Cybersecurity Incident
Response Guide
A practical handbook for businesses on what to do before, during, and after a cyber incident — covering the full 5-stage Incident Response Life- cycle and business continuity for the modern MSP.

Before the Storm: The Importance of Preparation
- Documented procedures, roles, communication protocols
- Contact lists (internal, legal, PR, MSPs, law enforcement)
If internal resources are scarce, an outsourced security partner (like MAGN Intel) can serve as your Incident Manager and Technical Lead.
- Endpoint Detection & SIEM
- Immutable, offsite backups
- Secure remote access
Conduct tabletop exercises or breach simulations regularly.
Be aware of notification laws and know your cyber insurance terms.
Detection & Analysis
When an incident occurs, the speed and accuracy of your initial response determines how much damage is done.
- Ransom notes, locked files, blocked accounts
- Unusual traffic or antivirus alerts
Verify the alert and define the scope of the breach.
Containment
Once confirmed, prevent the threat from spreading further. Every second of delay allows attackers to move laterally and escalate their impact.

STOP THE SPREAD
- Isolate infected systems
- Disable accounts, block malicious IPs

QUARANTINE ZONE
- Quarantine infected machines

SUSTAINED DEFENCE
- Firewall reconfiguration, vulnerability patching
Eradication & Recovery
Post-Incident Analysis
Recovery restores systems. Continuity keeps your business operating while that recovery happens. Planned together, they close every gap. Planned separately, they create dangerous blind spots.
What happened? What worked and what didn't? What gaps exist in your IRP? MAGN Intel helps you formalise the post-mortem to identify patterns across your client base and deploy scalable, proactive fixes.
Refine your IRP, security posture, and controls.
Report to regulators and inform your team.
Train teams, upgrade tools, improve detection and prevention systems.


