course · beginner · 90 minutes

Who this course is for

Operations, IT, and security leads in Hong Kong SMEs who need a usable first-response playbook — not a theoretical textbook. You do not need a dedicated SOC to benefit, but you do need someone accountable for escalation.

Learning outcomes

  • Classify severity and decide when to escalate
  • Collect minimum viable evidence without destroying volatility
  • Contain common SaaS and endpoint incidents without panic shutdowns
  • Communicate with leadership using a one-page brief
  • Run a short after-action review that changes the next playbook

Module 1 — Detect and triage

Start with signals you already have: MFA fatigue alerts, impossible travel, mass failed logins, ransomware notes, and customer complaints. Ask four questions in the first fifteen minutes:

  1. What asset or tenant is affected?
  2. Is data exfiltration plausible right now?
  3. Are privileged accounts involved?
  4. Do we need external counsel, HKCERT coordination, or insurer notice?

Document the clock. Timed notes beat memory.

Module 2 — Contain without panic

Containment is controlled isolation, not random reboot. Prefer:

  • Disable compromised sessions and API keys
  • Block known-bad IPs at the edge after confirming false-positive risk
  • Quarantine endpoints via EDR, not by yanking cables from production databases
  • Preserve logs before rotating retention

Avoid irreversible wipes until evidence capture is confirmed.

Module 3 — Eradicate and recover

Remove persistence, rotate credentials, rebuild from known-good images where integrity is uncertain, and validate backups before restore. For Hong Kong organisations handling personal data, record what personal data categories were plausibly accessed — you will need that for PCPD-oriented decision making even if this course is not legal advice.

Module 4 — After-action review

Within five working days, capture:

  • Detection lag and containment lag
  • What worked in the playbook
  • What tooling or access blocked responders
  • One control improvement with an owner and date

Hong Kong operating notes

  • Keep bilingual contact trees for directors and counsel
  • Know your cloud region residency and logging retention before an incident, not during one
  • Align messaging with your membership directory claims — public trust signals matter after a breach narrative starts

Practice worksheet (member unlock)

Member tiers unlock downloadable severity cards, a one-page board brief template, and facilitator notes for a 45-minute tabletop. See membership plans.

  1. Complete the Secure-by-Design Checklist
  2. Read the latest Security Bulletins
  3. Skim Methodology if you plan a Trust Review later