Who this course is for
Operations, IT, and security leads in Hong Kong SMEs who need a usable first-response playbook — not a theoretical textbook. You do not need a dedicated SOC to benefit, but you do need someone accountable for escalation.
Learning outcomes
- Classify severity and decide when to escalate
- Collect minimum viable evidence without destroying volatility
- Contain common SaaS and endpoint incidents without panic shutdowns
- Communicate with leadership using a one-page brief
- Run a short after-action review that changes the next playbook
Module 1 — Detect and triage
Start with signals you already have: MFA fatigue alerts, impossible travel, mass failed logins, ransomware notes, and customer complaints. Ask four questions in the first fifteen minutes:
- What asset or tenant is affected?
- Is data exfiltration plausible right now?
- Are privileged accounts involved?
- Do we need external counsel, HKCERT coordination, or insurer notice?
Document the clock. Timed notes beat memory.
Module 2 — Contain without panic
Containment is controlled isolation, not random reboot. Prefer:
- Disable compromised sessions and API keys
- Block known-bad IPs at the edge after confirming false-positive risk
- Quarantine endpoints via EDR, not by yanking cables from production databases
- Preserve logs before rotating retention
Avoid irreversible wipes until evidence capture is confirmed.
Module 3 — Eradicate and recover
Remove persistence, rotate credentials, rebuild from known-good images where integrity is uncertain, and validate backups before restore. For Hong Kong organisations handling personal data, record what personal data categories were plausibly accessed — you will need that for PCPD-oriented decision making even if this course is not legal advice.
Module 4 — After-action review
Within five working days, capture:
- Detection lag and containment lag
- What worked in the playbook
- What tooling or access blocked responders
- One control improvement with an owner and date
Hong Kong operating notes
- Keep bilingual contact trees for directors and counsel
- Know your cloud region residency and logging retention before an incident, not during one
- Align messaging with your membership directory claims — public trust signals matter after a breach narrative starts
Practice worksheet (member unlock)
Member tiers unlock downloadable severity cards, a one-page board brief template, and facilitator notes for a 45-minute tabletop. See membership plans.
Recommended next steps
- Complete the Secure-by-Design Checklist
- Read the latest Security Bulletins
- Skim Methodology if you plan a Trust Review later