

0 / 2 embers
0 / 3000 xp
click for more info
Complete a lesson to start your streak
click for more info
Still calibrating
click for more info
Not enough gems
Cost: 6 gems
1: Observability
incomplete
2: Alerts
incomplete
3: Responsible Disclosure
incomplete
4: Incident Severity and Triage
incomplete
5: Damage Control
incomplete
6: Postmortems
incomplete
7: Incident Reporting
incomplete
Back
ctrl+,
Next
ctrl+.
This lesson's interactive features are locked, please to keep using them
When an incident is active, the first thing to do is limit the damage fast. You don't need a perfect explanation, you don't need to figure out who's to blame, and you don't need to opine about how this could have been avoided. Just stop the bleeding.
Reduce the attacker's access and stop further spread, for example:
After immediate containment, avoid cleanup that destroys forensic value. Before resetting, deleting, restoring, or rebuilding anything, be sure to preserve:
Without evidence, you won't know what happened or be able to establish the incident's scope for regulators, internal teams, or affected users.
Restore anything you had to break during containment in a way that doesn't reintroduce the vulnerability. For example:
See the OWASP SCS Incident Response Handbook and NIST SP 800-61 Rev. 3 for detailed response guidance.
Bearly Secure needs a kill switch that invalidates every active session during an incident.
Add emergency session revocation to the account store.
With Bearly Secure still running, run and submit the CLI tests from the project root.