Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is DFIR (incident response)?

DefinitionDFIR (Digital Forensics and Incident Response) is the discipline that combines incident response, which contains the attack and restores operations, with digital forensics, which collects and analyzes evidence to understand what happened, how and to what extent.

How it works

The classic response lifecycle, described in NIST SP 800-61, has four phases:

  1. Preparation: plan, roles, contacts, tools and exercises defined before the crisis.
  2. Detection and analysis: confirm the incident and assess severity and scope.
  3. Containment, eradication and recovery: isolate systems, remove the attacker's access and restore operations safely.
  4. Post-incident activity: lessons learned and control adjustments.

Revision 3 of SP 800-61, published in 2025, reorganized these recommendations around the functions of NIST CSF 2.0, treating response as part of risk management.

Forensics runs through every stage: it preserves memory, disks and logs, rebuilds the timeline and identifies the entry vector, the compromised accounts and the data accessed.

Why forensics matters

Without forensics, response tends to treat the symptom and leave the door open. Restoring servers without knowing how the attacker got in invites a repeat. Evidence also supports business decisions: notifying regulators and data subjects, filing insurance claims, legal action and reporting to the board.

Preserving evidence has rules: collect before shutting down or reinstalling systems, record who handled each item and ensure the integrity of copies.

DFIR vs SOC

The SOC monitors continuously and provides the first response. DFIR steps in when the incident requires in-depth investigation, crisis coordination and recovery. Both work best when the response plan defines this handoff in advance.

Network Secure offers an Incident Response service.

Frequently asked questions

What is the difference between DFIR and incident response?

Incident response focuses on containing the attack and restoring operations. DFIR adds digital forensics, which collects and analyzes evidence to explain what happened and to what extent.

Should I shut down a compromised computer?

In general, it is better to isolate it from the network without shutting it down, because powering off erases evidence that exists only in memory. Ideally, follow the response plan and call the responsible team.

Go deeper