Detection & Response
Prevention fails. Telemetry → detection → alert → investigation → containment → recovery → learning, plus vulnerability management that prioritises exposure over CVSS.
Every lesson below identifies the asset, attacker capability and boundary before naming the vulnerability. Controls are split into prevention, detection and recovery; residual risk is explicit.
Telemetry becomes a detection hypothesis, an alert, an investigation and a response path; a noisy alert with no owner is not a control.
New device, unusual location, impossible-travel signals and failed attempts change risk; none proves compromise on its own.
Prepare → detect → contain → eradicate → recover → learn: restoring service without containment or evidence can extend the incident.
Discover → triage → assess exposure → prioritize → fix or mitigate → verify; severity is not risk without reachability, assets and controls.