June 2026 · 6 min read
What advising 25+ security teams taught me about incident response
For the past several years I've worked as a cybersecurity advisor for managed detection & response customers — which means I've had a seat at the table for incident response across more than 25 organizations at once. Different industries, different sizes, different maturity levels, same alerts firing at 2 a.m.
That vantage point teaches you something a single SOC seat can't: you see the same incident play out twenty-five different ways. Same initial access vector, same malware family — wildly different outcomes. The teams that recover in hours and the teams that recover in weeks aren't separated by budget or headcount nearly as often as you'd think. Here's what actually separates them.
1. The first hour is decided before the incident starts
When an MDR analyst escalates a critical finding, the clock starts. The fast teams already know who picks up, who can approve isolating a host, and what the comms channel is. The slow teams spend the first hour figuring out those three things — while the attacker spends it moving laterally.
If your incident response plan can't answer "who can authorize containment at 2 a.m. on a Saturday?" in one line, it isn't a plan yet. It's a document.
You don't need a 40-page playbook. You need a one-page decision tree that's been tested once. Tabletop exercises feel like theater until the day they aren't.
2. Name an incident commander — even in a three-person shop
The most common failure mode I see isn't technical. It's five capable people doing overlapping work while nobody owns the timeline. Evidence gets stepped on, the same host gets reimaged twice, and leadership gets three conflicting updates.
One person runs the incident. They don't have to be the most technical person in the room — they have to be the person who decides, delegates, and communicates. Everyone else works a lane.
3. Preserve before you purge
The instinct when you find a compromised host is to make the bad thing go away: wipe it, reset the account, move on. I've watched that instinct destroy the only evidence that would have answered the question executives ask next — "how did they get in, and are they still here?"
Isolate, don't obliterate. Capture volatile data, preserve logs, snapshot before reimaging. Containment and preservation aren't in tension if the order of operations is decided ahead of time.
4. Communicate on a cadence, not on demand
During an active incident, silence gets filled with anxiety — and anxious executives start pulling responders into status meetings, which slows the response, which creates more silence. The fix is almost embarrassingly simple: commit to an update rhythm ("next update at 4:00, even if nothing changed") and keep it. The teams that do this buy their responders uninterrupted working time. The teams that don't end up with a VP in the war room.
5. Vulnerability noise is a liability during an incident
Working both detection & response and vulnerability management, I see the connection constantly: the teams drowning in 80,000 unranked vulnerabilities are the same teams that can't tell, mid-incident, whether the exploited CVE was on their radar. Risk-ranked, asset-aware vulnerability management isn't a compliance exercise — it's pre-positioned incident context. "Is this exposed? Is it exploitable? What else looks like it?" should take minutes to answer, not days.
6. Maturity is built in the review, not the incident
The single best predictor of how a team handles their next incident is what they did after their last one. Not the size of the post-mortem doc — whether the three most painful gaps got an owner and a deadline. The monthly and quarterly reviews I run with security leaders are where that accountability lives: we look at what fired, what we missed, what the metrics say, and what changed since last quarter. Boring, consistent, compounding.
The uncomfortable summary
None of this requires a bigger budget. A one-page decision tree, a named commander, an evidence-first containment habit, a comms cadence, ranked vulnerabilities, and an honest review loop — that's the difference between hours and weeks. The tooling matters, but I've watched under-resourced teams with good habits outperform well-funded teams without them, over and over.
If you're building or rebuilding an IR program and want a second set of eyes, my inbox is open.