Roles in a Response
What is it?
A working response separates roles: the Incident Commander owns decisions and communication flow; analysts/responders own investigation and technical actions; a scribe owns the record; stakeholders (IT, legal, management, affected business owners) are informed on a defined cadence.
Why it matters
In an unstructured response everyone investigates and nobody decides — or worse, three people 'contain' the same host three different ways.
Where you see it
The first fifteen minutes of a declared incident, when the commander is named and the channel is opened.
What normal looks like
One named commander per incident, one live record, decisions logged with who/when/why, and stakeholders updated on schedule instead of by rumor.
What suspicious looks like
Executives calling individual analysts directly for updates, and actions happening that no one can attribute to a decision.
How analysts investigate
By routing findings to the commander and the record — not into private chats — so the response has one shared, current picture.
Common beginner mistakes
- Confusing 'commander' with 'most senior engineer' — command is a coordination role; the best analyst is usually more valuable analyzing than commanding.
When Marasi declares its incident, the IT lead names a commander, opens one response channel, and assigns one person to keep the record. Nothing about the attacker changed — but the defense just got twice as effective.
- Incident Commander — decides, sequences actions, owns communication cadence.
- Responders/Analysts — investigate, execute approved actions, report findings to the record.
- Scribe — timestamps decisions, actions and findings while they happen.
- Stakeholders — informed on a cadence; they do not direct technical actions mid-incident.
Quick check
Mid-incident, a Marasi executive messages an analyst directly: 'skip the imaging, just wipe the laptop, we need it back'. What is the correct move?
A quick self-check — it doesn't affect your XP or progress.
Sign in to save your progress on the server.