Skip to content

Containment Strategy

Definition

A deliberate decision about how to limit an incident's spread, balancing the need to stop harm immediately against the risk of alerting an attacker before evidence is collected. Strategies range from immediate network isolation to monitored cohabitation (letting the attacker stay while evidence is gathered).

Range
Immediate isolation to monitored cohabitation
Core tension
Stop harm now vs preserve evidence and attacker visibility
Framework stage
Follows detection and scoping in the incident response lifecycle
Documented in
Incident response plan, chosen per incident

Common questions

Why would a team deliberately let an attacker remain active instead of isolating them immediately?+

Premature isolation can tip off a sophisticated attacker, causing them to destroy evidence, deploy destructive payloads, or disperse to new footholds, so monitored cohabitation is sometimes chosen to fully map the attacker's access and tools before acting.

What factors decide whether to contain quickly or observe first?+

Teams weigh the severity of ongoing harm such as active data exfiltration or ransomware deployment, legal and regulatory notification obligations, business impact of downtime, and confidence in monitoring coverage before choosing between rapid isolation and a watch-and-learn approach.

How does containment strategy differ from eradication?+

Containment is a short-term decision to limit spread and stabilise the situation, while eradication is the later, deliberate removal of the attacker's access, malware, and persistence mechanisms once the investigation has established the full scope of compromise.

Related terms

Eradication
The phase in which the root cause of an incident is removed from the environment: deleting malware, patching exploited vulnerabilities, revoking compromised...
After-Action Report (AAR)
The formal document produced during Lessons Learned that records the incident timeline, decisions made, outcomes, and recommended improvements. The AAR drives updates...
Incident Declaration
The formal decision, made during the Identification stage, that a detected event meets the organisation's criteria for a security incident. Declaration triggers...
Incident Response Lifecycle
The structured sequence of phases NIST SP 800-61 defines for handling computer security incidents: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity....
Incident Response Plan
A formal document that defines an organisation's approach to incident handling: roles and responsibilities, escalation paths, communication procedures, legal and regulatory obligations,...
Indicators of Compromise (IoCs)
Artefacts observed on a network or system that suggest an intrusion or malicious activity has occurred, such as unusual outbound connections, known-malicious...
Lessons-Learned Meeting
A structured post-incident review, recommended by NIST within approximately two weeks of incident resolution, that examines what happened, what the response did...
NIST SP 800-61
The US National Institute of Standards and Technology's Computer Security Incident Handling Guide. It defines a four-phase IR lifecycle: Preparation; Detection and...
PICERL
Acronym for the six SANS IR stages: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. The model is cyclical: the final stage...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.