Incident response containment, eradication, and recovery are the three core phases that follow threat detection and analysis, each serving a distinct role in neutralizing and resolving a security incident.
Containment Eradication Recovery
Once we've declared that there is an incident, we're going to get into some troubleshooting and figure out what's going on. When we figure out what's going on, then we're going to move into containment, eradication, and recovery.
Once we've detected that there is an issue and done a little bit of analysis on it, figured out, hey, this is what's wrong on our system, our next step is that we want to contain the situation. We want to contain whatever is happening. Then we're going to eradicate, and then we're going to recover.
So what is the difference between containment, eradication, and recovery?
Let's develop a scenario to illustrate this. Let's say a machine got ransomware on it. What ransomware is, is it encrypts files on the machine and you can't access them because they're encrypted. In order for you to gain access to them again, you have to pay a ransom. You have to pay some sort of fee to the hacker, to the group that has this ransomware, and then once you pay that fee they'll decrypt it, and now you have access to those files and folders again.
So what we want to do is contain, eradicate, and recover. Containment just means we isolate that affected machine. It's got ransomware on it, so we're going to isolate it from the rest of the network so it doesn't spread anywhere else.
Once it's isolated, we're going to start eradicating it, getting rid of this threat. We have malware on this device, so we're going to get rid of it, we're going to remove it. We're going to go through the process of eliminating that on this isolated machine.
Next, once we do that, we're going to have to restore full functionality. We've gotten rid of the ransomware, but a lot of the files and folders have perhaps been removed or encrypted at this point in time, because we're not going to pay the ransom. We're just going to restore those files. So in this case we're restoring the files.
A lot of times, if the issue is coming from outside, we want to stop this from happening, from whatever the intrusion is into our network. Maybe we need to disconnect the network, or maybe we just need to stop that intruder from being able to have access to our network.
There are several ways we could do this. One of the things we could do is put a firewall rule up, or some sort of intrusion protection system or intrusion detection system rule, and identify that traffic and stop it. Or ACL rules, or signature rules, or behavior rules, or DLP rules, or some sort of scripts or regular expressions. Essentially, put something in place to stop that communication from happening.
We probably want to record what it is that we did, what we put into place, so that way later on we can fix whatever issue it is. A lot of times this is just to contain the issue. Maybe it is a permanent fix, maybe it's to eradicate and recover, but a lot of times it's just a temporary measure to contain the issue so that we can fix whatever is going on and then recover.
With something like malware that gets on our machine, if we're going to have to remove ransomware on a machine and then reinstall the files, one of the good things to do just to make sure it's clean is to reimage the machine altogether. As part of the remediation process, just remove any chance that it's happening by wiping all the files and doing a full restore.
Of course, this reimaging takes a little more work, so sometimes maybe you just remove the virus. But when you just remove the viruses, there's a chance that it might not have got everything, and so that's why a lot of times we just go to reimage the machine.
There are times with certain incidents that maybe we want to have some sort of compensating control. So think risk management with this. With risk management we have avoidance, reduced impact, transfer, or accept.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →