OTSecurity

SANS launches new Dynamic Incident Response framework to help security teams adapt as attacks evolve


SANS Institute published Dynamic Incident Response: A Framework for Security Teams by SANS Fellow Joshua Wright, the first major rebuild of the SANS incident response framework in two decades. The 720-page book is free in every digital format under Creative Commons, with contributed chapters on cloud, operational technology, and ransomware response.

An incident response team is deep into containment when new evidence changes the picture. What looked like a single compromised host is now a dozen systems across three business units. Traditional frameworks offer no guidance for that moment—they follow a linear path from preparation through recovery, unchanged for two decades, telling teams what to achieve at each stage but not how to adapt when circumstances shift. The new framework is built around how incidents actually unfold with shifting findings, evolving priorities, and attackers who adapt while teams respond.

Currently available, the book’s formats available include HTML chapters on the companion site, PDF, ePub, and Kindle. Readers who want a bound copy can order one through Kindle print-on-demand at printing cost, with no markup to SANS or to Wright. 

Eugene Schultz built the original process in 1990, and Stephen Northcutt and Alan Paller made it usable outside government with Computer Security Incident Handling: Step-by-Step, the SANS work this book succeeds. The new framework, the Dynamic Approach to Incident Response (DAIR), aligns to NIST guidance, the Cybersecurity Framework, and current Department of War guidance, and is the version taught in SEC504: Hacker Tools, Techniques, and Incident Handling, the flagship SANS incident handling course Wright authors and leads. 

“For years teaching incident response, I watched responders follow the process of prepare, identify, contain, eradicate, recover, and lessons learned. These models were built for a simpler era, and they don’t hold up against how incidents unfold today,” said Joshua Wright, SANS Fellow and Author of SEC504. “The book introduces DAIR, an adaptive, iterative model built for that reality. It is meant to supplement the excellent industry resources that already exist and give technical analysts the framework they need to respond to incidents more effectively.”

Wright announced the book from the stage at RSAC 2026 in March, after eighteen months of writing. Its twenty chapters span three parts: the elements of incident response, the DAIR model itself, and how the model plays out in the domains that give security teams the most trouble. Three chapters are contributed by SANS instructors writing in their areas of expertise: Megan Roddie-Fonseca on incident response in cloud environments, Dean Parsons on operational technology and control systems, and Ryan Chapman on ransomware and cyber extortion response.

“Joshua Wright has long been one of the most respected minds in cybersecurity, and this book shows exactly why. Dynamic IR challenges the traditional checkbox approach to incident response and replaces it with a practical, adaptive model built for the realities defenders face today,” wrote David Kennedy, Founder and CEO, TrustedSec and Binary Defense, in an endorsement of the book.



Source link