Cybersecurity Incident Response

How to Contain, Eradicate, and Recover from Incidents

  • Eric C. Thompson

Table of contents

  1. Front Matter
    Pages i-xv
  2. Eric C. Thompson
    Pages 1-10
  3. Eric C. Thompson
    Pages 11-16
  4. Eric C. Thompson
    Pages 17-46
  5. Eric C. Thompson
    Pages 47-64
  6. Eric C. Thompson
    Pages 65-70
  7. Eric C. Thompson
    Pages 71-85
  8. Eric C. Thompson
    Pages 87-98
  9. Eric C. Thompson
    Pages 99-116
  10. Eric C. Thompson
    Pages 117-123
  11. Eric C. Thompson
    Pages 137-149
  12. Eric C. Thompson
    Pages 151-159
  13. Back Matter
    Pages 161-176

About this book


Create, maintain, and manage a continual cybersecurity incident response program using the practical steps presented in this book. Don't allow your cybersecurity incident responses (IR) to fall short of the mark due to lack of planning, preparation, leadership, and management support.

Surviving an incident, or a breach, requires the best response possible. This book provides practical guidance for the containment, eradication, and recovery from cybersecurity events and incidents.

The book takes the approach that incident response should be a continual program. Leaders must understand the organizational environment, the strengths and weaknesses of the program and team, and how to strategically respond. Successful behaviors and actions required for each phase of incident response are explored in the book. Straight from NIST 800-61, these actions include:

  • Planning and practicing
  • Detection
  • Containment
  • Eradication
  • Post-incident actions

What You’ll Learn:

  • Know the sub-categories of the NIST Cybersecurity Framework
  • Understand the components of incident response
  • Go beyond the incident response plan
  • Turn the plan into a program that needs vision, leadership, and culture to make it successful
  • Be effective in your role on the incident response team


Cybersecurity Cyber Cyber Attack Breach Containment Incident Response Incident Management Disaster Recovery Cyber forensics Malware Ransomware Phishing Dark Web Tor

Authors and affiliations

  • Eric C. Thompson
    • 1
  1. 1.LisleUSA

Bibliographic information