{"id":25916,"date":"2020-05-11T13:51:00","date_gmt":"2020-05-11T13:51:00","guid":{"rendered":"https:\/\/kepner-tregoe.com\/the-essential-guide-to-incident-response\/"},"modified":"2026-05-28T14:46:51","modified_gmt":"2026-05-28T14:46:51","slug":"the-essential-guide-to-incident-response","status":"publish","type":"post","link":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/","title":{"rendered":"The Essential Guide to Incident Response"},"content":{"rendered":"<p>Sometimes it helps to go back to the basics. Such as reminding ourselves of the point of incident response (IR). The answer is simple: to keep the business running. But that simplicity is deceptive. This is an incredibly heavy responsibility, as you know if anything has ever gone wrong in your ability to respond to a major incident. <a href=\"https:\/\/blogs.gartner.com\/andrew-lerner\/2014\/07\/16\/the-cost-of-downtime\/\" target=\"_blank\" rel=\"noopener\">According to Gartner<\/a>, every minute that your systems are down cost on average $5,600, adding up to more than $300,000 per hour. That\u2019s a lot of money, and a. lot of pressure.<\/p>\n<p>At KT, we put our collective heads together and came up with seven best practices for ensuring the success of your IR program. They include some operational, some technical, some organizational suggestions, but all of them contribute to building a first-class IR team.<\/p>\n<h3>Why Incident Response?<\/h3>\n<p>ITIL describes an incident as any interruption or disturbance to normal IT services. We can make it more personal to your business, and say than an incident is any circumstance in which a system acts in a way that negatively impacts your customers. It doesn\u2019t have to be an outright system crash. Take a slow-performing email system. Does that constitute an incident? Using our definition, you bet it does, as slow emails mean slower response to customer service enquiries, delayed reactions to requests for proposals (RFPs), slowed product development, and just about every activity your business engages in for profit.<\/p>\n<p>IR is your process for responding to these incidents (and incidents are different from problems, which we will discuss later). Successful IR\u2014which means that it\u2019s both fast and effective\u2014results in improved worker and process efficiency, higher productivity, and, ultimately, higher revenues for the business. It really is a mission-critical operation.<\/p>\n<h3>7 best practices for superb incident response<\/h3>\n<p>Here are eight best practices that will fine-tune your IR team to make it top-performing.<\/p>\n<h4>1. Communicate, communicate, communicate<\/h4>\n<p>There has historically been a communication chasm between IT and the rest of the organization\u2014particularly between IT and users. This raises problems when attempting to deliver great IR, because many, if not most, of your incidents will be reported by your users. They must have an easy way to do this reporting, so you hear about incidents as soon as possible. Then you have to keep them informed in real-time as you resolve the incident. All this is necessary to gain their trust so they will work more closely with you\u2014a collaboration that is essential\u2014in future incidents. For starters, open up multiple channels to let users raise tickets easily. For example, they should be able to alert the IR team via email, chat, a portal, or an enterprise social network like Yammer. You should also create self-service mechanisms so users can solve the easy incidents.\u00a0 Make self-service easily accessible and educate users about the benefits of self-help and using the knowledge base to resolve issues on their own.<\/p>\n<p>Then, as the IR team works on fixing the incident, it\u2019s essential to keep everyone apprised of progress in real-time. There are two pieces of information that should be prominently displayed at all times: the incident status (current resolution state, including estimated time of completion), and the priority of the incident (how important it is to resolve the incident relative to other incidents.<\/p>\n<p>Automation can help, by sending automatic updates throughout the lifecycle of major incidents. Clear and visible notifications will also prevent users from raising duplicate tickets and overloading the help desk. Even if there\u2019s nothing to report, tell your stakeholders that, on an hourly or half-hourly basis. And have a dedicated line to respond to major incidents immediately and offer support to anyone affected.<\/p>\n<h4>2. Adopt DevOps Processes<\/h4>\n<p>Before DevOps became mainstream, the IR team was basically in it for themselves. They, rather than the people who had actually built the systems, were responsible for all incidents. There was no feedback loop to the developers on how to fix repetitive interruptions to a particular application, for example. There was very little communication at all between the people who built the systems, and the ones responsible for fixing them when things went wrong. Indeed, one reason that DevOps was created was to eliminate these organizational silos. This is essential because of the complexity of today\u2019s systems\u2014they are all interconnected, and what affects one is likely to affect others.<\/p>\n<p>With a DevOps structure in place, developers do a better job in building their systems, because they now know they must also support them\u2014no more throwing problems over the wall for another group to worry about. IR teams have support, and, typically\u2014if DevOps is done right\u2014clear documentation of how to keep complex systems up and running.<\/p>\n<h4>3. Sense when to \u201cswarm\u201d<\/h4>\n<p>Although most businesses have a \u201ctiered\u201d structure for dealing with incidents\u2014Tier 1 is the help desk, Tier 2 involves application specialists, and Tier 3 are generally the system uber-experts and developers\u2014you don\u2019t want to universally enforce this structure when solving major incidents. You want to give your team the freedom to \u201cswarm\u201d when necessary.<\/p>\n<p>This usually is necessary when an issue has a huge business impact. In such cases, you want to deviate from normal tiered IR processes. Swarming replaces that structure with a model of networked collaboration. \u00a0It originated at Cisco, which wrote about it in its 2008 white paper, \u201c<a href=\"https:\/\/s3.amazonaws.com\/connected_republic\/attachments\/4\/Digital_Swarming_EB_0812c_FINAL.pdf\" target=\"_blank\" rel=\"noopener\">Digital Swarming<\/a>.\u201d The concept was subsequently adopted by the Consortium for Service Innovation, and developed into a vision entitled \u201c<a href=\"https:\/\/www.serviceinnovation.org\/intelligent-swarming\/\" target=\"_blank\" rel=\"noopener\">Intelligent Swarming<\/a>..\u201d<\/p>\n<p>The general idea behind swarming is that instead of escalation, you bring everyone who might be able to help solve an incident into the IR team at the same time. There they brainstorm and bounce ideas off each other, and in general use the group dynamic to come up with fresh and innovative solutions to difficult IR issues.<\/p>\n<p>Core principles of swarming include:<\/p>\n<ul>\n<li>The \u201ctiers\u201d of support are eliminated<\/li>\n<li>There is no escalation from one group to another\u2014everyone who needs to be on the team is there from the beginning<\/li>\n<li>The case should be given directly to the person or persons most likely to be able to resolve it<\/li>\n<li>The person who takes the case is the one who sees it through to resolution.<\/li>\n<\/ul>\n<h4>4. Implement a Don\u2019t-Let-It-Happen-Again policy<\/h4>\n<p>You should also take care not to be putting out the same fires over and over again. This means knowing the difference between IR and problem management. IR takes care of getting things back to normal, even if that means only a temporary fix. Problem management is when you find out the root cause of the incident, and fix it.<\/p>\n<p>Note that you can never eliminate incidents from occurring, that isn\u2019t realistic. However, you can avoid having to provide fixes to the same problem repeatedly by effective problem management.<\/p>\n<h4>5. Get the problem statement and priority right<\/h4>\n<p>Probably the single most important thing you can do is understand and articulate what the incident involves. This is called incident classification, but you need to go behind putting the incident into some basic category to specifying the problem statement extremely accurately and precisely. This should include such parameters as the system(s) impacted, the geographic location, how many internal users are impacted, and what the specific impact on business operations is.<\/p>\n<p>Only when you have a clear problem statement can you set priorities. Proper classification helps in better troubleshooting and improving the resolution time. Then, prioritization ensures that the most business-critical issues are addressed first.<\/p>\n<h4>6. Encourage a no-blame culture<\/h4>\n<p>This is essential. Rather than looking to point fingers if something goes wrong\u2014either in the IR response itself, or in the underlying issue with a system\u2014consider simply focusing on the problem, and on finding the true root cause, whatever that might be. Having a \u201cblame-and-shame\u201d culture does you no good, and can even slow down IR response because people are so afraid of making mistakes.<\/p>\n<h4>7. Set the right KPIs and improve them<\/h4>\n<p>Key performance indicators (KPIs) are incredibly important because they measure how you\u2019re doing, and give you a quantitative yardstick to use to see if you are improving. However, be careful about your KPIs. Some give false ideas of how well your IR team is performing and can cause you to prioritize the wrong things. For example, first call resolution (FCR), a common metric, measures how many incidents can be resolved with the first call. But sometimes that results in hasty decisions and actions when service quality is more important.<\/p>\n<p>Therefore, set up realistic metrics and measure them for constant improvement. Here are some suggested KPIs to track:<\/p>\n<ul>\n<li>Incident volume (per issue category, priority, status, requester, etc.)<\/li>\n<li>Mean time to resolution<\/li>\n<li>Mean time to respond<\/li>\n<li>SLA %<\/li>\n<li>Incidents resolved without escalation<\/li>\n<li>Average cost per Incident<\/li>\n<li>Incident reopen rate<\/li>\n<\/ul>\n<h4>Conclusion: Benefits of effective incident management<\/h4>\n<p>We all know the results of poor IR\u2014the business suffers. Alternatively, the benefits of doing IR right are manifold. You have smooth business operations. You achieve Improved efficiency and productivity within IT team as well as the organization. You have much higher user satisfaction as you maintain your SLAs. And, as you get better at IR, you can begin proactively identifying and preventing major incidents from occurring by spotting potential major incidents before they\u2019re reported by users or customers. That\u2019s a big win-win-win.<\/p>\n<h4>About Kepner-Tregoe<\/h4>\n<p>Kepner-Tregoe has been the industry leader in problem-solving and service-excellence processes for more than 60 years. The experts at KT have helped companies raise their level of incident- and problem-management performance through tools, training and consulting \u2013 leading to highly effective service-management teams ready to respond to your company\u2019s most critical issues.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sometimes it helps to go back to the basics. Such as reminding ourselves of the point of incident response (IR). The answer is simple: to keep the business running. But that simplicity is deceptive. This is an incredibly heavy responsibility, as you know if anything has ever gone wrong in your ability to respond to [&hellip;]<\/p>\n","protected":false},"author":48,"featured_media":556,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[28],"tags":[],"ppma_author":[83],"class_list":["post-25916","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-incident-response"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.7 (Yoast SEO v27.7) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The Essential Guide to Incident Response - Kepner-Tregoe<\/title>\n<meta name=\"description\" content=\"The results of poor Incident Response is plain and simple - the business suffers. Alternatively, the benefits of doing it right are manifold. You have smooth business operations; much higher user satisfaction and you start being able to spot potential major incidents before they\u2019re reported by customers. That\u2019s where the gold is.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/\" \/>\n<meta property=\"og:locale\" content=\"nl_NL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Essential Guide to Incident Response\" \/>\n<meta property=\"og:description\" content=\"The results of poor Incident Response is plain and simple - the business suffers. Alternatively, the benefits of doing it right are manifold. You have smooth business operations; much higher user satisfaction and you start being able to spot potential major incidents before they\u2019re reported by customers. That\u2019s where the gold is.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/\" \/>\n<meta property=\"og:site_name\" content=\"Kepner-Tregoe\" \/>\n<meta property=\"article:published_time\" content=\"2020-05-11T13:51:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-28T14:46:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/IT-MIN.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"573\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christoph Goldenstern\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/\"},\"author\":{\"name\":\"\",\"@id\":\"\"},\"headline\":\"The Essential Guide to Incident Response\",\"datePublished\":\"2020-05-11T13:51:00+00:00\",\"dateModified\":\"2026-05-28T14:46:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/\"},\"wordCount\":1609,\"publisher\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kepner-tregoe.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/IT-MIN.jpg\",\"articleSection\":[\"Incident Response\"],\"inLanguage\":\"nl-NL\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/\",\"url\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/\",\"name\":\"The Essential Guide to Incident Response - Kepner-Tregoe\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kepner-tregoe.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/IT-MIN.jpg\",\"datePublished\":\"2020-05-11T13:51:00+00:00\",\"dateModified\":\"2026-05-28T14:46:51+00:00\",\"description\":\"The results of poor Incident Response is plain and simple - the business suffers. Alternatively, the benefits of doing it right are manifold. You have smooth business operations; much higher user satisfaction and you start being able to spot potential major incidents before they\u2019re reported by customers. That\u2019s where the gold is.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/#breadcrumb\"},\"inLanguage\":\"nl-NL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"nl-NL\",\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kepner-tregoe.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/IT-MIN.jpg\",\"contentUrl\":\"https:\\\/\\\/kepner-tregoe.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/IT-MIN.jpg\",\"width\":1200,\"height\":573},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/blogs\\\/the-essential-guide-to-incident-response\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Essential Guide to Incident Response\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/#website\",\"url\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/\",\"name\":\"Kepner-Tregoe\",\"description\":\"Problem solving &amp; critical thinking training\",\"publisher\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"nl-NL\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/#organization\",\"name\":\"Kepner-Tregoe\",\"url\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"nl-NL\",\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/kepner-tregoe.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/kepner-tregoe-logo.png\",\"contentUrl\":\"https:\\\/\\\/kepner-tregoe.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/kepner-tregoe-logo.png\",\"width\":264,\"height\":38,\"caption\":\"Kepner-Tregoe\"},\"image\":{\"@id\":\"https:\\\/\\\/kepner-tregoe.com\\\/nl\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/14495\"]},{\"@type\":\"Person\",\"@id\":\"\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Essential Guide to Incident Response - Kepner-Tregoe","description":"The results of poor Incident Response is plain and simple - the business suffers. Alternatively, the benefits of doing it right are manifold. You have smooth business operations; much higher user satisfaction and you start being able to spot potential major incidents before they\u2019re reported by customers. That\u2019s where the gold is.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/","og_locale":"nl_NL","og_type":"article","og_title":"The Essential Guide to Incident Response","og_description":"The results of poor Incident Response is plain and simple - the business suffers. Alternatively, the benefits of doing it right are manifold. You have smooth business operations; much higher user satisfaction and you start being able to spot potential major incidents before they\u2019re reported by customers. That\u2019s where the gold is.","og_url":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/","og_site_name":"Kepner-Tregoe","article_published_time":"2020-05-11T13:51:00+00:00","article_modified_time":"2026-05-28T14:46:51+00:00","og_image":[{"width":1200,"height":573,"url":"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/IT-MIN.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christoph Goldenstern","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/#article","isPartOf":{"@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/"},"author":{"name":"","@id":""},"headline":"The Essential Guide to Incident Response","datePublished":"2020-05-11T13:51:00+00:00","dateModified":"2026-05-28T14:46:51+00:00","mainEntityOfPage":{"@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/"},"wordCount":1609,"publisher":{"@id":"https:\/\/kepner-tregoe.com\/nl\/#organization"},"image":{"@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/#primaryimage"},"thumbnailUrl":"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/IT-MIN.jpg","articleSection":["Incident Response"],"inLanguage":"nl-NL"},{"@type":"WebPage","@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/","url":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/","name":"The Essential Guide to Incident Response - Kepner-Tregoe","isPartOf":{"@id":"https:\/\/kepner-tregoe.com\/nl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/#primaryimage"},"image":{"@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/#primaryimage"},"thumbnailUrl":"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/IT-MIN.jpg","datePublished":"2020-05-11T13:51:00+00:00","dateModified":"2026-05-28T14:46:51+00:00","description":"The results of poor Incident Response is plain and simple - the business suffers. Alternatively, the benefits of doing it right are manifold. You have smooth business operations; much higher user satisfaction and you start being able to spot potential major incidents before they\u2019re reported by customers. That\u2019s where the gold is.","breadcrumb":{"@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/#breadcrumb"},"inLanguage":"nl-NL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/"]}]},{"@type":"ImageObject","inLanguage":"nl-NL","@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/#primaryimage","url":"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/IT-MIN.jpg","contentUrl":"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/IT-MIN.jpg","width":1200,"height":573},{"@type":"BreadcrumbList","@id":"https:\/\/kepner-tregoe.com\/nl\/blogs\/the-essential-guide-to-incident-response\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kepner-tregoe.com\/nl\/"},{"@type":"ListItem","position":2,"name":"The Essential Guide to Incident Response"}]},{"@type":"WebSite","@id":"https:\/\/kepner-tregoe.com\/nl\/#website","url":"https:\/\/kepner-tregoe.com\/nl\/","name":"Kepner-Tregoe","description":"Problem solving &amp; critical thinking training","publisher":{"@id":"https:\/\/kepner-tregoe.com\/nl\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kepner-tregoe.com\/nl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"nl-NL"},{"@type":"Organization","@id":"https:\/\/kepner-tregoe.com\/nl\/#organization","name":"Kepner-Tregoe","url":"https:\/\/kepner-tregoe.com\/nl\/","logo":{"@type":"ImageObject","inLanguage":"nl-NL","@id":"https:\/\/kepner-tregoe.com\/nl\/#\/schema\/logo\/image\/","url":"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/kepner-tregoe-logo.png","contentUrl":"https:\/\/kepner-tregoe.com\/wp-content\/uploads\/2025\/06\/kepner-tregoe-logo.png","width":264,"height":38,"caption":"Kepner-Tregoe"},"image":{"@id":"https:\/\/kepner-tregoe.com\/nl\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/14495"]},{"@type":"Person","@id":""}]}},"authors":[{"term_id":83,"user_id":48,"is_guest":0,"slug":null,"display_name":"Christoph Goldenstern","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/1b037e061b1a8187503257c5dba944a54217f726b4db40289ef31b704339feab?s=96&d=mm&r=g","0":null,"1":"","2":"","3":"","4":"","5":"","6":"","7":"","8":""}],"_links":{"self":[{"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/posts\/25916","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/comments?post=25916"}],"version-history":[{"count":1,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/posts\/25916\/revisions"}],"predecessor-version":[{"id":28382,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/posts\/25916\/revisions\/28382"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/media\/556"}],"wp:attachment":[{"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/media?parent=25916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/categories?post=25916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/tags?post=25916"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/kepner-tregoe.com\/nl\/wp-json\/wp\/v2\/ppma_author?post=25916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}