Containment, Eradication, and Recovery
Containment, Eradication, and Recovery is a core phase of responding to a cybersecurity incident, focused on stopping further damage and getting the organization back to normal. It involves isolating the affected systems, removing the underlying cause of the problem, and then restoring operations. This phase typically follows the detection or identification of an incident within a broader incident response process.
Containment, Eradication, and Recovery is a phase within the incident response life cycle in which responders act to limit the spread and impact of a confirmed incident, eliminate its root cause, and return affected systems to normal operation. Containment refers to the coordinated set of actions and technologies used to isolate, limit, or neutralize malicious activity within the IT environment; eradication is the process of eliminating the root cause of the incident with a high degree of confidence; and recovery restores affected systems and services to a trusted operational state. In many frameworks this phase follows identification/detection and precedes post-incident activity. In a virtual or fractional CISO context, security leadership typically advises on and directs the strategy and governance around these activities, while the hands-on execution, such as system isolation, remediation, and restoration, is generally performed by operational teams or specialized responders unless explicitly contracted otherwise.
Why it matters
Containment, Eradication, and Recovery is often described as the main phase of incident response because it is where an organization actively stops ongoing damage rather than simply observing it. Once an incident is confirmed, the speed and discipline with which responders isolate affected systems, remove the root cause, and restore trusted operations frequently determine the ultimate scope of business impact. A poorly coordinated response in this phase can allow malicious activity to spread, destroy evidence, or reintroduce the same compromise during recovery.
The distinct sub-steps exist for a reason that experienced practitioners insist on: containment without eradication leaves the root cause in place, and recovery without eradication risks restoring systems into an environment where the attacker still has a foothold. Eradication in particular is defined as eliminating the root cause with a high degree of confidence, a standard that guards against premature declarations of resolution. Rushing to restore operations before the underlying cause is understood is one of the more common and costly mistakes in incident handling.
For organizations relying on virtual or fractional security leadership, this phase highlights the difference between governance and hands-on operations. A vCISO or fractional CISO typically advises on and directs the strategy, decision-making, and coordination around containment, eradication, and recovery, but the technical execution, system isolation, remediation, and restoration, is generally carried out by internal operational teams or specialized responders unless explicitly contracted otherwise. Recognizing this boundary before an incident occurs helps set realistic expectations about who does what under pressure.
Who it's relevant to
Inside Containment, Eradication, and Recovery
Common questions
Answers to the questions practitioners most commonly ask about Containment, Eradication, and Recovery.