Incident Response: The Manager's Role

About this module

Managers do not need to repair an incident themselves. They need to keep the response calm, fast, and clean. This module explains the first-hour manager role during events such as ransomware, suspicious device behavior, or compromised accounts. Learners see why disconnecting a device can help, while shutting it down or poking around can destroy evidence. The lesson also covers escalation, team communication, and documentation. A manager's first job is to contain, report, preserve, and avoid speculation.

Key takeaways

  • Managers should contain and escalate incidents, not investigate alone
  • Disconnecting a suspicious device can help stop spread
  • Shutting down or changing files can destroy useful evidence
  • The first hour affects cost, containment, and recovery

Full Transcript

You don't need to be a security expert to lead your team through a cybersecurity incident. You need to be fast, calm, and know exactly what to do in the first sixty minutes. It's nine fourteen in the morning. A teammate messages you: something feels wrong on my computer. That message is where incident response actually begins.

Priya messages you: her screen just froze, and her file names are turning into random letters. She asks if she should restart her laptop. What do you tell her to do first? Here's what a manager does: disconnect Priya's laptop from the network, but don't shut it down or try to fix it yourself. Then notify I.T. or security immediately, before doing anything else.

Studies show the first sixty minutes decide how contained or costly a breach becomes. Every minute Priya's laptop stays connected, the risk spreads further across the network. In the first five minutes, contain the threat: disconnect the device, but don't shut it down. By minute fifteen, notify I.T. or security. By minute thirty, preserve evidence — don't wipe or reinstall anything.

And within the hour, brief your team on what to say, and what not to say. Here's the trap: trying to quietly fix it yourself, or deleting files to, quote, clean up, feels responsible. It isn't. It destroys the evidence investigators need, and it delays the real response by hours. Two ways this hour can go.

Panic response: freeze up, hide the problem, or try to fix it solo — and hope no one notices. Or, the manager's response: contain the threat, report it fast, and communicate clearly with your team. One of these protects your company. The other makes the incident worse. As one incident response lead puts it: in the first hour, speed matters more than expertise.

You don't have to know how to fix it. You have to know who to call. When an incident hits, remember four moves: contain the device, report it to I.T. or security, preserve the evidence, and communicate clearly with your team. You now know how to lead the first hour of an incident.

Next, we'll look at cybersecurity budget basics — what managers need to know about funding this fight before disaster strikes.