Trailhead ITIL

Incident Management: From 'It's Broken' to 'Back Working'

Logging, categorising, prioritising by impact and urgency, escalating, resolving — the anatomy of the process every IT career starts inside.

Incident management is where most IT careers begin, which makes it the most practically urgent practice on this trail. The previous waypoint defined an incident — an unplanned interruption, mission: restore service fast. This one walks the actual lifecycle, because "fast" is achieved through structure, not adrenaline.

The lifecycle, stage by stage

Trail note

Major incidents are the special case with its own machinery: separate procedure, a designated coordinator running the response, dedicated communication to stakeholders (the hardest part is honest, regular updates while engineers work), and afterwards — a review that feeds problem management. If the ransomware kill-chain post on this trail is ever your Tuesday, a major incident process is the vehicle you'll live inside.

Two habits separate excellent incident handlers from adequate ones, and both are free. First: communicate proactively — a user updated every hour tolerates a six-hour fix better than one left silent for two. The ticket's status field is not communication. Second: write for the future reader — your resolution notes are tomorrow's knowledge base. The technician who documents well is quietly building the known-error database the whole organisation runs on — and building a reputation with it.

Next waypoint — Ridge

Problem Management: The Detective Work Behind Quiet Systems →