Containment, Eradication, and Recovery
Containment, Eradication, and Recovery is a phase of the incident response process in which responders act to stop an ongoing security incident from causing further damage, remove the cause of the incident, and restore affected systems to normal operation. It is generally treated as the action-oriented stage that follows the detection or identification of an incident. The exact steps depend on the nature of the incident and the organization's response procedures.
Containment, Eradication, and Recovery denotes the central active phase within an incident response life cycle, commonly associated with the model reflected in NIST incident-handling guidance. Containment focuses on limiting the scope and impact of a confirmed incident to prevent cascading damage and halt attacker activity; eradication addresses removal of the underlying cause, such as malicious artifacts or compromised components; and recovery restores affected systems and services to validated normal operation. In practice these sub-activities are often iterative rather than strictly sequential, and incident response as a whole is frequently described as a continuous cycle of identification, containment, eradication, and recovery. This entry describes the concept generically; specific procedures, tooling, and success criteria vary by organization, incident type, and the framework adopted, and readers should verify against the current authoritative source of any framework they rely on. It is a process phase, not a regulatory requirement in itself, though it may be referenced within security programs or contractual obligations.
Why it matters
Containment, Eradication, and Recovery is the phase where incident response translates from analysis into action, and the quality of execution here often determines whether a security incident becomes a contained event or a cascading crisis. Containment is frequently described as the most decisive phase, because it stops attacker activity and prevents further damage from spreading across systems and operations. Delays or missteps at this stage can allow an incident to expand in scope, complicating both eradication and recovery and increasing the overall cost and disruption to the organization.
For compliance and security programs, this phase matters because it directly affects the organization's ability to limit harm to data and systems, which in turn bears on obligations that may arise under data protection regulations, sector rules, or contractual commitments. It is important to be clear that Containment, Eradication, and Recovery is a process phase within an incident response life cycle, not a regulatory requirement in its own right. However, it is commonly referenced within security frameworks and may support demonstrable due diligence when organizations must account for how they responded to an incident.
Because these sub-activities are often iterative rather than strictly sequential, and because incident response as a whole is frequently characterized as a continuous cycle, organizations generally treat this phase as an ongoing effort rather than a single discrete step. The specific procedures, tooling, and success criteria vary by organization, incident type, and the framework adopted, so readers should verify the requirements of any framework they rely on against its current authoritative source.
Who it's relevant to
Inside Containment, Eradication, and Recovery
Common questions
Answers to the questions practitioners most commonly ask about Containment, Eradication, and Recovery.

