The technical work is only half of an incident. The other half is running it. This course follows the full lifecycle: preparation, detection and analysis, containment, eradication, recovery, and the lessons learned review that most teams skip. You will build a response plan, define severity levels that trigger the right people, and practise the decisions that matter under time pressure, including when containment costs more than the intrusion. Investigation work covers log aggregation and SIEM queries, threat hunting against a hypothesis, and correlating host, network, and identity evidence into one narrative. Communication is treated as a core skill: stakeholder updates, regulatory notification timelines, and a final report that is accurate and readable. A full simulated ransomware incident runs across the final module.