Managing IT security incidents organizationally
First organizational steps for roles, situation report, communication, evidence and restart in the event of a suspected IT security incident.
- For whom
- Management, IT, information security, data protection and communication in small and medium-sized companies.
- When to use it
- Immediately upon a suspected incident and in parallel with expert technical analysis.
In the event of a suspected IT security incident, what counts is calm, a named operations management, a secure situation report, coordinated technical measures, documented decisions and timely checked reporting and communication obligations.
Download PDFLeadership and accessibility
A small group capable of acting is better than many parallel individual decisions.
Situation report and evidence
Early observations and timing are crucial later for technology, duties and communication.
Coordinate containment
Emergency technical measures must limit damage without unnecessarily jeopardizing evidence or recovery.
Reporting and communication
Unverified statements create additional harm. However, deadlines should not be overlooked.
Restart and follow-up
A system is not trustworthy simply because it can be accessed again.
Result of the joint review
- A named operational management and clear roles
- A continuous situation report with a timeline
- Coordinated technical and communication decisions
- A tested restart with follow-up
Sources and professional basis
This working aid translates general recommendations into a compact initial review. The primary sources and your specific context remain decisive.
Frequently asked questions
Should an affected system be switched off immediately?
Not across the board. A shutdown can limit damage, but it can also affect evidence, availability or recovery. The decision should be made based on the specific situation and, if possible, with expert incident response support.
Does this list replace an incident response plan?
No. She helps with the initial organization. Responsibilities, contacts, technical measures and reporting channels should be planned and practiced before an incident.
Browser checkmarks are not stored or transmitted to sudo/PORT.