP 800-61 Revision 2 on 3 April 2025 and superseded it entirely with Revision 3, which restructures incident response around Govern, Identify, Protect, Detect, Respond and Recover. Plans that cite Revision 2 should be updated to reference Revision 3.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between incident response and disaster recovery?<\/summary>\n  <p>Incident response deals with a security event: an attacker, a compromise, a data exposure. Disaster recovery deals with restoring systems and data after any disruption, including outages with no attacker involved. An incident often triggers disaster recovery, but they answer different questions.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should an incident response plan be tested?<\/summary>\n  <p>At least annually, and after any material change to systems or team. Testing means a tabletop exercise or simulation with a recorded scenario, participants, findings and closure evidence. Auditors and insurers both treat an untested plan as an unproven one.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Email Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Incident response is the process an organisation follows once something has already gone wrong, from the moment an alert fires\u2026<\/p>\n","protected":false},"author":8,"featured_media":1121,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[526,527],"class_list":["post-1120","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-incident-response","tag-incident-response-plan"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1120"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1120\/revisions"}],"predecessor-version":[{"id":1122,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1120\/revisions\/1122"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1121"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}