1. Detection & reporting

2. Initial assessment

3. Mobilize the team

Incident Commander: Coordinates response, makes decisions, communicates status

Technical Lead: Directs investigation and remediation efforts

Communications Lead: Handles internal and external communications

Support Lead: Interfaces with affected users and support team

4. Investigation & mitigation

5. Resolution & verification