+31 (0)88 88 321 88
V Skill HF-D7.6-005 sector-specific 10 skills

Security incident response

Acts on a security incident following the runbook by containing it, preserving evidence, recovering and informing the right parties in time.

How hrmforce measures this

Assessment method
Simulation
hrmforce instrument
Knowledge test (client-specific), Work sample test
Competency (50-framework)
Stress resilience
Trainability
medium
Demand outlook 2026 to 2030
rising

Simulated work situation, usually digital, with standardised scoring.

Behavioural anchors

LevelBehaviour at this level
N1 Guided Reports a suspected incident immediately, touches nothing and follows the coordinator's instructions.
works under supervision and follows instruction · routine, one variable at a time · own task
N3 Proficient Independently limits damage during an incident, preserves evidence and delivers a traceable timeline of events.
sets own approach and seeks input proactively · several variables, some ambiguity · own team or process
N5 Leading Leads the organisation wide response team, decides on external communication and improves the runbook after every exercise.
sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession

N2 and N4 are deliberately not anchored. Raters place them between the anchors, following the O*NET convention.

Underlying skills

These skills inherit the assessment route and the behavioural anchors of this construct.

TSkillDefinitionDemand outlook 2026 to 2030
V Executing an incident response plan
Incident response
Acts on a security incident according to the runbook and records roles, decisions and timestamps. rising
T Using a SIEM
SIEM
Searches and correlates events in a siem, configures detection rules and assesses generated alerts. rising
V Performing SOC triage
SOC triage · Alert triage
Assesses incoming alerts for authenticity and urgency, enriches them with context and escalates or closes them. rising
V Containing a compromise
Containment
Isolates affected systems and accounts quickly so an attacker cannot move further through the network. rising
V Preserving evidence
Evidence preservation
Preserves log files, disk images and timelines so they remain usable for investigation or prosecution. rising
V Conducting forensic investigation
Digital forensics
Reconstructs from traces on systems and in log files what an attacker did and when. rising
V Recovering from ransomware
Ransomware recovery
Restores systems from clean backups, checks for remaining access and determines the order of resumption. rising
V Notifying a regulator of a security incident
Regulatory notification
Determines which notification duties apply, files the report within the deadline and tracks follow up. rising
V Running a crisis exercise
Tabletop exercise
Organises an exercise with a realistic scenario, measures team behaviour and records improvement points. rising
V Using threat intelligence
Threat intelligence
Uses information on current attack techniques and indicators to adjust detection and measures. rising
Free demo