Skip to content
Cyberbezpieczeństwo

DFIR

DFIR (Digital Forensics and Incident Response) combines two disciplines: investigating a security incident to establish what happened, and containing and recovering from it while preserving usable evidence.

What is DFIR?

Definition

DFIR (Digital Forensics and Incident Response) joins two disciplines usually described apart: digital forensics, which establishes what happened and preserves evidence that will hold up in a legal or contractual dispute, and incident response, which detects, contains and recovers from the attack while it is still unfolding. Running them together matters because under time pressure they pull in opposite directions — the fastest way to stop an intrusion is often the fastest way to destroy the evidence of it. In cybersecurity practice DFIR is the function that decides, in the moment, how much evidence is worth the delay.

Role in cybersecurity

DFIR plays an important role in building organizational resilience against cyber threats. Implementing appropriate mechanisms in this area is required by regulations such as NIS2, DORA and ISO 27001.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist