The Incident Response Lifecycle
Follow an evidence-led incident response lifecycle from preparation and triage through recovery and durable improvement.
Prepare authority and options
Preparation gives responders roles, contacts, evidence access, decision authority, communication routes, and tested recovery options before pressure arrives. Playbooks should guide judgment while leaving room for the facts of a specific incident.
Define who can isolate systems, revoke identities, notify leadership, engage suppliers, preserve regulated evidence, and accept service risk. Keep an out-of-band contact method and current asset, dependency, and data-owner records. Exercise credible scenarios rather than reading the plan aloud: can responders access logs when identity services fail, restore from protected backups, and communicate if normal collaboration tools are unavailable? Record gaps as owned improvements with a target and proof of completion.
Triage and establish scope
Triage determines what happened well enough to choose the next action. Normalize the signal, verify evidence health, identify affected identities and assets, build a bounded timeline, test alternatives, and state uncertainty. Scope remains a hypothesis that changes with evidence.
Separate observations from interpretations. An alert matched a rule; a process executed; an account accessed a file. “Ransomware incident” or “compromised user” is a judgment that needs support. Establish the earliest and latest relevant times, critical assets, possible safety or legal consequences, and immediate decisions. Assign severity from plausible impact and urgency, not from the product’s alert label alone. Revisit the classification when new evidence changes scope.
Contain and eradicate deliberately
Containment interrupts harm; eradication removes the cause or persistence. Compare urgency, confidence, reversibility, service impact, and evidence needs. Record the rationale and remember that blocking one indicator rarely proves the adversary has lost every path.
Containment may isolate a host, disable a token, block a route, pause a deployment, or limit a business process. Choose the smallest action that reliably reduces current harm, while preparing wider action if the hypothesis is confirmed. Eradication addresses exploited weaknesses, malicious artifacts, unauthorized accounts, persistence, and unsafe configuration. Do not rebuild before preserving the evidence needed to understand entry and reach, unless ongoing harm makes immediate action necessary; document that trade-off.
Recover to a trusted state
Restore from known-good components, credentials, configurations, and backups. Verify required controls and monitoring before returning to normal operation. Increased observation after recovery helps reveal incomplete scope or recurring access.
Recovery is a trust decision, not simply a service-start event. Validate the source and age of backups, rebuild path, software and configuration, secrets, identity dependencies, data integrity, and monitoring. Restore in stages with business owners, define what “usable and safe” means, and keep rollback available. Watch for old credentials, reintroduced vulnerable images, delayed attacker activity, and dependencies that were outside the initial scope. Record residual risk and who accepted it.
Learn and improve the system
Review technical conditions, decisions, handoffs, and control design without reducing the event to individual blame. Assign improvements to owners with evidence of completion. Threat intelligence and incident response exchange context, but response authority remains explicit.
A useful review asks which assumptions held, which evidence was missing, where decisions waited, how communications affected outcomes, and which controls limited impact. Distinguish a person making a reasonable decision with poor information from a system that made the safe choice difficult. Convert findings into specific changes—such as collecting one event family, protecting a recovery identity, or rehearsing a supplier contact—and later verify them. Feed new adversary behavior into intelligence and detection while removing temporary containment that no longer serves a purpose.