Anyone aligning an incident response plan to a recognized standard encounters the same complication: the lifecycle is described differently across the main institutional sources. The four-phase model from the United States National Institute of Standards and Technology (NIST), the six-phase PICERL mnemonic (preparation, identification, containment, eradication, recovery, lessons learned), the four-stage cycle in guidance from the UK's National Cyber Security Centre (NCSC), and the six Functions of the Cybersecurity Framework used in NIST's current publication are all in circulation. This guide sets out those models, the institutions that publish them, and the tooling that appears at each stage, with links to the primary sources throughout.
In short:
- The incident response lifecycle is the sequence of activities an organization carries out from preparing for an incident through to learning from it. Commonly cited enumerations include the six-phase PICERL mnemonic and the four-phase model in NIST SP 800-61 Revision 2.
- SP 800-61 Revision 3, published April 2025, is listed on NIST's catalogue as superseding Revision 2. Revision 3 organizes its recommendations by the Functions, Categories and Subcategories of the Cybersecurity Framework (CSF) 2.0, and includes a table mapping the previous life cycle phases onto the CSF 2.0 Functions.
- ISO/IEC 27035 from the International Organization for Standardization and International Electrotechnical Commission, response playbooks from CISA (the United States Cybersecurity and Infrastructure Security Agency), and the CSIRT (computer security incident response team) Services Framework from FIRST (Forum of Incident Response and Security Teams) describe related work at different scopes.
What is the incident response lifecycle?
The incident response lifecycle is the structured sequence of activities an organization carries out before, during and after a cyber security incident, running from preparation through detection and containment to post-incident review.
SP 800-61 Revision 3 defines a cybersecurity incident, citing the Federal Information Security Modernization Act of 2014, as "an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies."
The sequence is described as a lifecycle because the final stage feeds back into the first: findings from a post-incident review inform updates to the plan, the detection coverage and the playbooks used at the next incident.
Two adjacent disciplines are commonly grouped with incident response. FIRST's CSIRT Services Framework treats information security incident management as a service area covering incident reporting, analysis, coordination and recovery, where CSIRT stands for computer security incident response team. Disaster recovery and business continuity are separate disciplines covering restoration of operations and maintenance of essential functions during any disruption.
What are the six phases of the incident response lifecycle?
The six-phase model, known by the mnemonic PICERL, covers preparation, identification, containment, eradication, recovery and lessons learned. TryHackMe's Preparation room cites both NIST SP 800-61r2 and the SANS PICERL framework as reference models.
- Preparation. Everything put in place before an incident, including the response plan, defined roles, communications procedures and logging coverage. CISA's response playbooks and the UK National Cyber Security Centre's incident management collection both cover plan development, and TryHackMe's Preparation room frames it across people, documentation, technology and visibility.
- Identification. Recognizing that something has happened and establishing what, including triage, validation and scoping. MITRE ATT&CK, a globally accessible knowledge base of adversary tactics and techniques based on real-world observations, is commonly used to map observed behavior to known techniques here. Covered in Identification & Scoping and Detection and Analysis.
- Containment. Limiting the incident's spread while preserving the evidence needed to understand it, distinguishing short-term isolation from longer-term containment. Covered in Threat Intel & Containment.
- Eradication. Removing malware, unauthorized accounts and persistence mechanisms from the environment, along with closing the route in. Covered in Eradication & Remediation.
- Recovery. Returning affected systems to normal operation from a known-good state, typically under heightened monitoring. ISO/IEC 27035-3:2020 provides guidance for ICT incident response operations, and TryHackMe's Response and Recovery room works through it.
- Lessons learned. Structured review after service is restored, covering root cause, evidence retention and updates to plans and detection rules. ISO/IEC 27035-1:2023 includes the learning phase within the standard's core process, and TryHackMe covers it in Lessons Learned and Post-Incident Activity.
NIST's four-phase model in Revision 2 grouped containment, eradication and recovery into a single composite phase; PICERL separates those three. A six-phase lifecycle is sometimes attributed to NIST: Revision 2 set out four phases, and Revision 3 organizes around six CSF 2.0 Functions, which are not the same six items as PICERL's phases. TryHackMe's Incident Response module follows a single incident across five of the PICERL phases.
How did NIST's incident response guidance change in 2025?
In April 2025 NIST published SP 800-61 Revision 3. The Revision 2 PDF now carries a withdrawal notice dated 3 April 2025, stating that "NIST SP 800-61 Rev. 2 is withdrawn and superseded in its entirety by NIST SP 800-61r3." Revision 3 organizes its recommendations by the Functions, Categories and Subcategories of CSF 2.0 rather than by lifecycle phase. CSF 2.0 has six Functions: Govern, Identify, Protect, Detect, Respond and Recover.
Revision 3 refers to the four-phase diagram as "the incident response life cycle model illustrated in the previous version of this publication" and includes a table mapping each of those phases onto the CSF 2.0 Functions, with preparation mapping to Govern, Identify and Protect.
On the role of those first three Functions, Revision 3 states that "Govern, Identify, and Protect help organizations prevent some incidents, prepare to handle incidents that do occur, reduce the impact of those incidents, and improve incident response and cybersecurity risk management practices based on lessons learned from those incidents." The remaining three Functions cover the incident itself.
NIST's announcement of the revision, dated 3 April 2025, describes Revision 3 as incorporating incident response recommendations into cybersecurity risk management activities in alignment with CSF 2.0.
The four-phase model and PICERL remain in circulation across existing organizational plans, vendor documentation and training material. Revision 2 is listed as superseded on NIST's catalogue, so a reader relying on it as a current NIST source should be aware Revision 3 is now the current publication.
Which frameworks and standards define incident response?
Several institutional frameworks describe incident response, differing in scope and structure rather than in the underlying activities.
- NIST SP 800-61 Revision 3 (United States). Published April 2025, listed on NIST's catalogue as superseding Revision 2. Organizes incident response recommendations around the CSF 2.0 Functions, Categories and Subcategories.
- NIST SP 800-61 Revision 2 (superseded). Published 2012, and the publication in which the four-phase lifecycle appears.
- PICERL (six-phase). A mnemonic for preparation, identification, containment, eradication, recovery and lessons learned. Referenced in TryHackMe's Preparation room alongside NIST SP 800-61r2.
- ISO/IEC 27035 (International Organization for Standardization and International Electrotechnical Commission). A multi-part standard covering principles and process, planning and preparation and ICT incident response operations. Part 1, published 2023, describes a structured approach to preparing for, detecting, reporting, assessing and responding to incidents. ISO standards are purchased rather than published openly.
- **CISA (Cybersecurity and Infrastructure Security Agency) response playbooks (United States federal).**Checklist-style playbooks for incident and vulnerability response, published for federal civilian agencies.
- **FIRST (Forum of Incident Response and Security Teams) CSIRT Services Framework (international).**Groups the services an incident response team may provide into three service areas: information security event management, information security incident management, and vulnerability management. Version 2.1 states that "no CSIRT is expected to provide all described services."
- NCSC (UK National Cyber Security Centre) incident management guidance. Material on planning, response processes and communications, with guidance describing a four-stage response cycle of analyze, contain, remediate and recover.
- ENISA (European Union Agency for Cybersecurity). Publishes incident response material covering how to set up and operate a CSIRT or security operations center, alongside topical guidance for the EU CSIRTs Network.
What tools are used across the incident response lifecycle?
The functional categories of incident response tooling that recur across the frameworks above include log aggregation and search, endpoint visibility, network traffic analysis, forensic acquisition and analysis, threat intelligence, and case management. The rooms below indicate where each category is taught hands-on on TryHackMe, not a recommended toolset.
- Log aggregation and SIEM. Security information and event management platforms centralize log data for search and correlation, supporting coverage during preparation and triage during identification. Covered in Introduction to SIEM, with platform-specific work in Splunk: The Basics, Elastic Stack: The Basics and Log Analysis with SIEM.
- Endpoint detection and response. EDR platforms provide endpoint telemetry along with remote triage and containment actions, introduced in Introduction to EDR.
- Endpoint visibility and remote forensics. Tooling in this category supports collection and investigation across many endpoints at once, sitting between EDR and traditional forensics. Velociraptor is one such platform, covering endpoint monitoring, digital forensics and response.
- Network traffic analysis and intrusion detection. Packet capture and signature-based detection support identification and scoping, covered in Wireshark: The Basics, NetworkMiner, Snort and IDS Fundamentals, where IDS stands for intrusion detection system.
- Host and memory forensics. Acquisition and analysis of disk, memory and registry artifacts, largely serving identification and eradication. Taught through Volatility, Autopsy, KAPE, Redline, Windows Forensics 1 and Linux Forensics.
- Malware analysis. Establishing what a suspicious file does, which informs both scoping and eradication. See Intro to Malware Analysis.
- Threat intelligence. Enriching indicators and mapping behavior to known techniques, covered in Intro to Cyber Threat Intel and MITRE.
- Case management and orchestration. Recording findings, tracking actions and automating repetitive steps, where SOAR stands for security orchestration, automation and response. See TheHive Project and Introduction to SOAR.
For teams building capability across these categories, TryHackMe's Digital Forensics and Incident Response module and its blog on investigating, containing and recovering work through them hands-on.
FAQ
What are the six phases of the incident response lifecycle?
The six phases are preparation, identification, containment, eradication, recovery and lessons learned, referred to by the mnemonic PICERL. Other enumerations in circulation include a four-phase model in NIST Special Publication 800-61 Revision 2 and a four-stage cycle in UK National Cyber Security Centre guidance.
What is the difference between the four-phase and six-phase incident response models?
NIST SP 800-61 Revision 2 grouped containment, eradication and recovery into a single composite phase, giving four in total: preparation; detection and analysis; containment, eradication and recovery; and post-incident activity. The six-phase PICERL model separates those three into distinct phases. A six-phase lifecycle is sometimes attributed to NIST: Revision 2 set out four phases, and Revision 3 organizes around the six Cybersecurity Framework 2.0 Functions, which are not the same six items as PICERL's phases.
Did NIST change its incident response guidance?
In April 2025 NIST published SP 800-61 Revision 3, listed on NIST's catalogue as superseding Revision 2 (2012), the publication in which the four-phase lifecycle appears. Revision 3 organizes its recommendations around the six Functions of the Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond and Recover) rather than around lifecycle phases, and includes a table mapping the four earlier phases onto those Functions. NIST describes Revision 3 as incorporating incident response into cybersecurity risk management activities. The four-phase model remains widely referenced in existing plans and training material.
What tools are used for incident response?
Incident response tooling generally falls into a handful of categories: log aggregation and SIEM platforms, endpoint detection and response, endpoint visibility and remote forensics, network traffic analysis and intrusion detection, host and memory forensics, threat intelligence, and case management and orchestration. TryHackMe teaches these categories hands-on through rooms covering Splunk, Elastic Stack, Wireshark, Snort, Volatility, Autopsy, KAPE, Velociraptor and TheHive, among others.
How do you learn the incident response lifecycle in practice?
Working an incident end to end in a contained environment tends to build the pattern recognition that reading the phases in sequence does not. TryHackMe's Incident Response module follows a single incident across preparation, identification and scoping, containment, eradication and remediation, and lessons learned, and its SOC Level 1 path covers the detection and triage skills relevant to the earlier phases.
Guidance from NIST, CISA, NCSC, ENISA and FIRST is published openly. Details on team-level training are available at TryHackMe for Business.
