المراحل الخمس للاستجابةThe five response phases

التحضير → الكشف والتحليل → الاحتواء → الاستئصال والتعافي → الدروس المستفادة. الملاحظة الجوهرية: أربع مراحل من خمس تحدث قبل الحادث أو بعده. الاستجابة الجيدة تُبنى في التحضير، وتُستكمل في مراجعة ما بعد الحادث.Preparation → detection and analysis → containment → eradication and recovery → lessons learned. The essential observation: four of five phases happen before or after the incident. A good response is built in preparation and completed in the post-incident review.

أول 60 دقيقةThe first 60 minutes

خمس خطوات مرتبة: تأكيد أن هناك حادثاً فعلاً (لا إيجابية كاذبة)، تفعيل فريق الاستجابة، عزل الأنظمة المصابة عن الشبكة دون إطفائها، توثيق كل شيء فوراً، وإبلاغ الإدارة بلغة واضحة بلا مبالغة أو تهوين.Five ordered steps: confirm there is an actual incident (not a false positive), activate the response team, isolate affected systems from the network without powering them off, document everything immediately, and brief management in clear language without exaggeration or understatement.

ما لا تفعله أبداًWhat never to do

لا تُطفئ الأجهزة المصابة (تفقد ذاكرة متطايرة وأدلة)، لا تحذف ملفات أو سجلات، لا تبحث بنفسك في الأنظمة المصابة (تُدمّر الأدلة)، لا تتواصل مع المهاجم دون مشورة، ولا تُخبر الجميع مبكراً قبل فهم النطاق — فقد تسبب ذعراً بلا داعٍ.Do not power off affected machines (you lose volatile memory and evidence), do not delete files or logs, do not browse the affected systems yourself (you destroy evidence), do not communicate with the attacker without advice, and do not tell everyone early before you understand the scope — you may cause unnecessary panic.

الالتزامات النظامية في السعوديةRegulatory obligations in Saudi Arabia

نظام حماية البيانات الشخصية (PDPL) يشترط إبلاغ الجهة المختصة عند وقوع تسريب بيانات شخصية خلال مدة محددة، وإبلاغ أصحاب البيانات المتأثرين. القطاعات المنظّمة (المالية، الصحي، الحكومي) لها متطلبات إبلاغ إضافية. تعرّف على التزامك **قبل** الحادث، لا أثناءه.The Personal Data Protection Law (PDPL) requires notifying the competent authority of a personal-data breach within a defined period, and informing affected data subjects. Regulated sectors (financial, health, government) have additional reporting requirements. Know your obligation **before** the incident, not during it.

الفريق والأدوارThe team and roles

كل منشأة تحتاج خمسة أدوار محددة مسبقاً: قائد الحادث (يتخذ القرارات)، المحلل التقني (يحقق)، مسؤول التواصل (يتحدث داخلياً وخارجياً)، المستشار القانوني (يقيّم الالتزامات)، ومسؤول التوثيق (يسجّل كل شيء). الغياب المفاجئ لأي دور يُشلّ الاستجابة.Every organization needs five pre-assigned roles: incident lead (decides), technical analyst (investigates), communications lead (speaks internally and externally), legal advisor (assesses obligations), and scribe (records everything). The sudden absence of any role paralyses the response.

التدريب قبل الحاجةRehearsing before you need it

خطة الاستجابة غير المُجرَّبة ليست خطة — بل وثيقة. نفّذ تمريناً واحداً على الأقل سنوياً (Tabletop Exercise) بحادث افتراضي واقعي، وشارك فيه الإدارة لا الفريق التقني فقط. الأخطاء المكتشفة في التمرين مجانية؛ تلك المكتشفة في حادث حقيقي مكلفة جداً.An untested response plan is not a plan — it is a document. Run at least one tabletop exercise a year based on a realistic scenario, involving management and not only the technical team. Mistakes found in an exercise are free; those found in a real incident are very expensive.