Cybersecurity › Module 6 › Lesson 5
Incident Response
From first minutes to full personal IR loop
Opening
Assume breach — then respond with a plan
Prevention fails sometimes. Incident Response (IR) is what you do next so a bad hour does not become a ruined year. You do not need a corporate SOC to learn the personal version. Align with the NIST-style lifecycle used by professionals — Prepare → Detect → Contain → Eradicate → Recover → Lessons Learned — and keep a pocket card for the first five minutes when adrenaline spikes.
1. Prepare (before anything breaks)
IR starts on a calm day. Prepare means: know your clean devices for password resets, know where off-site backups live (your 3-2-1), save bank fraud and workplace IT numbers offline, enable MFA on email, and write a one-page plan. Panic invents nothing useful; preparation does.
Also decide roles for household or small team: who isolates devices, who calls the bank, who touches restores. Ambiguity wastes the golden first minutes.
2. Detect (notice something is wrong)
Detection is recognizing signals: ransom screen, unexpected MFA prompts, unknown login alerts, files renaming themselves, antivirus warnings, or a friend saying "your account messaged me." Do not argue with reality. Name it: suspected malware, account takeover, or ransomware — then move.
3. Contain (stop the bleeding)
Containment limits damage. On a personal device: disconnect Wi-Fi / unplug Ethernet immediately if you suspect malware or ransomware. That cuts remote control and lateral spread. Stop using the suspect device for any logins. Photograph the screen for notes if needed — then step away.
Personal device
Disconnect first. Prefer isolation over random deletion sprees that destroy evidence you may need.
Work device
Disconnect if safe to do so, then notify IT. Do not panic-wipe without guidance — they may need forensics.
4. Eradicate (remove the cause)
Eradication means the attacker foothold is gone: trusted malware scan, or wipe and reinstall the OS for severe cases. Reset critical passwords and revoke sessions from a different clean phone/computer. Resetting on the infected machine can hand malware the new secrets (keyloggers and stealers).
5. Recover (return to safe operations)
Recovery restores what you need from known-good backups — never from mystery "decryptor" promises. Bring systems back carefully: patch first if a vulnerability was the door, re-enable MFA, confirm bank and email session lists look sane, then resume normal use. Availability returns only after you trust the rebuild.
6. Lessons Learned (close the door)
Post-incident learning is not optional fluff. Write five lines: what happened, when, what you clicked, what failed (phishing, reuse, missing MFA, unpatched app, no backup). Fix that root cause. Update the IR card. Share the lesson with family or teammates so the same door does not reopen tomorrow.
7. Wrong vs right: ransomware popup
Worked failure — red encrypting screen:
Wrong
Stay online bargaining with the attacker, pay immediately from the infected PC, and change banking passwords on that same machine while malware is live. Skip any review afterward.
Right
Contain: disconnect now. Eradicate/secure: use a clean device to reset accounts. Recover: restore from clean backups. Lessons Learned: note the entry point and harden it. Do not trust criminal promises.
8. Practical: personal IR card
Personal IR loop + first-minutes card
# NIST-style personal loop Prepare → Detect → Contain → Eradicate → Recover → Lessons Learned # IF malware / ransomware / account takeover suspected: 1. CONTAIN — DISCONNECT Wi-Fi / unplug cable 2. STOP using the suspect device for logins 3. From a CLEAN phone/PC (Eradicate / secure access): - Change email password + MFA - Change banking / payment passwords - Sign out other sessions where available 4. Notify bank / workplace IT if relevant 5. RECOVER — restore files only from verified clean backups 6. LESSONS LEARNED — write 5 lines: what / when / clicked / gap / fix # Prepare checklist (do on a calm day) - List two clean devices for resets - Know backup location (3-2-1) - Save fraud / IT numbers offline - One-page IR plan in a drawer or secure note # Do NOT - Enter new passwords on the infected machine - Pay ransoms as your first plan - Post incident details publicly while investigating
Mission: write your full personal IR plan
1) On paper or a secure note, map Prepare → Detect → Contain → Eradicate → Recover → Lessons Learned with one concrete action under each phase. 2) List two clean devices you could use for password resets. 3) List who you would call (bank fraud line / workplace IT / family). 4) Confirm you know where your off-site backup lives.
Stuck? Ask Cyberlium AI Mentor
Ask: "Hint only: order the IR phases after I spot ransomware" or "Hint only: why reset passwords from a different device after malware?" Do not ask for offensive malware samples — keep the focus on containment and recovery.
Calm containment beats chaos — and a full loop beats a one-hour panic. Next — the Module 6 quiz — applies patches, backups, physical security, AI scams, and IR together.
Knowledge Check
APPLY: You open a file and a ransom screen appears while files encrypt. Which phase and action come first?
Multiple choice
Knowledge Check
APPLY: Which activity best matches the Prepare phase of personal IR?
Multiple choice
Knowledge Check
APPLY: After you restore from clean backups, skipping Lessons Learned means…
Multiple choice