MGM Resorts gave every risk practitioner a live demonstration of what happens when the incident management workflow fails at its first gate. On September 10, 2023, attackers from the Scattered Spider group impersonated an employee they had researched on LinkedIn, and a roughly ten-minute call to the MGM help desk handed them administrator access.
Slot machines errored out on the Las Vegas floor, digital room keys died, and booking systems went offline for days. Full restoration took until September 20, and MGM told investors the incident would cost about $100 million, a figure it disclosed in an SEC filing that October.
| Incident Management Workflow: Key Takeaways |
| MGM Resorts told investors the September 2023 attack cost roughly $100 million, after a ten-minute vishing call to its help desk defeated the front of its workflow. |
| IBM’s Cost of a Data Breach Report 2025 puts the mean breach lifecycle at 241 days and the global average cost at $4.44 million, with US breaches at a record $10.22 million. |
| Extensive security AI and automation cut average breach costs by $1.9 million and shortened the lifecycle by 68 days, per IBM 2025. |
| The workflow runs in seven stages: preparation, detection and reporting, assessment and classification, containment and response, eradication and recovery, communication and documentation, and post-incident review. |
| NIST SP 800-61 Revision 3 now frames incident response as a continuous risk activity mapped to the CSF 2.0 functions, so the workflow belongs inside the risk program. |
| Priority comes from an impact-and-urgency matrix agreed in advance; P1 incidents trigger declaration, regulatory clocks, and executive communication. |
We wrote this guide to walk risk practitioners through the incident management workflow end to end. It covers the seven stages, the classification gate that decides priority, the roles and handoffs, the metrics worth trending, and the automation evidence that now justifies the budget request.
What the Incident Management Workflow Covers
The MGM story frames the definition well. An incident management workflow is the agreed sequence of steps an organization follows from the moment something breaks to the moment the lessons are closed, spanning detection, triage, response, recovery, and review. Atlassian’s ITSM guidance treats it as the connective tissue of service operations.
The authoritative anchor moved in April 2025. NIST Special Publication 800-61 Revision 3 recast incident response as a continuous risk management activity organized around the NIST Cybersecurity Framework 2.0 functions, which places the workflow squarely inside the risk practitioner’s mandate, next to the risk management lifecycle itself.
Scope matters as much as sequence. The same workflow skeleton should handle cyber events, system failures, third-party outages, and physical disruptions, because responders under pressure should never wonder which process applies. Structured risk identification techniques feed the same intake channel regardless of threat type.
| Workflow element | What it establishes | Standard anchor |
| Intake and declaration criteria | One channel for reports; written thresholds for escalating | NIST SP 800-61r3; ITIL 4 |
| Severity and priority model | Impact-and-urgency matrix mapped to response targets | ITIL 4 priority matrix |
| Role assignments | Named owners for coordination, resolution, and communication | ISO/IEC 27001 Annex A; ITIL 4 |
| Communication plan | Cadence, channels, and audiences for updates | ISO 22301 warning and communication |
| Documentation trail | Timeline, decisions, and evidence captured as events unfold | NIST SP 800-61r3 |
| Review and improvement loop | Post-incident review feeding corrective actions and KRIs | NIST CSF 2.0 Improve category |
Why the Incident Management Workflow Decides the Bill
Definitions become budget lines once the costs land. IBM’s Cost of a Data Breach Report 2025 puts the global average breach at $4.44 million and the US average at a record $10.22 million, with organizations taking a mean of 241 days to identify and contain an incident.
The direction of travel favors disciplined workflows. That 241-day lifecycle is the shortest IBM has measured in nine years, and the firm’s X-Force analysts credit AI-assisted detection for much of the gain. Organizations using security AI and automation extensively saved $1.9 million per breach and cut 68 days from the lifecycle.

Figure 1. Automation moves both the cost and the clock, per IBM’s 2025 report.
Downtime economics point the same way. Splunk and Oxford Economics measured $400 billion a year in downtime costs across the Global 2000, while Uptime Institute’s 2025 outage analysis found one in five operators’ most recent serious outage cost more than $1 million. A faster workflow directly shrinks those exposure windows.
| Incident | Date | Documented cost | Source |
| MGM Resorts social engineering attack | Sept 2023 | About $100M, per investor disclosure | CS Hub timeline |
| CrowdStrike Falcon update failure | July 2024 | $5.4B Fortune 500 direct losses | Parametrix via Fortune |
| Change Healthcare ransomware attack | Feb 2024 | About $3.1B in response and disruption costs | UnitedHealth reporting; HHS |
| Average US data breach | 2025 report | $10.22M, an all-time high | IBM |
| Average breach lifecycle | 2025 report | 241 days to identify and contain | IBM |
The tail risks stay documented and public: the CrowdStrike outage’s $5.4 billion Fortune 500 bill and the Change Healthcare attack that exposed data on about 190 million people both started as single incidents inside somebody’s workflow. What separated the expensive outcomes from the survivable ones was speed through the stages below.
The Seven Stages of the Incident Management Workflow
Those invoices argue for structure, and the structure has seven stages. Each stage produces an artifact a risk practitioner can audit afterward, from the intake record to the closed corrective action in the risk register, and the stages loop back into preparation.

Figure 2. The workflow is a loop, not a line: stage seven feeds stage one.
| Stage | Core activity | Artifact to audit |
| 1. Preparation | Plans, playbooks, tooling, and trained roles in place before anything breaks | Approved response plan; drill records |
| 2. Detection and reporting | Monitoring alerts and human reports converge on one intake channel | Timestamped incident record |
| 3. Assessment and classification | Impact and urgency scored; priority assigned from the matrix | Priority decision with criteria cited |
| 4. Containment and response | Spread stopped; workarounds deployed; regulatory clocks checked | Containment log; notification checklist |
| 5. Eradication and recovery | Root cause removed; services restored to recovery targets | Restoration confirmation against RTO |
| 6. Communication and documentation | Cadenced stakeholder updates; running timeline maintained | Update archive; decision log |
| 7. Post-incident review | Causes analyzed; lessons converted to owned actions | Review report; action tracker |
Preparation: Building the Incident Management Workflow Before You Need It
Preparation is the stage MGM’s attackers exploited, because identity verification at the help desk is a preparation control. Write the playbooks, verify the call trees, and pre-approve containment authority. A documented incident response plan template and CISA’s federal response playbooks give you tested starting structures.
Detection and Reporting: Feeding the Incident Management Workflow
Detection blends tooling with culture. Monitoring platforms catch machine-visible failures, while staff catch the odd phone call, the wrong invoice, and the tailgating stranger, so the reporting channel must be one step simple. Verizon’s 2025 data breach investigations found ransomware present in 44% of breaches, and early reports are the cheapest control against it.
Containment Through Recovery in the Incident Management Workflow
Containment decisions trade damage against evidence, and hesitation compounds both. Isolate affected systems, preserve forensic images, and work the fix in parallel with the recovery time and recovery point objectives agreed with service owners. Where the disruption outlasts recovery targets, the business continuity plan takes the handoff.
Post-Incident Review: Closing the Incident Management Workflow Loop
The review is where the workflow pays for itself. Within ten business days, walk the timeline, separate root causes from triggers, and assign every corrective action an owner and a date. Feed recurring findings into key risk indicators so the next quarterly report shows whether fixes held.
Classifying Incidents: The Triage Gate of the Incident Management Workflow
Every stage after detection depends on classification getting the priority right. Score business impact on one axis and urgency on the other, then read the priority from a matrix agreed long before the incident, the same approach ServiceNow builds into its incident management product as automatic priority calculation.

Figure 3. Priority falls out of two scores agreed in advance, not a debate in the war room.
Impact scoring should borrow from work you have already done. The business impact analysis ranks critical functions, and the corporate risk appetite sets the financial thresholds, so classification inherits both. Regulatory exposure raises priority automatically: a P2 outage becomes P1 the moment reportable data is involved.
| Classification input | P1 signal | P2-P3 signal | P4 signal |
| Critical function impact | Core service down enterprise-wide | One unit degraded or single service down | Cosmetic fault with workaround |
| Escalation likelihood | Spreading across systems or sites | Contained but fragile | Stable and isolated |
| Regulatory and legal exposure | Reportable breach or filing clock running | Possible obligation, under assessment | No obligation |
| Financial exposure | Above board-reporting threshold | Material to the business unit | Absorbed in operating budget |
Regulatory clocks make this gate unforgiving. The SEC gives public companies four business days from a materiality determination on a cyber incident, and New York’s DFS Part 500 gives licensed firms 72 hours. Classification is the step that starts those timers, which is why the criteria belong in policy.
Roles and Handoffs Across the Incident Management Workflow
A correct priority still fails if the handoffs blur. The workflow moves through distinct hands, and each transfer needs a defined package of information, because incidents lose minutes at every seam. EU-regulated firms face the same discipline under DORA’s incident classification and reporting rules, where late handoffs become late filings.
| Handoff | Passes between | What must transfer intact |
| Report to triage | Reporter and service desk | Time, symptoms, systems affected, reporter contact |
| Triage to response | Service desk and incident manager | Priority score, criteria cited, initial scope |
| Response to specialists | Incident manager and technical leads | Containment status, access granted, evidence preserved |
| Response to communications | Incident manager and communications lead | Approved facts, update cadence, audience list |
| Response to risk function | Incident manager and risk practitioner | Regulatory clock status, loss estimate, insurer notice |
| Resolution to review | Incident manager and review chair | Full timeline, decision log, unresolved questions |
The risk practitioner’s handoff deserves emphasis because it is the one most workflows omit. Someone must track loss accumulation, insurance notice deadlines, and the operational risk reporting the board expects, while engineers work the technical fix. Write that seat into the plan by name.
Handoffs only stay sharp under rehearsal. Run at least two exercises a year using our fifteen ready-made continuity scenarios, score them against the business continuity maturity model, and let ISO 22301 define the evidence standard for the drill records.
Automation and Metrics That Tighten the Incident Management Workflow
Rehearsed handoffs get faster still when tooling carries the routine steps. Alert correlation, automatic priority scoring, and templated stakeholder updates all remove human latency, and our comparisons of incident management software, crisis management platforms, and operational resilience suites map the field.
| Workflow metric | Definition | What it tells the risk function |
| Mean time to detect | Fault occurrence to first alert, averaged per period | Monitoring coverage by service |
| Mean time to acknowledge | Alert to a human actively engaged | On-call design and paging health |
| Mean time to resolve | Detection to full restoration | Headline workflow speed for the board |
| Escalation accuracy | Share of incidents classified correctly at triage | Whether the priority matrix works in practice |
| Reopen rate | Share of resolved incidents that recur within 30 days | Fix quality versus symptom patching |
| Notification timeliness | Share of regulatory notices filed within deadline | Direct evidence for SEC, DFS, and HIPAA clocks |
The investment case is now quantified. IBM’s 2025 mitigator rankings put a DevSecOps approach at $227,000 of breach-cost reduction, with AI security insights, SIEM analytics, threat intelligence sharing, and encryption close behind, and CyberScoop’s read of the report notes costs fell for the first time in five years.

Figure 4. Five controls the workflow can institutionalize, ranked by measured cost reduction.
Pair the tooling with cybersecurity risk management fundamentals and an ISO 22301-aligned continuity capability, and the workflow becomes a system with evidence at every stage. Shadow AI cuts the other way, adding $670,000 to average breach costs where ungoverned tools spread.
Seven Traps That Derail Incident Management Workflow Programs
Most workflow failures are inherited, sitting quietly in the process until a live incident finds them. The seven traps below surface constantly in our client reviews of incident management workflows, and each has a countermeasure that costs less than one bad quarter of incidents.
| Trap | Warning sign | Countermeasure |
| Multiple intake channels | Incidents surface in chat threads days later | One reporting channel, published everywhere, no exceptions |
| Verification theater at the front door | Help desk resets credentials on a caller’s say-so | Callback verification and step-up identity checks, MGM-style lesson |
| Priority by argument | War room debates severity for the first hour | Written impact-and-urgency matrix; triage cites it |
| Regulatory clock starts late | Legal hears about incidents after restoration | Risk practitioner joins at declaration, tracks all deadlines |
| Documentation reconstructed afterward | Timelines assembled from memory for the review | Scribe role plus tooling that timestamps as events happen |
| Reviews without teeth | Same root cause appears in consecutive reviews | Actions tracked as KRIs with owners, dates, and closure evidence |
| Workflow only covers cyber | Supply chain or facility events improvised | One skeleton for all threat types, tested against varied scenarios |
Incident Management Workflow FAQs: Expert Answers to Critical Questions
What is an incident management workflow?
An incident management workflow is the defined sequence an organization follows from detecting a disruptive event through resolving it and closing the lessons. It typically runs seven stages: preparation, detection and reporting, assessment and classification, containment and response, eradication and recovery, communication and documentation, and post-incident review, anchored to NIST SP 800-61 and ITIL 4.
How does the incident management workflow differ from an incident response plan?
The plan is the document; the workflow is the operating sequence the document describes. A response plan records roles, criteria, and procedures, while the workflow is what actually executes when an alert fires. Our comparison of response plans and continuity plans shows where each artifact sits in the larger resilience stack.
Which standards should an incident management workflow follow?
Anchor the workflow to NIST SP 800-61 Revision 3 for incident handling, the NIST CSF 2.0 functions for program structure, ITIL 4 for service operations, and ISO/IEC 27001 for the security management system around it. Continuity handoffs follow ISO 22301, and regulated sectors layer SEC, HIPAA, DFS, or DORA obligations on top.
Who should own the incident management workflow, IT or the risk function?
Split it deliberately. IT owns execution of the technical stages because they hold the systems, while the risk function owns the framework: classification criteria, regulatory clocks, loss tracking, and review quality. That pairing follows the five-step risk management process, where monitoring and reporting stay independent of the fix.
Which metrics show an incident management workflow is improving?
Trend mean time to detect, acknowledge, and resolve quarterly, then add escalation accuracy, reopen rate, and notification timeliness. Improvement means resolution time falling while reopen rates stay flat or drop. Resolution speed improving while the same root causes recur signals symptom patching, and boards should see both curves together.
How often should the incident management workflow be tested?
Exercise it at least twice a year, one tabletop and one live simulation, rotating scenarios across cyber, third-party, and physical disruptions. Include supply chain incident response at least annually, because vendor-origin events now drive a large share of disruptions. Update the workflow within thirty days of every exercise or live incident.
The Regulatory and Technology Horizon for the Incident Management Workflow
Start hardening the intake stage first. Social engineering of help desks, the technique that opened MGM, is now standard attacker tradecraft, and we expect identity verification at service desks to become an explicitly audited control in most security certification frameworks by 2027.
Automation will keep absorbing the middle stages. IBM’s numbers already show extensively automated programs resolving breaches 68 days faster, and the next platform generation will draft classifications, timelines, and stakeholder updates for human approval. Triage judgment and declaration authority should stay human, and workflows should say so explicitly.
Budget for shorter regulatory clocks in every jurisdiction you touch. The SEC’s four-business-day disclosure regime has produced its first enforcement lessons, DORA’s four-hour initial notice is live for EU financial entities, and US critical-infrastructure reporting rules are moving toward 72-hour requirements. Reporting drills belong in the 2026 exercise calendar now.
Expect the risk practitioner’s share of the workflow to grow. Classification thresholds, loss tracking, and review enforcement are risk-function work, and firms that staff that seat will convert incidents into control improvements faster than firms that treat the workflow as an IT procedure.
Pressure-Test Your Incident Management Workflow With Risk Publishing
A ten-minute phone call took down a $34 billion company’s operations, so the honest question is what ten minutes of social engineering would do to yours. Explore our services or contact us to scope a workflow review that walks every gate, from intake verification to review closure.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.