Rev. 3 (April 2025) replaces the four-phase lifecycle of the 2012 predecessor (Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident Activity) with a model built around the six functions of the NIST CSF 2.0. Govern, Identify and Protect form the preparation: they prevent incidents, reduce their impact and anchor incident response in risk management. Detect, Respond and Recover constitute the actual incident response – from detection and analysis through containment and eradication to recovery, including notifications and communication. What is new is the role of continuous improvement: lessons learned feed back into all functions at any time via the Improvement category (ID.IM), not only after the incident has been closed.
Incident Response & digital forensics
How organisations detect, contain and investigate security incidents in a structured, court-admissible way – and which reporting deadlines run in parallel.
Security incidents are no longer rare exceptions: they occur frequently, and according to NIST, recovery often takes weeks to months. Incident response is therefore not an isolated process run by a specialist team, but an integral part of cyber risk management – which is exactly how NIST SP 800-61 Rev. 3 (April 2025) frames it, superseding the 2012 classic and aligning fully with the Cybersecurity Framework 2.0. In parallel to the technical response, regulatory clocks are ticking: NIS2 requires an early warning within 24 hours, and the GDPR a notification to the supervisory authority where feasible within 72 hours. Organisations that preserve evidence in a forensically sound manner from the outset keep all options open – from root cause analysis to criminal prosecution.
The Essentials at a Glance
Six topic blocks — tap to expand.
The IR lifecycle under SP 800-61 Rev. 3
Rev. 3 structures incident response along the six functions of the NIST CSF 2.0 — tap a phase.
- Prevents incidents and reduces their impact.
- Anchors incident response in risk management.
- From detection and analysis through containment and eradication to recovery.
- Recovery includes notifications and communication.
- Lessons learned feed back into all functions at any time via the Improvement category (ID.IM) — not only after the incident has been closed.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
Current IR guideline (April 2025), supersedes Rev. 2 of 2012; new lifecycle model along the six CSF 2.0 functions with ID.IM as a continuous improvement loop.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 23 reporting obligations: early warning within 24 hours, notification within 72 hours, final report no later than one month after the notification, informing the recipients of the services.
Verordnung (EU) 2016/679 (DSGVO)
Art. 33: notification of personal data breaches to the supervisory authority without undue delay and, where feasible, within 72 hours; Art. 34: communication to data subjects in case of high risk.
ISO/IEC 27037:2012 – Guidelines for identification, collection, acquisition and preservation of digital evidence
International guideline for the four basic steps of digital evidence preservation and for maintaining evidence integrity.
Cybersecurity Incident & Vulnerability Response Playbooks
Example playbooks referenced by NIST SP 800-61r3 with operational procedures for incident and vulnerability response.
NIST SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
Methodological framework for tabletop exercises, simulations and tests, referenced by SP 800-61r3 under ID.IM-02.
How resilient is your incident response capability?
In a no-obligation initial consultation, we jointly assess where your IR process stands today – from roles and playbooks to reporting channels and forensic readiness.