Security incident response
Acts on a security incident following the runbook by containing it, preserving evidence, recovering and informing the right parties in time.
How hrmforce measures this
- Assessment method
- Simulation
- hrmforce instrument
- Knowledge test (client-specific), Work sample test
- Competency (50-framework)
- Stress resilience
- Trainability
- medium
- Demand outlook 2026 to 2030
- rising
Simulated work situation, usually digital, with standardised scoring.
Behavioural anchors
| Level | Behaviour at this level |
|---|---|
| N1 Guided | Reports a suspected incident immediately, touches nothing and follows the coordinator's instructions. works under supervision and follows instruction · routine, one variable at a time · own task |
| N3 Proficient | Independently limits damage during an incident, preserves evidence and delivers a traceable timeline of events. sets own approach and seeks input proactively · several variables, some ambiguity · own team or process |
| N5 Leading | Leads the organisation wide response team, decides on external communication and improves the runbook after every exercise. sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession |
N2 and N4 are deliberately not anchored. Raters place them between the anchors, following the O*NET convention.
Underlying skills
These skills inherit the assessment route and the behavioural anchors of this construct.
| T | Skill | Definition | Demand outlook 2026 to 2030 |
|---|---|---|---|
| V | Executing an incident response plan Incident response | Acts on a security incident according to the runbook and records roles, decisions and timestamps. | rising |
| T | Using a SIEM SIEM | Searches and correlates events in a siem, configures detection rules and assesses generated alerts. | rising |
| V | Performing SOC triage SOC triage · Alert triage | Assesses incoming alerts for authenticity and urgency, enriches them with context and escalates or closes them. | rising |
| V | Containing a compromise Containment | Isolates affected systems and accounts quickly so an attacker cannot move further through the network. | rising |
| V | Preserving evidence Evidence preservation | Preserves log files, disk images and timelines so they remain usable for investigation or prosecution. | rising |
| V | Conducting forensic investigation Digital forensics | Reconstructs from traces on systems and in log files what an attacker did and when. | rising |
| V | Recovering from ransomware Ransomware recovery | Restores systems from clean backups, checks for remaining access and determines the order of resumption. | rising |
| V | Notifying a regulator of a security incident Regulatory notification | Determines which notification duties apply, files the report within the deadline and tracks follow up. | rising |
| V | Running a crisis exercise Tabletop exercise | Organises an exercise with a realistic scenario, measures team behaviour and records improvement points. | rising |
| V | Using threat intelligence Threat intelligence | Uses information on current attack techniques and indicators to adjust detection and measures. | rising |