> For the complete documentation index, see [llms.txt](https://docs.cybaops.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cybaops.com/modules/detect-and-respond-mdr/responding-to-an-incident-ticket.md).

# Responding to an Incident Ticket

### <mark style="color:$primary;">How to Respond to an Incident Ticket in CybaOps</mark>

When a security incident is detected, CybaOps provides a single place to track the investigation, communicate with analysts, review evidence, and understand what actions have been taken. It is designed to provide complete transparency throughout the incident lifecycle, ensuring you always have visibility into what happened, what is being investigated, and what requires your attention.

Whether you're a **CybaEdge** or **CybaOne** customer, understanding how incidents progress through the platform will help you get the most value from the service and ensure incidents are resolved as quickly as possible.

***

#### <mark style="color:$primary;">Understanding Incident Statuses</mark>

Every incident moves through a series of statuses as it progresses from detection to resolution.

#### <mark style="color:$primary;">New</mark>

A new incident has been created and is awaiting initial review.

At this stage:

* A detection has triggered an incident or an incident has been created manually - *make sure you review the* [*Ticket Creation*](/modules/detect-and-respond-mdr/ticket-creation.md) *doc*
* Initial context and evidence are being collected.
* The assigned team will begin triage activities.

#### <mark style="color:$primary;">Progressing</mark>

The incident is actively being investigated.

During this stage, analysts may:

* Review evidence and artefacts.
* Identify affected users, devices, or assets.
* Determine the scope and impact.
* Document findings and recommendations.

#### <mark style="color:$primary;">Pending</mark>

The investigation is waiting for information, approval, or action from your organisation.

Common examples include:

* Confirming whether activity is legitimate.
* Approving a containment action.
* Providing business context.
* Completing remediation activities.

When an incident is in this state, an email notification is triggered to all Admins within the tenancy. Responding promptly helps the SOC continue the investigation with minimal delay.

{% hint style="info" %}
Review the [Communicating Through Comments](#communicating-through-incident-comments) section for more information on this
{% endhint %}

#### <mark style="color:$primary;">Resolved</mark>

The investigation has been completed and the incident is closed.

The final record will typically contain:

* What happened.
* How it happened.
* Actions that were taken.
* Recommendations to help prevent a similar incident in future.

***

### <mark style="color:$primary;">Understanding the Timeline</mark>

*<mark style="color:$primary;">CybaOne customers only</mark>*

The timeline is the most important area of an incident.

Every action, comment, note, status change, artefact update and investigation activity is recorded with a timestamp, creating a complete audit trail of the investigation. This allows everyone involved to view the full history of the incident and understand exactly how it has been handled.&#x20;

<figure><picture><source srcset="/files/vCJDHVJ4yLkuA29J0Rnn" media="(prefers-color-scheme: dark)"><img src="/files/kTWQvxb05Odss1AuhgIm" alt=""></picture><figcaption></figcaption></figure>

#### <mark style="color:$primary;">How to Use the Timeline</mark>

When reviewing an incident:

1. Start with the original detection to understand what triggered the alert.
2. Follow the investigation chronologically to review evidence and analyst findings.
3. Review any actions already taken or recommendations provided.
4. Review any comments that require a response.
5. Use it to monitor updates until the incident is resolved.

The timeline provides a clear record answering four key questions:

* What happened?
* How did it happen?
* What actions were taken?
* How can it be prevented in the future?&#x20;

> **Best Practice:** Always review the latest timeline entry before responding to an incident. This will usually tell you exactly what information or action is required.

***

### <mark style="color:$primary;">Communicating Through Incident Comments</mark>

CybaOps is designed to keep incident communication within the case itself. This ensures discussions, decisions and evidence remain attached to the investigation and visible to everyone involved.

#### <mark style="color:$primary;">When Should You Add a Comment?</mark>

Comments can be used to:

* Confirm whether activity is legitimate.
* Answer questions from the SOC.
* Provide business context about a user, device or application.
* Confirm remediation has been completed.
* Ask questions about the investigation.
* Share additional evidence or findings.

All comments become part of the permanent investigation record and are visible within the incident timeline.

***

#### <mark style="color:$primary;">Comments Update the Status of an Incident</mark>

When adding a comment there are two options,&#x20;

<br>

This helps both parties understand who owns the next action.

#### Pending Customer

The SOC is waiting for your organisation to respond.

Examples include:

* Additional information is required.
* Approval is needed before containment actions can proceed.
* An internal IT team needs to carry out remediation.
* The SOC requires confirmation before continuing.

#### Pending SOC

The customer has responded and the case is back with the SOC for review and further investigation.

Examples include:

* You have answered a question.
* You have supplied additional evidence.
* You have confirmed remediation has been completed.
* Approval for a response action has been provided.

#### What Happens When You Add a Comment?

If an incident is marked as **Pending Customer**, adding a comment:

* Notifies the SOC that new information has been provided.
* Updates the incident timeline.
* Returns the investigation to the analyst for review.
* Helps move the case forward without requiring separate email communication.

For this reason, it's always recommended that incident-related updates are provided directly within the case whenever possible.

> **Tip:** An incident may still show a status of **In Progress**, but if it is marked **Pending Customer**, the next action is with your organisation. Reviewing the latest timeline entry will explain what is required.

***

## Responding as a CybaEdge Customer

CybaEdge customers benefit from:

* 24/7 SOC monitoring.
* Threat Hunting.
* ITDR Premium.
* Unlimited Incident Response support. [\[CybaEdge Unpacked | PDF\]](https://olsconsulting.sharepoint.com/sites/SalesMarketing/Shared%20Documents/Marketing/Content%20&%20Collateral/Marketing%20for%20Team/CybaVerse%20Packages%20-%20Suitable%20for%20MSP%20and%20Resellers/CybaEdge%20Unpacked.pdf?web=1), [\[Incident R...unlimited) | PDF\]](https://olsconsulting.sharepoint.com/sites/SalesMarketing/Shared%20Documents/Sales/Marketing%20Materials/New%20Bolt-Ons/Incident%20Response%20\(unlimited\).pdf?web=1)

When an incident is raised:

1. Open the incident and review the summary.
2. Check the timeline for investigation activity.
3. Respond to any requests for information.
4. Complete any recommended actions.
5. Monitor updates until the incident is resolved.

CybaEdge provides unlimited access to incident response support, ensuring investigations can continue without concerns around support hour limitations. [\[Incident R...unlimited) | PDF\]](https://olsconsulting.sharepoint.com/sites/SalesMarketing/Shared%20Documents/Sales/Marketing%20Materials/New%20Bolt-Ons/Incident%20Response%20\(unlimited\).pdf?web=1)

***

## Responding as a CybaOne Customer

CybaOne provides the most collaborative incident management experience within CybaOps.

In addition to operational visibility, incidents become shared workspaces where customers and analysts can collaborate throughout the investigation lifecycle. CybaOne includes advanced case management capabilities, allowing customers to actively participate in investigations. [\[CybaOne Unpacked | PDF\]](https://olsconsulting.sharepoint.com/sites/SalesMarketing/Shared%20Documents/Marketing/Content%20&%20Collateral/TIEVA/Marketing%20Materials/CybaOne%20Unpacked.pdf?web=1), [\[Master fil...CybaVerse | Word\]](https://olsconsulting-my.sharepoint.com/personal/o_spence_cybaverse_co_uk/_layouts/15/Doc.aspx?sourcedoc=%7B2C2BF7D1-0819-4E12-B19E-5DD3499B488E%7D\&file=Master%20file%20on%20CybaVerse.docx\&action=default\&mobileredirect=true\&DefaultItemOpen=1)

CybaOne customers can:

* Add comments.
* Review investigation activity.
* Track tasks.
* Monitor ownership and status changes.
* Collaborate directly with analysts. [\[Master fil...CybaVerse | Word\]](https://olsconsulting-my.sharepoint.com/personal/o_spence_cybaverse_co_uk/_layouts/15/Doc.aspx?sourcedoc=%7B2C2BF7D1-0819-4E12-B19E-5DD3499B488E%7D\&file=Master%20file%20on%20CybaVerse.docx\&action=default\&mobileredirect=true\&DefaultItemOpen=1), [\[CybaOne Unpacked | PDF\]](https://olsconsulting.sharepoint.com/sites/SalesMarketing/Shared%20Documents/Marketing/Content%20&%20Collateral/TIEVA/Marketing%20Materials/CybaOne%20Unpacked.pdf?web=1)

To get the most value from CybaOne:

* Review incidents regularly.
* Monitor timeline updates.
* Provide business context early.
* Respond quickly when information is requested.
* Use comments to keep all communication within the case.

***

## Responding to a P1 (Critical) Incident

A P1 incident represents a critical security event that requires immediate attention.

Examples may include:

* Confirmed compromise.
* Active malicious activity.
* Significant business impact.
* High-risk security threats.

#### What You Should Do

**1. Open the Incident Immediately**

Review:

* The incident summary.
* The latest timeline entries.
* Recommended actions.

**2. Follow Escalation Communications**

The CybaVerse SOC will follow the agreed escalation process and contact the individuals defined during onboarding and within your escalation matrix. [\[CybaVerse...C - Call 1 | Meeting\]](https://teams.microsoft.com/l/meeting/details?eventId=AAMkAGNmZDhjYjRjLWExZWMtNGM1OS05YTUwLWIyYzZlZTc1NjE4ZABGAAAAAAAQJNervmCbRoczNq1WiuaaBwBfd2a09OIQRp8uK3G5WDAsAAAAAAENAABfd2a09OIQRp8uK3G5WDAsAALSVaQ3AAA%3d), [\[Onboarding...'s clients | Word\]](https://olsconsulting.sharepoint.com/sites/Delivery/_layouts/15/Doc.aspx?sourcedoc=%7B9F402FCB-F2C9-4823-82A1-D9B37BEA3F05%7D\&file=Onboarding%20process%20-MSP%27s%20clients.docx\&action=default\&mobileredirect=true\&DefaultItemOpen=1)

**3. Respond Quickly**

If information, approval or action is requested, provide a response as quickly as possible to support containment and investigation activities.

**4. Monitor the Timeline**

Use the timeline to track:

* Investigation progress.
* Analyst updates.
* Containment actions.
* Recommendations.
* Customer responses.

**5. Remain Engaged Until Resolution**

Even after the immediate threat has been contained, continue monitoring the incident until it reaches a resolved state. Review the final findings and recommendations to reduce the likelihood of future incidents.

***

### Best Practices

To get the maximum value from CybaOps incident management:

✅ Use the timeline as your primary source of truth.

✅ Keep incident-related communication within the case.

✅ Respond promptly when an incident is marked as **Pending Customer**.

✅ Review analyst recommendations carefully.

✅ Regularly check the latest timeline activity rather than relying solely on email notifications.

✅ Review resolved incidents and corrective actions to improve your organisation's security posture.

Remember, the timeline is more than an activity log. It is the complete investigation record, providing full visibility into what happened, how it happened, what actions were taken, and what can be done to prevent similar incidents in the future.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cybaops.com/modules/detect-and-respond-mdr/responding-to-an-incident-ticket.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
