Skip to main content
← BlogCybersecurity

Incident Response and Digital Forensics: A Guide for Indonesian Companies

What incident response and digital forensics are, the six phases of handling an incident, the 3x24 hour breach notification duty under the PDP Law, and how to prepare your business before an incident happens.

M
Mirna Indriasari · Security Program Manager
July 9, 2026·5 min read

The first hours decide everything

Most of the damage from a cyber incident does not happen the moment an attacker first gets in. It grows in the hours and days that follow, when no one notices, or when the person who notices does not know what to do. A panicked staff member shuts down a server, deletes a suspicious file, or reformats a machine with good intentions, and unknowingly destroys the evidence needed to understand the attack.

This is where incident response and digital forensics come in. The two are often mentioned together as DFIR, and while they are related, they answer different questions.

Two distinct but connected disciplines

Incident response is about action. Its goal is to stop an attack in progress, limit the damage, and return the business to normal operations as quickly as it can be done safely. It is fast-moving, decision-driven work.

Digital forensics is about evidence. Its goal is to answer precisely what happened, when the attacker got in, which path they used, what data was touched, and whether they are still inside. This work demands care, because its results can support legal decisions, insurance claims, or reports to a regulator.

In practice the two run side by side. The response team needs to understand enough about the attack to contain it properly, and the forensics team needs to make sure containment actions do not destroy the evidence they need.

The six phases of handling an incident

A widely used framework, including from NIST, divides incident handling into connected phases. Understanding this order helps your team stay calm when pressure is high.

It all begins long before an incident, at the preparation phase, when you build a plan, define roles, and make sure logs are kept properly. When something happens, the detection and analysis phase determines whether this is truly an incident and how severe it is. The team then contains it to prevent spread, followed by eradication to remove the attacker's traces from the systems, then recovery to restore services safely. The final phase, the one most often skipped, is the post-incident review to understand the root cause and fix the weaknesses so a similar event does not recur.

Organizations that skip the preparation and review phases tend to face the same incident again and again in slightly different forms.

Why readiness is cheaper than emergency response

Hiring a forensics team while an incident is unfolding is always more expensive and slower than preparing one in advance. Without preparation, the first hours are spent on administrative work such as finding the right contact, agreeing on a contract, and explaining the environment from scratch, all while the attacker keeps moving.

Many Indonesian companies now choose an incident response retainer, an arrangement that guarantees an expert team on call with an agreed response time. With this setup, the team handling the incident already knows your environment before trouble strikes. This mirrors why many organizations move monitoring to a SOC as a service, because early detection is what makes handling possible in the first place.

In Indonesia, incident handling does not end with the technical side. The Personal Data Protection Law requires data controllers to notify data subjects and the relevant authority no later than 3x24 hours after a personal data breach is known. For banks and financial institutions, OJK rules add their own incident reporting duties.

That means when an incident occurs, the clock is ticking not only for the technical team but also for legal and communications. A mature response plan brings all three together so notification decisions are based on facts, not guesses. We cover these reporting obligations in more depth in our comparison of the PDP Law and GDPR.

Mistakes to avoid in the first hours

Some reactions that seem sensible actually make things worse. Shutting down an infected system can erase evidence held in memory. Deleting a suspicious file removes the trace needed to understand the attack. Paying a ransom without consulting experts often does not restore data and instead marks your organization as a target willing to pay.

The right move in the first hours is to isolate affected systems from the network without shutting them down, contact the response team, and record every action taken with its timestamp. This simple documentation later becomes the backbone of the forensic investigation and the report to regulators.

Preparing your business before an incident comes

The right question is not whether an incident will happen, but how ready your organization is when it does. Readiness starts with simple things such as making sure logs are kept, deciding who has authority to make decisions, and agreeing on who to call outside working hours.

Our incident response service combines fast containment with a forensic investigation that holds up legally, backed by analysts who understand reporting obligations in Indonesia. If you do not yet have a written and tested response plan, the best starting point is to build one simple scenario and ask who would pick up the phone at two in the morning.