Skip to main content
Category: Incident Response

Containment, Eradication, and Recovery

Also known as: Containment, Eradication & Recovery
Simply put

Containment, Eradication, and Recovery is a core phase of responding to a cybersecurity incident, focused on stopping further damage and getting the organization back to normal. It involves isolating the affected systems, removing the underlying cause of the problem, and then restoring operations. This phase typically follows the detection or identification of an incident within a broader incident response process.

Formal definition

Containment, Eradication, and Recovery is a phase within the incident response life cycle in which responders act to limit the spread and impact of a confirmed incident, eliminate its root cause, and return affected systems to normal operation. Containment refers to the coordinated set of actions and technologies used to isolate, limit, or neutralize malicious activity within the IT environment; eradication is the process of eliminating the root cause of the incident with a high degree of confidence; and recovery restores affected systems and services to a trusted operational state. In many frameworks this phase follows identification/detection and precedes post-incident activity. In a virtual or fractional CISO context, security leadership typically advises on and directs the strategy and governance around these activities, while the hands-on execution, such as system isolation, remediation, and restoration, is generally performed by operational teams or specialized responders unless explicitly contracted otherwise.

Why it matters

Containment, Eradication, and Recovery is often described as the main phase of incident response because it is where an organization actively stops ongoing damage rather than simply observing it. Once an incident is confirmed, the speed and discipline with which responders isolate affected systems, remove the root cause, and restore trusted operations frequently determine the ultimate scope of business impact. A poorly coordinated response in this phase can allow malicious activity to spread, destroy evidence, or reintroduce the same compromise during recovery.

The distinct sub-steps exist for a reason that experienced practitioners insist on: containment without eradication leaves the root cause in place, and recovery without eradication risks restoring systems into an environment where the attacker still has a foothold. Eradication in particular is defined as eliminating the root cause with a high degree of confidence, a standard that guards against premature declarations of resolution. Rushing to restore operations before the underlying cause is understood is one of the more common and costly mistakes in incident handling.

For organizations relying on virtual or fractional security leadership, this phase highlights the difference between governance and hands-on operations. A vCISO or fractional CISO typically advises on and directs the strategy, decision-making, and coordination around containment, eradication, and recovery, but the technical execution, system isolation, remediation, and restoration, is generally carried out by internal operational teams or specialized responders unless explicitly contracted otherwise. Recognizing this boundary before an incident occurs helps set realistic expectations about who does what under pressure.

Who it's relevant to

Security and IT leaders
CISOs, IT directors, and their operational teams own the practical decisions in this phase, what to isolate, how to confirm the root cause has been eliminated, and when systems can be safely restored. They benefit from a plan that defines these steps clearly before an incident, rather than debating them under pressure.
Organizations engaging a virtual or fractional CISO
Buyers of vCISO or fractional CISO services should understand that such leadership typically advises on and directs the strategy and governance of containment, eradication, and recovery, while hands-on execution is generally handled by internal teams or specialized responders unless explicitly contracted. Clarifying this scope early prevents mistaken assumptions that a vCISO will personally perform system isolation or remediation.
Incident responders and operational teams
The specialists who execute isolation, remediation, and restoration rely on clear direction and a defined process to distinguish containment from eradication and recovery. Their work is most effective when the organization has established procedures and when eradication is held to the standard of eliminating the root cause with a high degree of confidence before recovery begins.
Executives and business stakeholders
Officers and business leaders retain organizational accountability for security decisions and need to understand why recovery should not be rushed ahead of eradication. Their cooperation, authorizing containment actions that may disrupt operations, for example, directly affects how quickly and safely the organization returns to normal.

Inside Containment, Eradication, and Recovery

Containment
The phase focused on limiting the scope and impact of an incident to prevent further damage or spread. Containment often distinguishes between short-term measures, such as isolating affected systems or disconnecting network segments, and longer-term measures that stabilize the environment while investigation continues. In many virtual CISO engagements, the vCISO advises on and directs containment strategy rather than personally executing hands-on isolation, which is typically carried out by internal teams or contracted incident response specialists.
Eradication
The removal of the underlying cause and artifacts of an incident, which may include eliminating malware, closing exploited vulnerabilities, disabling compromised accounts, and removing attacker footholds. Eradication is generally an operational activity; a virtual CISO usually provides oversight, validates that root causes are addressed, and ensures the effort aligns with the broader security program, while the technical execution often falls outside typical vCISO scope unless explicitly contracted.
Recovery
The restoration of affected systems and services to normal operations, often involving validation that systems are clean, monitoring for signs of recurrence, and phased return to production. In many engagements the vCISO advises on recovery prioritization and acceptance criteria from a business risk perspective, while accountability for the decision to resume operations typically remains with the client organization and its officers.
Evidence Preservation
The practice of capturing and protecting forensic evidence before and during containment and eradication so that investigation, potential legal action, or regulatory reporting is not compromised. Actions taken to contain an incident can inadvertently destroy evidence, so this element must be balanced against the urgency to limit damage.
Coordination and Communication
The governance activities that connect technical response to executive, legal, and stakeholder decision-making. A virtual CISO often plays a leadership role here, translating technical status into business risk terms and supporting decisions, though the value of this coordination depends heavily on access to stakeholders and defined scope.

Common questions

Answers to the questions practitioners most commonly ask about Containment, Eradication, and Recovery.

Does a virtual CISO personally carry out containment, eradication, and recovery during an incident?
Typically no. A virtual CISO advises on and directs the strategy behind these phases, helps ensure a response plan exists, and provides executive-level guidance during an event. The hands-on execution work such as isolating systems, removing malicious artifacts, rebuilding hosts, and restoring from backups is generally operational and falls outside a standard vCISO scope unless it is explicitly contracted. Confusing the advisory role with operational incident response is a common mistake; a vCISO is not a substitute for an incident response team, SOC, or managed security service provider.
If a vCISO oversees these phases, are they accountable for the outcome of the recovery?
Not usually. A virtual CISO can advise on and direct containment, eradication, and recovery activities, but legal and organizational accountability for security decisions typically remains with the client organization and its officers. The vCISO contributes leadership and judgment; the client generally retains responsibility for the outcome. Any transfer of accountability or liability would need to be spelled out in a contract, and this is uncommon in typical engagements.
How can a virtual CISO help an organization prepare for the containment, eradication, and recovery phases before an incident occurs?
In many engagements, a vCISO supports readiness by helping develop or review an incident response plan, defining roles and escalation paths, clarifying decision authority, and ensuring the organization understands the difference between containment, eradication, and recovery. They may also advise on preconditions such as maintaining tested backups, logging, and access controls. The value of this preparation often depends on organizational maturity, stakeholder access, and whether operational teams or external responders are in place to execute.
What should be defined in the engagement scope regarding these phases?
It is generally advisable to state explicitly whether the vCISO's role is advisory only or includes any hands-on execution, since hands-on containment, eradication, and recovery are typically out of scope by default. The scope should also clarify availability during an incident, who performs operational work, how the vCISO coordinates with internal teams or a retained incident response provider, and where decision authority sits. Clear scope reduces the risk of assuming the vCISO will replace an entire response team.
How does a virtual CISO coordinate these phases when the client relies on external providers or an MSSP?
A vCISO often acts as the client-side leadership point who directs strategy and translates between technical responders and business stakeholders. They may help set priorities during containment, validate that eradication addresses root cause rather than symptoms, and confirm recovery aligns with business needs. Because a vCISO is distinct from an MSSP, the practical arrangement depends on defined interfaces, agreed escalation, and the client's cooperation in granting access and making decisions.
How do relevant frameworks factor into how a vCISO approaches these phases?
Frameworks such as NIST CSF provide structure for organizing response and recovery activities, and a vCISO may use them to guide plan development and to check that containment, eradication, and recovery steps are addressed. However, following a framework supports readiness rather than guaranteeing any particular outcome; a vCISO engagement does not guarantee breach prevention or a specific recovery result. The effectiveness of framework-aligned planning varies by provider, scope, and the organization's maturity and cooperation.

Common misconceptions

A virtual CISO personally performs containment, eradication, and recovery during an incident.
A vCISO typically provides strategy, governance, and executive-level direction rather than hands-on operational execution such as isolating systems, removing malware, or restoring backups. These tasks are generally out of scope unless explicitly contracted, and are often carried out by internal teams, a SOC, or a dedicated incident response provider. Conflating a vCISO with a managed security service provider is a common error an expert would correct.
Containment, eradication, and recovery are strictly sequential and clearly separated phases.
In practice these phases often overlap and iterate. Containment may continue while eradication begins, and recovery frequently reveals residual issues that require further eradication. The distinct labels are useful for structuring response but should not be treated as rigid, one-directional steps.
Once recovery is complete, the incident is fully resolved and no residual accountability remains.
Completing recovery restores operations but does not by itself close out organizational accountability. Legal and regulatory accountability for security decisions usually remains with the client organization and its officers, and the effectiveness of the response depends on organizational maturity, client cooperation, and access to stakeholders rather than on the vCISO assuming liability.

Best practices

Define containment, eradication, and recovery responsibilities and scope in the engagement agreement, explicitly clarifying which activities the virtual CISO directs versus which the internal team or a contracted incident response provider executes.
Establish evidence preservation procedures before taking containment actions so that forensic, legal, and regulatory needs are not compromised by the urgency to limit damage.
Treat the phases as overlapping and iterative, revisiting containment or eradication when recovery surfaces residual compromise rather than assuming a strictly linear sequence.
Ensure the vCISO translates technical response status into business risk terms for executives and legal stakeholders, while keeping decision accountability clearly with the client organization and its officers.
Validate that root causes and attacker footholds have been addressed during eradication before authorizing recovery, and define clear acceptance criteria for returning systems to production.
Confirm that recovery includes heightened monitoring for recurrence, recognizing that the value of the response depends on organizational maturity, defined scope, and stakeholder cooperation.