home  /  incident response & forensics  /  response adequacy
the response · cybersecurity incidents

Response adequacy.

The completed timeline always looks slow. The question is what was reasonable at each point along it.

begin here

What happened, and when did you learn of it?

Start a conversation with the Incident Concierge, already scoped to response adequacy. Pick a starting point, or describe the incident directly.

Incident Conciergeresponse adequacy · orientation, not a security opinion
Tell me when it was detected, when it was contained, and what was done to establish scope. Those intervals are what an adequacy analysis actually examines — and scope is where most responses are criticized.

Response adequacy is the second front in most breach disputes, and it is separate from the standard-of-care question: an organization with reasonable safeguards can still respond badly, and an organization with weak safeguards can respond well enough to substantially limit the harm. The analysis runs across four stages — detection, containment, scope investigation and notification — and asks at each whether what was done was reasonable given what was known at that moment. That last qualification is where most arguments actually happen, because a reconstructed timeline makes every delay look inexplicable. The single most common substantive criticism is not slowness at all: it is containing what was found without establishing what else the attacker reached, which produces a second discovery later that is invariably worse than the first.

mechanisms

The four stages, and what each is judged on.

Each is assessed against what was known then, not against the finished picture.

Detection

Whether the intrusion was found in a reasonable time given the monitoring in place, and how it was found.

Containment

Whether isolation followed within a reasonable period of detection, and whether it was complete.

Scope investigation

Whether the organization established what else was reached. The most common failure.

Notification

Whether obligations to regulators, individuals and partners were met on their own clocks.

Escalation and governance

Whether the right people were told, when, and whether the decisions were recorded.

Remediation and recurrence

Whether the root cause was actually fixed, or only the symptom that was found.

methodology

What the evidence shows — and what we examine.

How adequacy is assessed.

Build the knowledge timelineNot what happened, but what the organization knew and when. They are different documents.
Compare to the planWhether there was a response plan and whether it was followed. Departures need reasons.
Measure the intervalsDetection to containment, containment to scope, scope to notification. Each is separately assessed.
Test the scope workWhether the investigation looked beyond the initially discovered systems.
what's at stake

What adequacy decides.

Frequently the size of the harm rather than whether harm occurred.

how far the harm was allowed to run a second and separate negligence theory regulatory exposure on notification coverage and cooperation conditions officer and director exposure whether recurrence was foreseeable

The failure is usually scope, not speed.

Containing what you found while never establishing what else was reached produces a second discovery weeks later. That second announcement damages an organization far more than the first, and it is the criticism that lands hardest in litigation.

common questions

Response adequacy — practical questions.

How fast is fast enough?

There is no fixed number, and anyone offering one should be treated cautiously. Adequacy is assessed against what was known and what was reasonably achievable with the resources and information available, so a delay while an organization legitimately worked out whether an alert was real is different from a delay caused by nobody looking. Notification obligations are the exception: those run on defined statutory clocks that vary by jurisdiction and regime, they can be short, and they are a legal question for counsel rather than a matter of reasonableness.

We used our insurer’s panel responder. Does that protect us?

It helps, and it is not a complete answer. Using an experienced panel firm is evidence of a reasonable response and is often a coverage condition worth honouring. But the organization remains responsible for its own decisions — what it authorised, what it declined, how quickly it escalated, and what it did with what it was told. Panel reports are also frequently critical of the client's environment, and that report is likely to be sought in later litigation, so it is worth knowing what it says early.

What does a good response look like in the record?

Documented decisions with reasons and timestamps. The organizations that come through this well are not the ones that got everything right; they are the ones that can show what they knew, what they decided, who decided it and why, at each stage. That record converts a series of judgment calls into a defensible narrative. Its absence forces reconstruction from logs and recollection months later, which reliably makes reasonable decisions look arbitrary.

Does a bad response matter if the security was reasonable?

Yes, and defendants sometimes miss this. They are separate theories: reasonable safeguards may defeat the pre-incident negligence claim while an inadequate response supports an independent one, particularly where a faster or wider containment would have limited what was exfiltrated. Response failures also tend to be more legible to a factfinder than security architecture, because delay and incomplete investigation are easier to grasp than segmentation.

related

Related specialization areas & resources.

Build the knowledge timeline.

Describe the response so far. The Institute will help you see how adequacy would be assessed.

incident conciergeorientation · not a security opinion
Tell me when it was detected, when it was contained, and what was done to establish scope. Those intervals are what an adequacy analysis actually examines — and scope is where most responses are criticized.