PPIVTR-D

The lifecycle

Read it left to right. Scope, contain, eradicate and recover repeat until scoping stops turning up new evidence. Decision makers sit behind the whole sequence rather than inside any one phase, because every gate needs them.

Incident response lifecycle Preparation, Identification and Verification and Triage run left to right into a four part response actions loop holding Scope, Contain, Eradicate and Recover, which exits to Debrief. Gate conditions sit above each junction. A band behind the sequence marks continuous decision maker involvement. A dashed arrow returns from Debrief to Prepare. Decision makers, throughout Preparation Identification Verification and Triage Debrief Contain Eradicate Recover Scope Response repeat until no new evidence runs continuously event of interest verified, continue exit criteria met Debrief findings set the next Preparation cycle Incident response lifecycle The same lifecycle stacked vertically, with gate conditions between each waypoint and a repeat arrow on the response actions loop. Decision makers, throughout Preparation runs continuously Identification event of interest Verification and Triage verified, continue Response actions loop Scope Contain Eradicate Recover repeat exit criteria met Debrief Debrief findings set the next Prepare cycle
Each checkpoint sits above the junction it governs. Identification is drawn as continuous because it is. The dashed return path is the one most organizations never build.
The DAIR model: chevrons for Prepare, Detect, Verify and Triage, then a ring holding Scope, Contain, Eradicate and Recover, ending at Debrief.
Figure 22. The source model. Detect becomes Identification so the letters match PICERL, and the four activities in the ring are grouped under Response. Nothing else changes.

Why the loop is there

Figure 23 draws four activities as steps: isolate and gather evidence under contain, analyze and remove persistence under eradicate, each running once and in order.

Timeline with four activities as single segments, split between Contain and Eradicate.
Figure 23. The stepped view.

Figure 24 draws the same four as they actually run. Isolation happens three times, evidence gathering starts and stops four times, and analysis runs underneath it all from early on. Plan for the second picture. Status reporting built on the first one contradicts itself by the third update.

Timeline with the same four activities as recurring blocks across the full time axis, evidence analysis as one long bar.
Figure 24. The same work, as it actually runs.
The model with the background band behind all activities highlighted, marking decision maker involvement throughout.
Figure 25. The highlight covers the whole model, not one stage of it.

Where the model came from

PICERL is the cycle most responders already know: preparation, identification, containment, eradication, recovery, lessons learned. All of it is here.

What PICERL leaves implicit is verification, triage and scope. They happen in every incident whether or not a model names them, and the unnamed activity is the one that gets skipped under pressure.

Scope, contain, eradicate and recover share the R because they repeat. Giving each its own letter would claim they run once each in order, which is the mistake this model exists to correct.

LetterPhaseWhat it coversIn PICERL
PPreparationReadiness, authority, tooling, exercises, huntingPreparation
IIdentificationAlerting, detection and hunting, all running continuouslyIdentification
VVerificationEstablish that the event is an incident requiring a responseNamed here. Left implicit.
TTriagePrioritize the incident against organizational objectivesNamed here. Left implicit.
RResponseScope, contain, eradicate and recover, repeating until scoping produces nothing newContainment, Eradication, Recovery, plus scope named here
DDebriefClose the incident and convert it into changesLessons Learned

Verification and triage run together because both need the same conversation with decision makers. The hyphen marks where the incident ends and the closeout begins, and it stops the letters from being read as a word.

Start, work, finish, record

ActivityStarts whenCore workDone whenRecord produced
P. PreparationNo incident runningPolicy, authority, playbooks, backups, tooling, exercises, huntingNever closes. Reopened by every debrief.Authority matrix, playbooks, asset and contact lists
I. IdentificationTelemetry and reports flowingOperate detections, work alerts, hunt on a cadenceAn event of interest is raisedAlert or hunt finding with evidence references
V, T. Verification and triageEvent of interest raisedConfirm it requires a response, rank it against organizational objectivesContinue, stop, or defer, with a name against itIncident record, triage brief
R. Response (scope)Verified incident, one or more indicatorsDerive indicators, enterprise hunt, progressive sweep, attack timelineBreadth, systems involved and potential impact establishedScope findings, attack timeline
R. Response (contain)Reach of the compromise clear enough to actStop attacker activity, preserve evidence by volatilityThree validation channels show activity stoppedContainment decision record
R. Response (eradicate)Evidence collected and preservedShort-form investigation, remove persistence, rotate credentials, patchRerunning the original enumeration comes back cleanRoot cause, eradication log
R. Response (recover)Eradication verifiedVerification checks, validation testing, owner sign-off, restorationSystems in production under enhanced monitoringPre-restoration sign-off, owner acceptance
D. DebriefLoop exited and signedClose temporary assets, consolidate records, metrics, after-action reviewImprovement plan issued with owners and datesIncident report, metrics, improvement register
Adapts material from Dynamic Incident Response: A Framework for Security Teams by Joshua Wright, © 2026 The Escal Institute of Advanced Technologies, Inc. d/b/a SANS Institute, licensed under CC BY 4.0. Figures reproduced under that license. Changes were made. Not published by, endorsed by, or affiliated with the SANS Institute.