Incident response is how you react to a security incident and limit the damage. This video covers the key steps, including forensic analysis of what happened.
Incident response is the plan your team follows when something goes wrong, so that the damage stays small and the evidence stays intact for later analysis.
Incidents are not rare events reserved for large companies; smaller organizations are targeted precisely because their response is slower. The difference between a bad day and a serious loss is usually how quickly someone competent notices and acts. Round-the-clock detection through managed cybersecurity services is how most small teams get that speed.