
02.09.2026
A cyber attack does not always announce itself with a loud alarm. Often it begins inconspicuously: with a compromised user account, a suspicious login or a single phishing email.
Valuable hours can already have passed by the time a company realises that a security incident has actually occurred. However, it is precisely this time that often determines how significant the damage turns out to be in the end. For the longer an attacker remains undetected, the more opportunities they have to spread within the IT environment.
Incident Response describes the structured response to a security incident. Preparation is crucial: anomalies must be detected early and handled without delay in an emergency.
Thomas Ringhof, Incident Responder and Digital Forensics Expert at r-tec in the accompio Group, experiences in his daily work just how crucial a rapid and structured response to security incidents is. In this expert interview, he explains why companies frequently react too late, which mistakes happen during the first hours of a cyberattack, and how organisations can specifically improve their own responsiveness.
In the full expert interview, Thomas Ringhof, incident responder and digital forensics specialist at r-tec (part of the accompio Group), talks about his experiences with security incidents and explains what companies should pay particular attention to regarding their incident response.
Many companies only recognise an attack once the impacts become clearly visible. Thomas Ringhof sees two main causes for this: a lack of technical visibility and a lack of clear internal processes. If relevant log data is not available or responsibilities remain unclear, an initial anomaly quickly turns into an incident to which no one responds in time.
Typical starting points include phishing and infostealer malware. In the interview, Thomas Ringhof describes a case in which attackers gained access to an email mailbox, read ongoing communications and manipulated an invoice. The company subsequently transferred a large sum of money to the wrong account.
A compromised user account can initially be used relatively inconspicuously. Attackers secure their access, create persistence and avoid attention. Only later do they execute malware or cause visible system failures. When the incident is eventually detected, the attackers may already have been active in the IT environment for days or weeks.
The human factor also plays a role. An unusual login is sometimes assessed as a harmless error because the first plausible explanation provides reassurance. This confirmation bias can lead to warning signals not being investigated further and necessary escalations being delayed.
Therefore, incident response already begins with the Incident Response Readiness. Businesses must be able to detect suspicious activities early, classify them and pass them on via a defined escalation path. This requires technical visibility, clear processes and clearly designated persons in charge.
If a security incident is detected, it must be clarified as quickly as possible: What has happened? Which systems are affected? Which user accounts may have been compromised? And how far has the attacker already managed to spread?
In practice, delays frequently occur here. Responsibilities are not clearly defined, information is missing or it is unclear which measures must be carried out first. The path from the initial observation by an employee through to IT administration and classification as a security incident must therefore be defined in advance.
A prepared one Incident Response Process creates operational security here. Playbooks define for typical scenarios which information is required, who decides and which measures are to be taken first. This applies, for example, to compromised user accounts, suspicious logins, phishing or detected malware.
This means that in an emergency, you don't have to start from scratch.
Rapid incident response requires companies to be able to see what is happening in their IT environment in the first place.
The first step is centralised log management. A decision must be made as to which data should be included. Is login data sufficient, or are events from endpoints, servers and other host systems also required? Depending on the environment, a SIEM can help to bring this information together and evaluate user activities.
Monitoring makes anomalies visible at an early stage. Historical log data is also important for digital forensics. They can show when an attacker first became active, which accesses were used, and which systems were subsequently affected. Without this data, an incident can often only be reconstructed incompletely.
Technology alone is not enough, however. An alarm is initially just an indication that something unusual has happened. After that, it must be clear who will assess the incident, what measures are to be initiated and who needs to be informed.
The consequences of a security incident depend heavily on how early a company reacts. Company size does not offer reliable protection in this regard. Many attacks run automatically and scan large address ranges for reachable and vulnerable systems.
A single compromised user may initially seem like a limited problem. However, if the attacker can use the access to compromise further accounts or systems, the scope of the incident grows. At the same time, the subsequent investigation becomes more complex and difficult.
„If I wait too long, the costs do not rise linearly, but almost multiplicatively.“
Thomas Ringhof, Incident Responder and Digital Forensic Investigator at r-tec
Precisely why a company should not wait until an attack becomes clearly recognisable. The goal must be to detect suspicious activities as early as possible and be able to react quickly.
Good incident response begins long before the actual security incident. Organisations should first ensure sufficient visibility and check which systems and activities are monitored and what log data are available.
Building upon this, responsibilities and concrete procedures should be defined. For typical scenarios, incident response playbooks can specify what information must be gathered, which contacts involved, and what technical measures initiated.
It is also important to regularly review the processes in practice. Incident-Response Simulations demonstrate whether reporting channels and decisions work in an emergency. Penetration testing can reveal additional vulnerabilities and potential attack paths. The results are then incorporated into monitoring, playbooks and technical protective measures.
Four steps create a solid foundation:
Artificial intelligence and automation can analyse large amounts of security data more quickly and provide forensic investigators with initial leads. For example, a model can point out conspicuous correlations and thus accelerate the initial triage.
The expert assessment remains crucial. Experts review the reports, place them in the company context and decide on the next steps. In this way, automation reduces the noise in the data and creates more time for the actual analysis.
At the same time, the methods of attackers are evolving. Processes, monitoring and playbooks must therefore be reviewed and adjusted regularly.

accompio helps organisations prepare their IT environment for a security incident.
Incident response does not begin at the moment a company confirms a cyber attack. It already begins with preparation.
Anyone who monitors their IT environment, makes relevant log data available, defines responsibilities and prepares concrete scenarios creates a significantly better foundation for emergencies.
Because when an attack actually takes place, there is no time for fundamental considerations.
Reacting instead of hoping therefore means above all: being prepared, making visible what is happening, and being able to act at the decisive moment.

Thomas Ringhof is an incident responder and digital forensics specialist at r-tec (part of the accompio group) and brings experience with security incidents to prepare companies for cyber attacks.
Incident Response refers to a company's structured response to an IT security incident. The aim is to detect an attack as early as possible, contain its impact and subsequently investigate the incident.
The longer an attacker remains undetected, the more opportunities they have to compromise further accounts and systems. A rapid response can therefore help to limit the scope and impact of a security incident.
An incident response playbook outlines specific procedures for certain security incidents. For example, it specifies what information must be gathered, who is responsible and what steps should be taken next.
Monitoring and central log data provide the necessary visibility to detect suspicious activities and subsequently investigate security incidents forensically. Without sufficient data, a rapid and well-founded response is significantly more difficult.
Organisations should make relevant log data centrally available, clearly define responsibilities and prepare playbooks for typical attack scenarios. The procedures should then be tested in practice on a regular basis.
Common starting points are phishing, compromised email mailboxes and infostealer malware. Attackers use captured credentials to move about unnoticed within the IT environment and reach further systems or accounts.
AI can analyse large volumes of data, flag conspicuous correlations and provide forensic scientists with initial leads. The final assessment and the decision on concrete measures remain with the responsible experts.
