When prevention fails, incident response (IR) limits the damage and gets the business back to normal — calmly and methodically.
The Incident Response Lifecycle
The NIST four-phase model for handling a security incident.
Tap or hover a part to learn more.
Be ready.
Plans, playbooks, tooling, contacts and training built before anything happens. The phase most often skipped and later regretted.
Check your understanding
1. Which phase includes 'lessons learned'?
2. Why capture volatile data before powering a machine off?
The lifecycle (NIST/SANS)
- Preparation — plans, tools, roles and playbooks before anything happens.
- Detection & Analysis — confirm and scope the incident (from the SOC).
- Containment — stop the spread (isolate hosts, disable accounts).
- Eradication — remove the threat and root cause.
- Recovery — restore systems safely and monitor.
- Lessons Learned — a blameless review to improve.
Preserving evidence and clear communication matter throughout. This ties to Malware & Endpoint Security and Security+.
