Intermediate Vocabulary #collocations #security #incident-response

Incident Response Collocations

5 exercises on the language of handling security incidents — the verbs and named artefacts that drive runbooks, SOC procedures, and post-mortems.

Key patterns in this set
  • contain a breach — stop it spreading (NIST phase)
  • triage an incident — rapidly prioritise by severity
  • escalate an incident — raise to higher responders/leadership
  • post-incident review — blameless after-the-fact analysis
  • isolate a host → eradicate the threat → hunt IOCs
0 / 5 completed
1 / 5
An incident-response runbook reads:

"The first priority is to ___ the breach — stop it spreading to other systems and limit the damage — before we even think about clean-up."

Which verb is the standard collocation for limiting the spread of a breach?