An incident response lifecycle defines the structured process for detecting, responding to, and recovering from production incidents — from the first alert to the final postmortem. A consistent, practiced lifecycle reduces mean time to detect (MTTD) and mean time to resolve (MTTR), prevents costly ad-hoc coordination during high-stress situations, and ensures lessons are systematically captured to prevent recurrence. The lifecycle has five phases: detect, triage, contain, resolve, and learn.
Analogy🏏Cricket
🏏 Think of it like cricket: A batting coach who only reviews a batter's technique after a tournament has already ended. The batter has played 10 matches with a flawed grip — every run scored with bad technique is harder to unlearn than if the coach had corrected it in the first net session. Shifting security left is bringing the coach into the net sessions, not the post-tournament review.