1 What incident response is & why a plan matters
An incident is any event that actually or potentially harms the confidentiality, integrity or availability of systems or data — a ransomware outbreak, a phishing compromise, data exfiltration or an insider abuse. Incident response (IR) is the organised set of activities used to detect, contain, investigate and recover from such events while limiting damage and cost.
A written IR plan matters because the middle of a crisis is the worst time to invent a process. A good plan defines roles, decision authority, communication paths (including legal and PR), and escalation thresholds before they are needed. It turns panic into procedure, reduces dwell time, and produces consistent, defensible evidence handling. Speed and discipline directly lower breach cost and reputational harm.