Incident Response in Cybersecurity: A Systematic Review
Lawrence Olabisi Kazeem
International Centre for Professional Development (ICPD), Federal University of Agriculture, Abeokuta, Nigeria.
Victoria Oluwaseyi Adedayo-Ajayi *
Ladoke Akintola University of Technology, Ogbomoso, Oyo State, Nigeria.
Simeon Okechukwu Ajakwe
Smart Computing Department, Kyungdong University (KDU), Global, South Korea.
Oyesanmi Fiyinfoluwa
Department of Electrical and Electronics Engineering Technology, University of Johannesburg, Johannesburg, South Africa.
*Author to whom correspondence should be addressed.
Abstract
Background: Cybersecurity incident response is commonly described as a sequence of technical activities, yet major incidents are managed by people working across organisational boundaries, under uncertainty and time pressure. Evidence about the human, organisational, procedural and technological conditions that shape response performance has not been consolidated across sectors.
Objective: To determine which factors shape organisational cybersecurity incident-response performance and what evidence exists that training, structured processes, collaboration or decision support improve operational outcomes.
Methods: An openly accessible evidence search was completed on 6 July 2026 for English-language primary empirical reports published from 1 January 2000 to 30 June 2026. Six reproducible web searches were supplemented by backward citation checking. One reviewer screened records, assessed full texts, extracted data and applied the Mixed Methods Appraisal Tool 2018. Because designs, settings, outcomes and estimands were incompatible, findings were synthesised thematically without statistical pooling.
Results: Eighty-five records were identified, 11 duplicates were removed, 74 records were screened, 30 full-text reports were assessed and 26 reports representing 25 unique studies were included. Evidence was predominantly qualitative and spanned security operations centres, computer security incident response teams, critical infrastructure, finance, public administration and healthcare. Recurrent determinants were shared situation awareness, communication across tiers and shifts, role clarity, trusted informal networks, workload and staffing, realistic cross-functional training, usable tools and data, and learning that extends beyond immediate technical restoration. Healthcare studies showed that manual alternatives and local adaptation can preserve care, but may transfer substantial safety and wellbeing burdens to staff. Automation was perceived as useful, but respondents expressed limited willingness to delegate decisions without human oversight.
Conclusions: Cybersecurity incident response is a socio-technical capability rather than a discrete technical procedure. Moderate-confidence evidence supports investment in shared situation awareness, explicit coordination, sustainable staffing and deliberate learning. Evidence for particular training formats, automation strategies and objective improvements in detection, containment or recovery time remains limited. Prospective multi-site evaluations using common operational and human-factors outcomes are needed.
Keywords: Cybersecurity, incident response, computer security incident response team, security operations centre, human factors, organisational learning, situation awareness, systematic review