Security Notes
Incident Response & Forensics

Incident Response Psychology — Decision-Making Under Pressure

What separates a good IR analyst from a great one is rarely technical knowledge. It is the ability to make defensible decisions under time pressure, with incomplete information, while managing fear of being wrong. This section covers the research behind how IR responders should think — and how interviewers assess that thinking.

11 min read 7 sections 5 model answers verified 2026-06

Last verified2026-06


Why "No Action" is Worse Than "Bad Action"

The intuition that you should wait until you're certain before acting is wrong in IR. Research from both emergency medicine and military decision science consistently shows that delayed action compounds damage faster than imperfect early action.

The dwell time problem

According to the Mandiant M-Trends report, the median attacker dwell time (time from initial intrusion to detection) has ranged from 24 to 200+ days across different years. Every hour of inaction after detection is an hour of continued attacker access:

Lateral movement

happens within hours of initial compromise on an unmonitored network

Data exfiltration

often begins 48–72 hours after initial access

Persistence mechanisms

multiply — the attacker creates new footholds faster than you can remove the first one

The research

Gary Klein's work on Naturalistic Decision Making (NDM) — studying firefighters, ER doctors, and military commanders — found that under time pressure, experienced decision-makers do not evaluate all options. They recognize the situation as a familiar pattern, simulate the first plausible course of action mentally, and act if it seems good enough. The trap is waiting for a plan that has no downside.

The OODA loop (Colonel John Boyd, 1970s): Observe → Orient → Decide → Act. Boyd's key insight, from studying air combat: the side that cycles through the loop faster wins, even if the individual decisions are less optimal. In IR: a faster, imperfect response beats a perfect response that arrives too late.

Practical principleIf you can identify one concrete reversible action (isolate a host, rotate a credential, block a domain), take it while you gather more information. Do not wait for a complete picture to act on the obvious.


The Mental Model of an IR Responder

Interviewers for IR roles are not testing whether you know every tool. They are assessing how you think. The expected model:

1. Crown Jewels First

Before asking "what happened?", ask "what am I protecting?"

  • Identify what data/systems a successful attack would target: credentials, customer PII, source code, financial records, infrastructure keys
  • Work backward from impact: "If the attacker wanted to cause maximum damage, what would they do next?"
  • This prevents tunnel vision on a single IoC while missing a larger campaign

2. Timeline Thinking

All IR is fundamentally a reconstruction problem. Every action leaves a timestamp somewhere. The model:

What is the earliest evidence of attacker activity?
  └→ How did they get in? (initial access vector)
     └→ What did they do immediately after? (discovery, privilege escalation)
        └→ Where did they go from there? (lateral movement)
           └→ What did they touch? (impact assessment)
              └→ What did they leave behind? (persistence)

Never jump to remediation until you've answered all five questions. Eradicating the first foothold while a backdoor persists is worse than leaving both — you've signalled to the attacker that they were detected.

3. Hypothesis-Driven, Not Tool-Driven

Weak investigators run tools and see what they find. Strong investigators form a hypothesis and look for evidence that confirms or refutes it.

Example hypothesis: "The attacker moved from the web server to the database using a service account credential."

Evidence you need:

  • Authentication logs on the database: did the service account log in from an unexpected source IP?
  • Web server process list: was there a process spawned with that account's credentials?
  • Network logs: is there lateral movement traffic matching the timing?

If you run Volatility and scroll through malfind output without a hypothesis, you will drown in data. If you run it to answer "is there injected shellcode in the memory of the process that owns this suspicious network connection?", you get an answer.

4. Scope Before Contain

The most common IR mistake made by junior analysts: containment before scoping.

  • Blocking the C2 domain before mapping all lateral movement tells the attacker they've been detected — they may destroy evidence or accelerate their mission
  • Isolating a single host before confirming the full blast radius may leave other compromised hosts communicating outbound undetected
  • Rotating a single credential before auditing all sessions leaves active attacker sessions alive

The correct order

  1. Silently observe until you understand the scope
  2. Preserve evidence (memory acquisition, log export) before touching systems
  3. Contain everything simultaneously when possible — or accept that partial containment tips the attacker off

Cognitive Biases That Kill IR Investigations

These are the documented failure modes. Knowing them lets you catch yourself.

Confirmation Bias

You find evidence of ransomware in one place and stop looking. The actual intrusion may have started six months earlier with a credential theft that is now invisible because you stopped looking once you found the "answer."

Counterexplicitly look for evidence that your hypothesis is wrong. Ask: what would I expect to see if this were not ransomware? If I don't see that, is it because it's not there or because I stopped looking?

Anchoring

The first alert sets the frame for the entire investigation. If the first alert is "malicious PowerShell on workstation," the investigation centers on that workstation. But initial access may have been through a VPN appliance six weeks earlier.

Counteralways build a timeline from the earliest evidence you can find, not the alert timestamp.

Availability Heuristic

The last incident your team handled was a business email compromise. When ambiguous indicators appear, you pattern-match to BEC. This time it's a supply chain compromise with completely different TTPs.

Counterexplicitly list alternative explanations before committing to a hypothesis. Use the MITRE ATT&CK framework to ask "what else could explain this indicator?"

Groupthink

In a war room with senior leadership watching, junior analysts defer to the senior analyst's hypothesis. Conflicting evidence gets explained away rather than investigated.

Counterexplicitly ask the most junior person for their interpretation before the senior person speaks. Assign a "devil's advocate" role to someone whose job is to argue against the current hypothesis.

Tunnel Vision / Sunk Cost

Six hours into investigating a host, you are convinced the intrusion originated there. New evidence points to a different origin, but you've invested too much time to change course.

Countertreat each new finding as if it's the first. "Given only this new evidence, what does it suggest?" Discard the framing of the prior hours and re-evaluate.


Decision-Making Framework Under Pressure

The Action Threshold

Not all decisions are equal. Before acting, classify the action:

Action typeReversible?Impact if wrongDecision threshold
Preserve memory / logsYesNoneAct immediately
Isolate a single endpointPartiallyBusiness disruption60% confidence
Block a C2 domainYes (re-enable)Tips off attacker70% confidence + full scope mapped
Rotate a credentialPartiallyMay break services70% confidence
Wipe and reimage a systemNoEvidence loss90% confidence + evidence preserved
Notify regulators (GDPR 72hr)NoLegal exposureAny confirmed breach

Irreversible actions require high confidence. Reversible actions should be taken early.

SBAR — Communication Under Pressure

From emergency medicine. Use this structure every time you brief a stakeholder or request an action:

S — Situation:    "We have a confirmed intrusion on three hosts in the finance VLAN."
B — Background:   "Initial access appears to be a phishing email received yesterday at 09:00.
                   The attacker has been in the environment for ~18 hours."
A — Assessment:   "The attacker has accessed the finance shared drive and is still active.
                   No evidence of exfiltration yet, but the window is closing."
R — Recommendation: "I recommend we isolate the three hosts and rotate the compromised
                     service account credentials within the next 30 minutes."

Brief stakeholders in SBAR order. Never lead with technical details — lead with the current state, then the assessment, then what you need.

Closed-Loop Communication

From aviation and military: when you give an instruction to another team member, they must read it back, and you must confirm.

"Block outbound connections from 10.0.1.15 to all destinations."
← "Confirming: block all outbound from 10.0.1.15."
"Confirmed."

In a stressful war room, instructions get misheard, misremembered, or not executed. Closed-loop confirms execution without wasted follow-ups.


What Interviewers Are Assessing

When an interviewer presents an IR scenario, they are evaluating these specifically:

What they're looking forWhat it looks like in practice
Structured thinkingYou name the phase you're in (identification, scoping, containment) before describing actions
Hypothesis formationYou say "my hypothesis is X because of Y; to test it I would look at Z"
PrioritisationYou identify the most time-sensitive action (scope? evidence? containment?) and say why
Awareness of tradeoffsYou articulate what you're giving up with each choice ("containing now tips them off, but waiting risks exfiltration")
Communication clarityYou explain what you'd say to the CISO and what you'd say to the sysadmin in different terms
Knowing your limitsYou know when to escalate, when to bring in legal, when to call law enforcement
ComposureYou stay methodical when they add new evidence mid-scenario (simulating a real investigation)

What they are NOT assessingwhether you know every flag of Volatility or every Splunk query syntax. Those can be looked up. Thinking under pressure cannot be outsourced to documentation.


Key Research and Frameworks

SourceRelevance
Gary Klein, Sources of Power (1998)Naturalistic Decision Making, Recognition-Primed Decision model — how experts decide under time pressure
Daniel Kahneman, Thinking, Fast and Slow (2011)System 1 vs System 2; cognitive biases; anchoring and availability heuristic
John Boyd, "Patterns of Conflict" (briefing, 1986)OODA loop — tempo advantage in adversarial situations
Mandiant M-Trends (annual)Dwell time statistics, attacker TTPs, IR case studies
NIST SP 800-61 (Computer Security Incident Handling Guide)The formal PICERL process: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned
MITRE ATT&CKAdversary behaviour taxonomy; use for hypothesis generation and gap analysis
SANS FOR508 coursePractical IR methodology; the course material codifies much of the above

Interview Questions

Q
An alert fires at 2am. You see a process making outbound connections to an unfamiliar IP. Walk me through your first 30 minutes.
Model answer

First, I don't touch the endpoint — I observe. I pull network logs to understand how long this connection has been active, whether there are other endpoints connecting to the same IP, and whether the domain has any history (passive DNS, VirusTotal). I form a hypothesis: is this C2, data exfiltration, or legitimate software phoning home? I preserve volatile evidence — I'd request a memory image of the endpoint before doing anything that might alert the attacker or terminate the process. Only after I understand the scope of potentially affected systems would I move to containment, and I'd aim to contain everything simultaneously rather than one host at a time.

Q
You contain a compromised host immediately after discovery. Your manager congratulates you. What concern do you raise?
Model answer

I'd raise that we may have acted too fast. Containing a single host before mapping lateral movement tells the attacker they've been detected — they may activate backup persistence, accelerate exfiltration, or destroy evidence on other hosts. I'd want to confirm: Did we log all current network connections from that host before isolating it? Do we know if the attacker was present on other hosts? Have we captured memory? Containment feels like progress, but if it's premature, it trades a visible threat for a hidden one.

Q
You've been investigating an incident for 6 hours and are confident it's ransomware pre-deployment. New evidence suggests the initial access was 3 months ago. How do you handle this?
Model answer

I reset the frame. The 6 hours I've spent are sunk — the new evidence changes the scope fundamentally. A 3-month dwell time means I need to find the initial access vector, understand everything the attacker has touched over those 3 months (credentials, data, systems), and assume that my initial hypothesis about scope was wrong. I'd go back to the earliest evidence I can find and rebuild the timeline from that point. The temptation is to explain away the new evidence to preserve the existing theory; that's the anchoring bias and it kills investigations.

Q
How do you communicate the status of an active incident to a non-technical CISO?
Model answer

I use SBAR: situation (what is confirmed), background (how we got here and what we've done), assessment (what the risk is right now), recommendation (what I need them to decide or approve). I lead with business impact — "customer data may be at risk" — not technical details. I give them a risk-adjusted estimate, not false certainty ("we believe with high confidence…" vs. "we know for certain…"). I tell them what we don't know yet and when I expect to have that answer. Then I stop talking and wait for their question rather than filling silence with speculation.

Q
You disagree with the incident commander's call to wait 24 hours before containment. What do you do?
Model answer

I raise it once, clearly and with reasoning: "My concern is that waiting 24 hours gives the attacker time to exfiltrate; can we at least monitor their active sessions and set a tripwire that triggers immediate containment if exfiltration starts?" If they still decide to wait, I document my concern in the incident log and ensure evidence preservation is happening in the meantime. I don't freelance — unauthorized containment actions in an active incident can destroy forensic evidence and create legal liability. The incident commander owns the call; my job is to give them the best information to make it.