Security Incident Response
Detection, scoping, containment and notification clocks.
5 to work through
-
intermediate
At 09:00 a customer reports that a report they exported contains another customer's records. You have the on-call. Walk me through your first hour, and tell me what architectural question you would ask on day two.
3 min answer -
advanced
A blockchain infrastructure provider suspects a compromised credential with access to production. What must the response prioritise, and what capability determines how well it goes?
2 min answer -
advanced
A platform discovers that an attacker has held valid credentials for an unknown period. What does the response require beyond containment, and what determines how well it goes?
2 min answer -
advanced
Anomalous access to a customer database is detected. Walk me through the first day, and say what determines whether you can answer the regulator.
2 min answer -
advanced
You discover an attacker holds valid credentials in your environment. What are your first three actions and what must already exist for them to be possible?
2 min answer
3 terms in this topic
Containment vs Eradication
Stopping an attacker's ongoing access versus removing their foothold entirely — sequential phases with different urgency and different risks of doing…
metricDwell Time
The period between an attacker gaining access and being detected — the metric that determines how much damage an intrusion can do.
practiceSecurity Incident Response
Responding to a compromise — where the architecture determines whether you can detect it, contain it, and prove what happened.
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.