Security Incident Response
Spot a live breach in the SOC and escalate it to the DPO.
What Is Security Incident Response?
Not every security incident is a data breach, but every data breach starts as one, and telling them apart quickly is the skill here. As a SOC analyst you see a brute-forced admin login followed by an export of 50,000 customer records to an outside server. You acknowledge both alerts, find the missing MFA that let the attacker in, confirm personal data has left, trigger incident response so the Data Protection Officer can notify the regulator, and document the full timeline.
What You'll Learn in Security Incident Response
- Triage a security incident to determine whether personal data has been accessed, exfiltrated, or compromised
- Recognise when the 72-hour Article 33 clock starts, and why awareness does not wait for the investigation
- Assess whether a breach is likely to result in a risk, or a high risk, to the people whose data was taken
- Escalate a confirmed breach to the incident response team and the DPO without delay
- Document an incident timeline and the response actions taken, as Article 33(5) requires
Security Incident Response — Training Steps
-
Introduction
Today's training will teach you about GDPR-compliant incident response - how to assess security events, determine breach notification requirements, and trigger the right procedures when personal data may be compromised.
-
Starting Your Shift
Alice begins her morning shift at the Security Operations Center (SOC). The dashboard shows normal activity levels - a few routine alerts that have already been triaged by the overnight team. SecureNet Financial handles payment processing for hundreds of enterprise clients. The SOC monitors for unauthorized access, data exfiltration, policy violations, and other security events around the clock.
-
High-Severity Alert
Suddenly, a high-severity alert appears on the dashboard. The SIEM has detected unusual login attempts - multiple failed authentication attempts followed by a successful login from a foreign IP address. The alert indicates the account belongs to a system administrator with elevated privileges. This could be a brute-force attack that succeeded in compromising credentials.
-
Analyzing the Login Alert
The alert details reveal concerning information: Account : sysadmin_jsmith (System Administrator) Source IP : 185.220.101.45 (Eastern Europe) Failed attempts : 47 over 3 hours Successful login : 06:47 AM local time Session duration : 1 hour 37 minutes (still active) The legitimate account owner, John Smith, is currently on vacation in Spain - but the login originated from a different country entirely.
-
Second Alert Appears
While reviewing the login alert, a second alert appears - medium severity. The Data Loss Prevention (DLP) system has flagged a large data export request. Someone used the compromised sysadmin account to export customer records from the production database. The export completed before the automated systems could block it.
-
The Scope of the Breach
The data export alert reveals the extent of potential damage: Records exported : 50,000 customer records Data types : Full names, email addresses, phone numbers, financial account numbers, transaction history Export destination : External FTP server (IP: 185.220.101.89) Time of export : 07:15 AM local time This is no longer just a security event - personal data has been exfiltrated to an external server controlled by unknown parties.
-
Acknowledging the Alerts
Alice needs to acknowledge both alerts to indicate they are under active investigation. This creates an audit trail showing when the SOC became aware of the potential breach. Under GDPR, the organization is considered 'aware' of a breach when the SOC identifies an incident involving personal data - not when the investigation concludes.
-
Acknowledging the Data Export Alert
The unauthorized access has been marked as acknowledged. Now Alice needs to acknowledge the data export alert as well. With both alerts acknowledged, there is a clear timestamp showing when SecureNet Financial became aware of the potential breach involving personal data.
-
Checking Compliance Status
Before escalating the incident, Alice checks the compliance dashboard to understand the organization's current security posture. This context helps determine what controls may have failed. Understanding existing compliance gaps can help explain how the breach occurred and what mitigations should be prioritized.
-
Identifying the Vulnerability
The compliance dashboard reveals a critical issue: Consent Management : Compliant DSAR Response Time : Compliant Data Encryption : Compliant MFA Enforcement : Warning - 23% of admin accounts lack MFA Data Retention : Compliant The compromised sysadmin account was one of the 23% without Multi-Factor Authentication enabled. This security gap allowed the attacker to gain access using only stolen credentials.
Security Framework Coverage
CIS Controls
- CIS 3 Data Protection
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.DS Data Security
GDPR
- Art. 32 Security of processing
- Art. 33 Notification of a personal data breach to the supervisory authority