Skip to main content

The Six-Phase Methodology

How the Preparation → Detection → Containment → Eradication → Recovery → Lessons Learned framework works.

Every playbook in CrownSync Playbooks follows a structured six-phase incident response methodology. This framework is aligned with NIST Special Publication 800-61 (Computer Security Incident Handling Guide) and incorporates guidance from the National Cyber Security Centre (NCSC). By using a consistent structure across all playbooks, your team can build familiarity with the response process regardless of the specific incident type.

Phase 1: Preparation

Harden and Train

The Preparation phase covers everything your organisation should have in place before an incident occurs. This is the most proactive phase and focuses on reducing your attack surface, establishing response capabilities, and ensuring your team knows what to do when an incident is declared.

Key activities in this phase include:

  • Configuring security controls specific to the threat scenario (e.g., email filtering rules for BEC, endpoint detection for ransomware)
  • Establishing communication channels and escalation paths
  • Training staff to recognise indicators of compromise
  • Preparing forensic tools and evidence collection procedures
  • Documenting key contacts including legal counsel, insurers, and regulators
  • Running regular drills and exercises

Phase 2: Detection and Analysis

Identify and Assess

The Detection and Analysis phase guides your team through the initial identification of a potential incident and the assessment of its scope and severity. This is often the most time-critical phase, as the speed and accuracy of detection directly affects your ability to contain the threat.

Key activities in this phase include:

  • Identifying indicators of compromise (IoCs) specific to the incident type
  • Gathering initial evidence and preserving the chain of custody
  • Assessing the severity and potential impact to determine the response level
  • Notifying the incident response lead and assembling the response team
  • Beginning the incident timeline

Time-sensitive

Detection is where the ICO 72-hour notification clock starts ticking. As soon as you become aware of a personal data breach, you must assess whether it is reportable. See regulatory deadlines for details.

Phase 3: Containment

Quarantine the Threat

The Containment phase provides step-by-step guidance for isolating the threat to prevent further damage to your systems, data, and operations. Containment strategies vary significantly between incident types — containing a ransomware infection requires very different actions from containing a business email compromise.

Key activities in this phase include:

  • Implementing short-term containment measures (e.g., isolating affected hosts, blocking malicious domains)
  • Preserving evidence before making changes to affected systems
  • Assessing whether to take systems offline or maintain monitored access
  • Communicating containment status to stakeholders
  • Implementing long-term containment while eradication is planned

Phase 4: Eradication

Eliminate the Root Cause

The Eradication phase focuses on completely removing the threat from your environment. This goes beyond containment — while containment stops the bleeding, eradication ensures the attacker or vulnerability cannot cause further harm.

Key activities in this phase include:

  • Identifying and removing malware, backdoors, or compromised accounts
  • Patching the vulnerability that was exploited
  • Resetting credentials for all potentially affected accounts
  • Reviewing system configurations for unauthorised changes
  • Validating that all indicators of compromise have been addressed

Phase 5: Recovery

Restore Systems and Operations

The Recovery phase guides your team through safely restoring affected systems and returning to normal business operations. This phase requires careful validation to ensure that restored systems are clean and that the threat has not persisted.

Key activities in this phase include:

  • Restoring systems from verified clean backups
  • Rebuilding compromised systems where restoration is not possible
  • Implementing enhanced monitoring for signs of re-compromise
  • Gradually returning systems to production with validation checkpoints
  • Communicating recovery status and any ongoing restrictions to users

Phase 6: Lessons Learned

Improve and Adapt

The Lessons Learned phase is arguably the most valuable for long-term resilience. It provides a structured approach to reviewing the incident, identifying what worked well and what did not, and implementing improvements to prevent similar incidents in the future.

Key activities in this phase include:

  • Conducting a formal post-incident review within 10 working days
  • Documenting the complete incident timeline with root cause analysis
  • Identifying gaps in detection, response, and communication
  • Creating improvement actions with owners and deadlines
  • Updating playbook content based on real-world experience
  • Scheduling follow-up drills to validate improvements

Framework alignment

This six-phase methodology maps directly to the NIST SP 800-61 incident response lifecycle and is consistent with NCSC guidance on incident management. Organisations pursuing ISO 27001 certification will find that following this methodology supports compliance with Annex A controls for information security incident management.

Was this page helpful?