The Incident Response Lifecycle
What is it?
The response lifecycle: Preparation → Detection & Analysis → Containment → Eradication → Recovery → Lessons Learned. Preparation happens before any incident; the rest execute during and after one — and analysis keeps running through every later phase.
Why it matters
The lifecycle is the map that stops a team from skipping phases under pressure — the classic failure is jumping from detection straight to recovery with nothing eradicated.
Where you see it
Every incident ticket's status field, and every post-incident review that asks which phase failed.
What normal looks like
Phases completed in order with explicit exit criteria — containment does not end because people are tired; it ends because spread has stopped.
What suspicious looks like
A 'resolved' incident with no recorded eradication step, or recovery that started while containment was still uncertain.
How analysts investigate
By naming the current phase out loud, and asking what evidence proves this phase's exit criteria are met before moving on.
Common beginner mistakes
- Treating the lifecycle as strictly linear — analysis re-opens constantly as containment and eradication surface new evidence.
This is a refresher of the cycle you met in Cyber Foundations 6.7 — but from here on, this path treats each phase as its own discipline with its own decisions, evidence and exit criteria.
Quick check
During eradication, the responder finds a second persistence mechanism nobody had seen. Which phase does the team formally return to?
A quick self-check — it doesn't affect your XP or progress.
Sign in to save your progress on the server.