IR-200: Foundational Incident Response - on the way to OSIR.
IR-200 (OSIR) covers the incident response lifecycle: preparation, detection, containment, evidence preservation, recovery and lessons learned - including communications and case management.

- Certification
- OSIR - OffSec Incident Responder
- Level
- Intermediate
- Discipline
- Defend
- Audience
- For security teams
Who this course is for
Incident response owners and teams that need a defensible process.
Not the right course yet if
- -You need detection fundamentals first - start with SOC-200
- →Run an incident by process instead of improvising
- →Preserve and document evidence defensibly
- →Plan recovery and embed lessons learned
- ·Windows and Linux fundamentals
- ·Basic understanding of networking and logging
Not sure whether you meet them? We run a short placement conversation before you buy.
What IR-200 covers.
- IR process and roles
- Containment and evidence preservation
- Host and network analysis
Course content, labs and the OSIR exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Case-based labs along a complete incident, from first report to closing report.
Exam and credential
Practical exam working a case, with a report. Passing awards the OSIR certification.
The packages that include IR-200.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +A tabletop exercise built on a realistic attack path from our engagements
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
No. It makes your team capable, but does not replace external escalation capacity.
It supports reporting processes and evidence, but it does not certify the organisation.
Not sure whether IR-200 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more