DFIR
DFIR (Digital Forensics and Incident Response) combines two disciplines: investigating a security incident to establish what happened, and containing and recovering from it while preserving usable evidence.
What is DFIR?
Definition
DFIR (Digital Forensics and Incident Response) joins two disciplines usually described apart: digital forensics, which establishes what happened and preserves evidence that will hold up in a legal or contractual dispute, and incident response, which detects, contains and recovers from the attack while it is still unfolding. Running them together matters because under time pressure they pull in opposite directions — the fastest way to stop an intrusion is often the fastest way to destroy the evidence of it. In cybersecurity practice DFIR is the function that decides, in the moment, how much evidence is worth the delay.
Role in cybersecurity
DFIR plays an important role in building organizational resilience against cyber threats. Implementing appropriate mechanisms in this area is required by regulations such as NIS2, DORA and ISO 27001.