CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
πŸŒ™β˜€οΈ
Log inStart free
Home/Templates/Cybersecurity

πŸ” Cybersecurity Β· Flowchart

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

More Cybersecurity templates

Drawing diagram…

What this diagram shows

  • Alerts are triaged by severity before anyone is paged
  • Containment comes before root-cause work
  • Every incident ends with a post-incident review

Prompt used

Incident response flowchart (NIST): an alert arrives from the SIEM or EDR, the SOC analyst triages it; false positives are closed and the detection rule tuned. Real incidents get a severity (P1 to P3); P1 pages the incident commander and informs leadership. The team contains the threat (isolate hosts, disable accounts), collects evidence, eradicates it, recovers systems from clean backups, monitors for recurrence, notifies regulators if data was exposed, and holds a post-incident review.

Mermaid code
flowchart TD
  A[Alert from SIEM / EDR] --> B[SOC analyst triage]
  B --> C{Real incident?}
  C -->|No| D[Close, tune detection rule]
  C -->|Yes| E[Assign severity P1-P3]
  E -->|P1| F[Page incident commander, inform leadership]
  E -->|P2 / P3| G[Assign to on-call responder]
  F --> H[Contain: isolate hosts, disable accounts]
  G --> H
  H --> I[Collect evidence]
  I --> J[Eradicate: remove malware, patch]
  J --> K[Recover from clean backups]
  K --> L{Personal data exposed?}
  L -->|Yes| M[Notify regulator and affected users]
  L -->|No| N[Monitor for recurrence]
  M --> N
  N --> O[Post-incident review and lessons learned]

Related templates

C4 ArchitectureProCybersecurity

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

Data FlowCybersecurity

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

SequenceCybersecurity

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.

State MachineCybersecurity

Vulnerability Management Lifecycle

The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.