NIS 2 Response Controls (RS): Containment and Eradication in Incident Handling

Containment and eradication are iterative response steps that limit damage and remove attacker persistence. Practical guide to strategy selection, evidence-driven verification, and handoff to recovery.

February 06, 2026 2 min read

Operations room during incident handling, with a manager on the phone Made with AI
Contents
  1. Key takeaways
  2. Containment and eradication operating sequence
  3. Minimum evidence set for containment/eradication
  4. 90-day execution checklist
  5. FAQ
  6. Related reading
  7. Official sources

In the NIS incident-response lifecycle, containment and eradication are the execution steps that limit damage and remove attacker persistence. Operationally, teams need pre-defined strategies, controlled tradeoffs, and evidence-driven verification to avoid service disruption or incomplete remediation.

Sources: ACN incident management guidance, ACN baseline obligations determination

Key takeaways

  • Containment and eradication are not one-off actions; they are iterative response activities.
  • Containment choices must balance evidence preservation, service continuity, and risk reduction.
  • Eradication should remove root compromise conditions and verify residual risk before closure.
  • Both phases require documented objectives, actions, rationale, and effectiveness checks.

Sources: ACN incident management guidance

Containment and eradication operating sequence

1. Define containment strategy

Select containment actions based on incident severity, business impact, evidence-preservation needs, and operational dependencies.

2. Execute and track containment actions

Apply technical and procedural controls (for example isolation, account controls, segmentation, temporary restrictions) and document decisions and impacts.

3. Verify containment effectiveness

Check whether compromise indicators persist; if they do, return to investigation and refine containment.

4. Plan eradication actions

Define actions to remove malicious artifacts, persistence mechanisms, and exposed weaknesses, with clear ownership and sequencing.

5. Validate eradication and transition

Confirm that eradication goals are met and that outputs are ready for downstream recovery and governance reporting.

Sources: ACN incident management guidance, ACN baseline obligations determination

Minimum evidence set for containment/eradication

RS phase Practical objective Typical evidence
Containment strategyRisk-informed and traceable action selectionContainment plan, decision rationale, impact notes
Containment executionControlled action rolloutAction log, change records, timeline updates
Effectiveness checksResidual-compromise validationVerification checklist, indicator review results
Eradication planningComplete removal strategyEradication plan, owner assignments, dependencies
Eradication closureVerified completion and handoff readinessClosure criteria record, residual-risk note, handoff package

Sources: ACN incident management guidance

90-day execution checklist

  1. Define containment decision criteria with legal, operations, and cyber stakeholders.
  2. Standardize containment action templates with mandatory rationale and impact fields.
  3. Establish objective effectiveness checks before moving to eradication closure.
  4. Create eradication play patterns for recurring attack scenarios.
  5. Require formal handoff package from eradication to recovery and post-incident review.

FAQ

Can containment and eradication be executed only once per incident?

Not always. Guidance indicates iterative loops may be required when new evidence or residual compromise emerges. Source: ACN incident management guidance

What should be documented for containment decisions?

At minimum: objectives, selected actions, rationale, expected impact, and criteria used to evaluate effectiveness. Source: ACN incident management guidance

How is eradication considered complete?

When planned eradication actions are verified, residual compromise is not detected, and records are ready for recovery and governance follow-up. Source: ACN incident management guidance

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 05, 2026

NIS 2 Response Controls (RS): Signaling and Investigation Operating Model

The NIS 2 Response (RS) domain requires structured incident response through signaling, investigation, and iterative decision loops. Practical guide …

February 18, 2026

NIS 2 Point of Contact and CSIRT Contact Role: Accountability and Operating Duties

NIS 2 implementation guidance distinguishes the legal Point of Contact from the operational CSIRT contact role. Practical guide to role formalization…

February 14, 2026

NIS 2 Documentary Evidence and Audit Readiness: How to Structure Compliance Proof

ACN baseline guidance requires documentary evidence as a core compliance element. Practical guide to evidence families, obligation-to-evidence mappin…