Incident Manager
Restore the service before you chase the cause
Ashley Jones ยท 6 October 2026
Incident Manager
Ashley Jones ยท 6 October 2026
During an incident, the first job is to get the service back. The reason it failed is a problem management question, and it can wait until people are working again.
An open incident is lost time for the business. Every minute spent debating causes on a bridge call is a minute the service is still down. Teams that chase root cause too early split attention, delay a workaround, and leave stakeholders guessing.
Incident management restores service. Problem management finds out why it broke. Mixing the two feels thorough. It usually slows recovery.
Name one incident lead. That person keeps the response focused and decides what happens next.
Then work in this order:
Keep updates factual and short. Say what is affected, what is being done, and when you will speak again. Do not fill the gap with theories.
The bridge stays small. People who are not restoring service are not on the call.
There is a clock for communications. Updates go out even when nothing has changed, so silence is not mistaken for progress.
The workaround is written down in language a support team can follow on the next occurrence. If the same failure has happened before, someone looks up the known error before starting a fresh investigation.
When service is back, the incident closes. A problem record is opened only when there is a pattern, a significant impact, or a cause that still needs removing.
Starting a deep technical investigation while users are still blocked. Diagnosis can run in parallel only if it does not delay restoration.
Treating every incident as a major incident. Major incident management is for disruption that needs wider coordination. Using it for everything creates noise and hides the cases that need it.
Closing the record with no note of what actually restored service. The next team then starts from zero.
Root cause can wait. Service restoration cannot. Restore the service, tell people what is happening, and pass the learning on once the business is moving again.
We help teams put ITSM practices to work with clear ownership, practical governance, and delivery that holds up under pressure.
Contact us