الانتقال إلى المحتوى
← Defensive operations: how the blue team works

الدرس 3 من 4 · 9 دقيقة

Incident response: the six phases, from preparation to lessons learned

How organisations handle a security incident step by step, why preparation decides the outcome, and how the six-phase model maps to NIST’s guidance.

هذه الصفحة متاحة بالإنجليزية حاليًا.

Sooner or later, every organisation has a security incident: a phished account, a stolen laptop, ransomware on a file server. What separates a bad day from a disaster is rarely the attack itself. It is whether people knew what to do, who was in charge and what to do first. Incident response is the discipline of answering those questions in advance.

Two ways of drawing the same cycle

You will meet two common models. The SANS Institute’s incident handler’s handbook describes six phases, often remembered as PICERL: Preparation, Identification, Containment, Eradication, Recovery and Lessons learned. NIST’s Computer Security Incident Handling Guide (SP 800-61 revision 2) groups the same work into four phases: Preparation; Detection and Analysis; Containment, Eradication and Recovery; and Post-Incident Activity. In 2025 NIST published revision 3, which reorganises its recommendations around the six functions of the NIST Cybersecurity Framework 2.0. The steps are the same work; only the grouping differs.

The six phases of incident response in a cycle: preparation, identification, containment, eradication, recovery and lessons learned, with lessons feeding back into preparation.
The six-phase cycle. Lessons learned feed the next round of preparation.

1. Preparation

Preparation is everything you do before the incident: an up-to-date contact list, a written plan with clear roles, logging turned on and kept, backups tested, and playbooks for the incidents you expect most (phishing, ransomware, a lost device). It also means practice: tabletop exercises where the team talks through a scenario and discovers, safely, that nobody knows who can shut down the VPN at 2 a.m.

2. Identification

Something looks wrong: an alert, a user report, a strange bill from a cloud provider. Identification means confirming whether it is a real incident, how serious it is and what is affected. The key discipline here is to write everything down with timestamps from the first minute, because early notes become the timeline everyone relies on later.

3. Containment

Containment stops the damage from spreading while you work out the rest. Short-term containment might mean disconnecting a laptop from the network, disabling a compromised account or blocking an attacker’s address at the firewall. The tension here is real: acting too fast can destroy evidence or tip off the attacker; acting too slowly lets them move further. A good plan says in advance who is allowed to make that call.

4. Eradication

Once the incident is contained, you remove what the attacker left behind: malicious files, persistence mechanisms, rogue accounts, stolen credentials. Eradication is only as good as your understanding of the scope. If you clean one machine but miss the second one the attacker also reached, they come back.

5. Recovery

Recovery brings systems back to normal: restoring from clean backups, rebuilding machines, resetting passwords and watching closely for signs that the attacker is still present. For ransomware, this is where tested, offline backups turn a crisis into an inconvenience.

6. Lessons learned

Within a couple of weeks, the people involved meet to review what happened, without looking for someone to blame. What let the attacker in? What slowed the response? Which detection would have caught it earlier? The output is a short list of concrete changes, and it feeds straight back into preparation. Skipping this phase is the most common way organisations get hit twice by the same thing.

Beyond the technical work

  • Legal and regulatory duties: some incidents must be reported to authorities or to affected people within strict deadlines, for example under the GDPR in Europe.
  • Communication: one person speaks for the organisation, and staff know not to post about the incident publicly.
  • Outside help: know in advance which incident response firm, insurer or national CERT you will call.

أهم النقاط

  • Six phases: Preparation, Identification, Containment, Eradication, Recovery, Lessons learned.
  • NIST SP 800-61r2 groups the same work into four phases; revision 3 (2025) aligns with NIST CSF 2.0.
  • Preparation and practice decide the outcome more than any tool.
  • Containment balances speed against preserving evidence; decide in advance who makes that call.
  • Lessons learned feed the next preparation cycle; skipping it invites a repeat.

اختبر نفسك

  1. 1. Which phase comes right after identifying a real incident?

    • Lessons learned
    • Containment — صحيح.
    • Recovery
    • Preparation

    Once an incident is confirmed, the priority is to stop it spreading.

  2. 2. Why is the lessons-learned phase so important?

    • It is where the attacker is punished
    • It turns the incident into concrete improvements that feed the next preparation cycle — صحيح.
    • It is only needed for insurance
    • It replaces the need for backups

    Without it, the same weakness is likely to be exploited again.

  3. 3. What is a tabletop exercise?

    • A real attack against your own network
    • A discussion-based rehearsal where the team talks through an incident scenario — صحيح.
    • A type of backup
    • A furniture inventory

    Tabletop exercises reveal gaps in plans and roles safely, before a real incident.

جرّبها مع FireAI

طبّق هذا الدرس عمليًا على جهاز Mac الخاص بك.

المصادر

طبّق ذلك على جهاز Mac الخاص بك

جرّب كل الميزات مجانًا لمدة 17 يومًا، دون بطاقة.

تنزيل لجهاز Mac التوثيق