Providing adaptive response recommendations for a network security incident comprising at least one underlying security event is disclosed. A first set of data associated with the event is received. An initial group of one or more recommended responsive actions to be taken in response to the event is identified based at least in part on the first set of data. A second set of data associated with the event is received. The initial group of one or more recommended responsive actions is updated based at least in part on the second set of data associated with the event.