Process family

Security incident response process: phishing report to breach notification

The security incident response family: phishing report, severity classification, SOC response, escalation to the CISO, the organizational response and GDPR breach notification, with HIPAA, vulnerability and risk acceptance alongside.

Security incident response is what happens between an alert and a closed incident. A reported email or a confirmed alert is triaged to a verdict, given a severity, contained and eradicated by the SOC, escalated as far up the organization as that severity demands, and, if personal data was exposed, tested against the 72-hour clock. The six templates in the sequence are those handoffs, drawn as swimlanes because each one changes hands.

The most common entry point is a user report. The phishing response loop examines the headers, links and attachments, searches the tenant for every other copy, purges them, blocks the sender, URLs and hashes, then asks what the affected user did: credentials entered means a password reset and session revocation, an attachment opened means the host is isolated and scanned, and signs of account compromise leave the loop and escalate to incident response. Severity classification then fixes one agreed level, P1 to P4, from availability, scope, business impact and data exposure, and that level decides everything after it.

The SOC runs the technical lifecycle: declare and assign a commander, authorize any containment that will disrupt services, isolate, preserve forensic images, hunt for further footholds, remove malware and persistence, rebuild from clean backups, tune the detection rules at the end. In parallel, the escalation ladder decides how far up the organization the incident travels: an S1/S2 threshold that keeps S3/S4 tickets inside the SOC queue, the incident manager, the CISO for an S1, the crisis team, a personal-data check, and the decision to notify the regulator, law enforcement, customers and the insurer.

The organizational response template holds the whole shape, detection to lessons learned, in one chart for the people outside the SOC. Where personal data was exposed, data breach response takes that branch: contain, assess the risk to individuals, notify the supervisory authority within 72 hours or document why not, notify individuals if the risk is high, update the breach register; unsecured PHI follows the HIPAA variant instead. The usual failures: a severity assigned by whoever is on shift, containment that destroys evidence a notification later needs, and a 72-hour clock nobody started because the personal-data question was never asked.

Two members sit beside the sequence. Vulnerability management is the pre-incident half of the work: authenticated scans, CVSS scoring, SLA bands, rescan before closure. Risk acceptance is the sign-off for what is not fixed: residual risk within appetite, a review date, who may sign set by the rating band. There is no standalone post-incident review template; every member ends with one. When recovery inside the service is not possible, invoking disaster recovery is its own decision with its own criteria. The plain IT version of this shape, restore and close rather than contain and notify, is IT service management; the same severity tree serves both.

The sequence

  1. Step 1: Phishing incident response process flowchart (reported email)

    Phishing incident response flowchart template: user report, SOC triage verdict, tenant-wide mail search, purge and indicator blocking, credential reset with session revocation, compromise escalation and awareness follow-up.

  2. Step 2: Incident severity classification flowchart

    An incident severity classification flowchart: a decision tree taking availability, scope, business impact and exposure tests through to P1, P2, P3 or P4.

  3. Step 3: Cybersecurity incident response process flowchart (SOC)

    Swimlane flowchart of the technical cybersecurity incident response lifecycle a SOC or CSIRT runs, from alert triage to eradication, recovery and rule tuning.

  4. Step 4: Security incident escalation process flowchart (SOC to CISO)

    Security incident escalation process flowchart template: SOC triage, an S1/S2 severity gate, incident manager and CISO ownership, the crisis team, a personal data check and external notification.

  5. Step 5: Security incident response process flowchart

    A swimlane flowchart of the security incident response process, from detection and triage through containment, eradication, breach notification and review.

  6. Step 6: Data breach response process flowchart (GDPR 72-hour clock)

    A swimlane flowchart for personal data breach response: containment, the risk-to-individuals test, the 72-hour regulator notification and the breach register.

Also part of this family

Used in these industries

Related guides

  • How to create a decision flowchart — How to create a decision flowchart: write each decision as a question, make the exits exhaustive and exclusive, state the criteria, and give every outcome an ending. With a live bug-triage example.
  • How to create a process map — How to create a process map: set the boundaries, name the roles, map the steps and decisions into lanes, then record the systems and evidence each step touches. With a live worked example.

QueryChart features for Security incident response

Related process families

More in Process families