JOEY VICTORINO Independent Technical Judgment

Field Notes · Incident Command · 6 min read

The incident is contained. That does not mean it is closed.

Containment is an operational state: the adversary's known activity has been interrupted. Closure is a governance decision: leadership accepts, on evidence, that the scope is understood, the access is gone, the obligations are discharged, and the residual unknowns are known and tolerable. Between those two points sit several distinct states that incident communication routinely collapses into one announcement. This note separates them, describes the evidence each one actually requires, and lists the questions a board or GC should ask before accepting that an incident is over.

Five states, one announcement

Incident response doctrine has always treated containment, eradication, and recovery as distinct activities; NIST's incident response guidance carries that structure through its current revision. Executive communication tends to flatten them. When leadership hears "the incident is contained," what follows organizationally is often the behavior appropriate to "the incident is over." It is worth stating the states separately, because each one makes a different claim and rests on different evidence:

  1. Contained. The adversary's known activity has been interrupted: known malicious access blocked, affected accounts disabled, compromised hosts isolated. The operative word is known. Containment is scoped by what the responders have found so far.
  2. Eradicated. The adversary's footholds have been removed: persistence mechanisms, altered credentials, implanted tooling, rogue accounts, modified configurations. Eradication makes a stronger claim than containment, and it is only as strong as the search that supports it.
  3. Recovered. Business operations are restored. Systems are rebuilt or returned to service. Recovery is the state most visible to the organization, which is precisely why it gets mistaken for the end.
  4. Investigatively complete. The questions that determine obligations and residual risk have been answered as far as the evidence allows: how access was obtained, when, what was reached, what was taken or altered, and which identities can no longer be trusted. This state has no visible operational signature at all, which is why it is the one most often skipped.
  5. Closed. A decision, not a technical state: the accountable executives accept that the investigation's conclusions and its stated limits support ending the incident, discharging or scheduling the remaining obligations, and carrying the residual risk knowingly.

The first three states are operational and largely observable. The fourth is evidentiary. The fifth is governance. An organization that closes at state three has made a governance decision without the evidentiary state that justifies it, whether or not anyone framed it that way.

Different states, different evidence

The reason the distinction is not pedantry is that the evidence supporting each state is different in kind, not just in quantity. Containment evidence is evidence of action: connections blocked, credentials disabled, hosts isolated. It answers "did we do the things," and it can be complete while the underlying understanding is badly wrong, because it inherits the current estimate of scope.

Closure evidence is evidence of understanding. It looks like a supported intrusion timeline; an account of the access path; a persistence search that covered the estate rather than only the systems already known to be affected; an identity review that asked which credentials, tokens, and keys the adversary could have reached, not only which ones they were seen using; and a determination about data movement that is explicit about the telemetry it rests on.

That last point carries a distinction that experienced responders apply constantly and reports frequently blur: the difference between evidence of absence and absence of evidence. "We found no indication of data exfiltration" is a statement about what was observed within the coverage that existed. If network egress was not logged during the relevant window, the statement is true and nearly weightless. The strength of every "no evidence of X" conclusion is set by the coverage of the telemetry behind it, and an executive reading such a conclusion is entitled to have that coverage stated rather than implied.

Why closure arrives early

Premature closure is not usually a failure of competence. It is the product of pressures that all point the same direction at the same time. Executives are exhausted and want the organization back on its feet. Customer and regulator communications reward definitive language: "resolved" reads better than "contained, with investigation continuing." Insurance processes and legal posture push toward a bounded event with an end date. The response firm's engagement has a scope and a burn rate, and its final report will honestly describe what was examined within that scope; the narrowness of the scope is stated in the report and absent from the summary slide. And recovery, the visible state, is complete, so the organization's own senses report that the incident is over.

None of these pressures is illegitimate, and none of them is evidence. That is the structural problem: everything pushing toward closure is real, and nothing pushing toward closure bears on whether closure is justified.

What premature closure costs

The costs arrive on three timelines. Operationally, closure ends the heightened monitoring and the investigative posture, so remaining adversary access, if it exists, is now being watched less attentively at exactly the moment confidence is highest. Contractually and legally, closure statements become the record: notification decisions made on an incomplete scope estimate, customer assurances that "the incident is resolved," and board minutes accepting a conclusion all become exhibits if the scope estimate later grows. Organizations that must re-notify after announcing resolution pay more, in every currency, than organizations that stated uncertainty honestly the first time. And reputationally, a reopened incident reads as either incompetence or concealment, even when it is neither, because the earlier definitive language forecloses the honest explanation.

What a board should require before accepting closure

A board, GC, or accountable executive does not need forensic training to govern this decision. Seven questions, asked of whoever presents the closure recommendation, expose most of what matters:

  1. Which of the five states are we actually in, and what is the evidence for the one you are claiming?
  2. How was initial access obtained? If the answer is unknown, what prevents recurrence tomorrow?
  3. Which conclusions in the report rest on absence of evidence, and what was the telemetry coverage during the relevant period?
  4. Was the persistence and identity review scoped to the whole estate, or to the systems already known to be affected?
  5. What was outside the investigation's scope, by decision or by limitation, and who decided that was acceptable?
  6. What would we expect to observe if the adversary retained access, and are we instrumented to observe it for a defined period after closure?
  7. What specifically are we accepting by closing now, stated as residual risk in writing?

The seventh question converts closure into what it actually is: a risk acceptance. Boards accept risk routinely; what they should not do is accept it unknowingly, packaged inside an operational status update.

The strongest objection

The reasonable pushback is that incidents cannot stay open indefinitely, and perfect certainty is not available at any price. Both points are correct, and neither argues against the thesis. Closure under uncertainty is legitimate; investigation has diminishing returns, and a disciplined organization will often close with material questions unanswered. The requirement is not certainty. The requirement is that the uncertainty be stated, bounded, and accepted by the people accountable for it, rather than dissolved into the word "resolved." An organization that closes an incident while explicitly carrying "we could not determine the initial access vector; compensating controls X and Y address the plausible paths; monitoring Z runs for ninety days" has closed responsibly. An organization that closes the same incident with "no evidence of ongoing compromise" has the same facts and a different, weaker position.

Conclusion

Containment, eradication, recovery, investigative completeness, and closure are five different claims resting on different evidence. The first three can be demonstrated operationally; the fourth is a function of what was examined and what could be seen; the fifth is a governance decision that inherits its integrity from the fourth. The pressures that compress these states into a single "resolved" announcement are real and carry no evidentiary weight. Leadership's protection is procedural and inexpensive: require the state to be named, require the evidence behind it, require the unknowns in writing, and treat closure as the risk acceptance it is.

Related: Evidence Gaps Are Findings, on why what an investigation could not examine belongs in its conclusions, not its appendix.

Being asked to accept closure now?

The Incident Closure Review is an independent examination of whether the evidence supports the conclusion you are being asked to accept: the investigation record, the scoping decisions, the telemetry coverage behind each "no evidence of" statement, and what remains open. The deliverable is a written conclusion the board can rely on: the closure holds, holds with named conditions, or does not hold. Typically $20,000 to $30,000+ depending on scope.

Know a director or GC being asked to sign off on "resolved" this quarter? Send them this note.

Sources

← All Field Notes