· Chris Tappin · Incident Response · 5 min read
A New Model of Incident Response
There are only three steps, and you've likely already memorised them. Incidents are a time to stop, collaborate and listen.

Photo by Jan Antonin Kolar on Unsplash
Problem Statement
Harried SOC analysts and overwhelmed CISOs need a simple, memorable model to follow in a crisis. In the same way that the strongest passwords are the passwords you can’t remember, perhaps the easiest model to remember is one you already memorised in the 90s.
Prior Art
This is not a brand new invention. In 1990, Van Winkle posited the original three step process as general lifestyle guidance. 34 years later, Tappin shoehorned in the Incident Response content, and a model was born.
The Van Winkle / Tappin model
Let’s kick it!
-Robert Matthew Van Winkle
Stop
Don’t panic
Are you about to make things worse? Don’t isolate systems without a way of regaining access to them yourself. I’ve personally worked on incidents where people have:
- pulled the power cable rather than network cable on physical PCs and lost critical evidence in memory.
- deleted compromised containers without securing key information first.
- entirely removed virtual network adapters rather than isolating the VMs.
Each of these decisions either caused crucial data to be lost or significantly delayed the evidence collection process.
Refer to your documentation
If you’re not sure what to do in a given situation, consult your IR plan and playbooks. If you do know what to do, document that in your IR plan or playbooks for your colleagues. You may be humming the bass line from Under Pressure now, but will you be able to perform under pressure during an incident? It’s important to have clear documentation to refer back to in such stressful situations.
Collaborate
Who is taking which role in the response?
Colleagues, existing contractors and specialists you engage all need to be tasked and their progress tracked. Often organisations don’t like to let go of this incident management role, but your Incident Response partner are likely more experienced in this area. Consider naming them as incident commander and instructing the other parties to take instruction from them.
How best can you chat and share files?
If you want to use your existing Teams, how quickly can you onboard guests? If your infrastructure may be compromised, how quickly can you stand up out of band communications? Good IR providers will be able to set up (for example) a Slack channel within minutes.
How often is too often to meet?
Meet too infrequently and people won’t have the latest info. Meet too regularly and there won’t be time to do anything between meetings. Demanding hourly updates on progress leaves the people doing the work no time between delivering the update and preparing the next one. Try to give people at least 4 hours between calls, with the understanding that anything urgent will be raised immediately.
Listen
…to the incident commander
Who’s in charge of the incident? It shouldn’t automatically be the most senior person in the room. If you aren’t comfortable leading the investigation, ask a supplier to manage it for you. Effective organisations facing large incidents will have a technical/operational group and a strategic/leadership group with separate update processes and someone acting as a conduit for information between the two.
Welcome bad news
Empower your team to deliver hard news and not fear the response. I’ve worked on cases where there were two updates scheduled, the main call and a preview. It became apparent that the preview call’s sole function was to tell a junior executive what we were going to tell his boss in the following call, so that he had extra time to think of excuses. If your team are afraid of you, they may be introducing inefficiencies to the IR process.
Don’t point fingers
There will be ample time in the after-action review to document lessons learned. Try to remove emotion from the IR process wherever possible. I’ve seen the carrot work much better than the stick as a motivation.
An orchestra only needs one conductor
A good IR consultant will slot into the role in which they can best add value at the time. Every so often, my team and I end up working on an incident with several people from another leading IR firm. Occasionally clients will think that we are bitter rivals who will race to complete all outstanding tasks ourselves, whereas the best thing for the client is that we divide up the work to complete the investigation sooner. Usually, the generalist security providers are the least used to the collaborative approach this requires.
Conclusion
Although based on an American framework, the Van Winkle / Tappin model was developed in Sydney, and is therefore as Australian as democracy sausages or claiming to have invented WiFi.
Opportunities for further research
This author suggests that the artistic works of 1990 may have further lessons to teach the Information Security community of today. The work of Burrell may be of specific interest to those in the field of Operation Technology space, especially when seeking a clear and succinct statement regarding safety in hazardous environments.
About the author: Chris Tappin is the Managing Director of 5∩6, a Digital Forensics and Incident Response consultancy in Sydney, Australia.



