GRC Careers

HomeResourcesIncident Response: Containment

CS-095 · Incident Response

Incident Response: Containment

Stopping the spread of an active incident to limit damage while preserving evidence.

Executive Summary

Containment is the phase where the team acts to stop an active incident from spreading and to limit the damage it can do. It buys time and space to investigate and remove the threat without letting it get worse. The central tension is speed versus care: stop the bleeding fast, but do it without destroying the evidence needed to fully clean up.

What It Is

Containment is the third phase of the incident response lifecycle. Once an incident has been identified and scoped, containment applies the actions that keep it from spreading further and reduce its impact. Practitioners often split it into short-term containment, the immediate moves to stop active harm such as isolating a compromised host or disabling an abused account, and long-term containment, the more durable measures that keep the threat in check while eradication is planned, such as applying temporary access restrictions or rebuilding affected systems onto a clean segment. In the lifecycle described by NIST SP 800-61 and SANS incident handling, containment sits between identification and eradication. Done well, it stabilizes the situation so the team can work deliberately rather than react in panic.

Why It Matters

An uncontained incident keeps getting worse, and the cost of a breach often rises sharply with how long an attacker stays active. Fast, correct containment is frequently what separates a minor incident from a company-wide crisis. But containment carries real risk of its own: cut too broadly and you cause an outage the business feels immediately, act too hastily and you may wipe the evidence needed to find every foothold or to satisfy legal and regulatory obligations. Tipping off a sophisticated attacker can also cause them to accelerate or destroy data. For professionals, the judgment to contain decisively while protecting evidence and minimizing business disruption is a hallmark of an experienced responder and a common differentiator in senior incident response roles.

How It Works

Containment starts from the scope determined during identification and chooses a strategy that fits the incident type, the value of the affected systems, and the business impact of the containment action itself. Short-term steps stop active harm quickly: isolating hosts from the network, disabling or resetting compromised credentials, blocking malicious domains and addresses, and revoking suspicious sessions. Where possible, responders capture forensic images and memory before making changes, so evidence survives. Decisions are guided by predefined criteria and, ideally, pre-authorized actions so the team does not stall waiting for approval mid-crisis. Long-term containment keeps the threat controlled while the team prepares to remove it fully, for example moving cleaned systems to a hardened segment or applying temporary rules. Throughout, the team keeps documenting actions and timing, because those records feed eradication, recovery, and the lessons-learned review.

Architecture Diagram

IdentificationContainmentEradicationRecoveryLessons Learned
Containment is the third phase: it takes the scoped incident from identification and stabilizes it for eradication.

Visual Workflow

Confirm scope from identification and choose a containment strategy for the incident type.Preserve evidence first where feasible, capturing images and memory before making changes.Apply short-term containment: isolate hosts, disable compromised accounts, block indicators.Weigh business impact and use pre-authorized actions to avoid delay on critical steps.Apply long-term containment to keep the threat controlled while eradication is planned.Document every action and its timing to support the phases that follow.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

EDR
Isolates endpoints from the network and blocks malicious processes during containment
Firewall and network controls
Block malicious domains and addresses and segment affected systems
Identity and access management
Disables or resets compromised accounts and revokes active sessions
Forensic imaging tool
Captures disk and memory evidence before systems are changed

Industry Standards

NIST SP 800-61
Computer Security Incident Handling Guide covering containment strategy selection
NIST SP 800-86
Guidance on integrating forensic techniques so containment preserves evidence
NIST Cybersecurity Framework (CSF) 2.0
The Respond function frames containment activities

Career Relevance

Containment is where incident responders and DFIR analysts make some of the highest-stakes calls in security, and where security engineers implement the technical controls that isolate threats. SOC analysts often perform the first short-term containment steps under playbook guidance. The blend of speed, technical action, and business judgment makes containment a common focus in senior incident response interviews for roles listed on AI-Governance-Jobs.com.

Interview Questions

Related Certifications

GIAC Certified Incident Handler (GCIH) GIAC Certified Forensic Analyst (GCFA) CompTIA CySA+

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

What is the difference between short-term and long-term containment?

Short-term containment is the immediate action to stop active harm, such as isolating a host or disabling an account. Long-term containment is the more durable measure that keeps the threat controlled while the team prepares to remove it fully, such as moving cleaned systems to a hardened segment or applying temporary access rules.

Should we always image a system before containing it?

Capture evidence first whenever it is feasible, because rebooting or reimaging can destroy volatile data needed to find every foothold and to meet legal needs. In extreme cases where harm is spreading fast, stopping the damage may take priority, but that trade-off should be a conscious, documented decision.

Can containment make an incident worse?

It can if handled carelessly. Overly broad isolation can cause outages, and a hasty move can alert a sophisticated attacker or wipe evidence. The goal is decisive action guided by scope, evidence preservation, and business impact, not reflexive action.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

GIAC Certified Incident Handler (GCIH)GIAC Certified Forensic Analyst (GCFA)CompTIA CySA+

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: Incident Response: Containment
  3. Go deeper: Incident Response: Preparation
  4. Go deeper: Incident Response: Identification
  5. Validate it: work toward GIAC Certified Incident Handler (GCIH)
  6. Find the role: browse current openings

Related sheets

More in Incident Response

Share this LinkedIn Facebook X Email