The DAIR model
The waypoints, outcomes, and response actions loop that replace a fixed sequence with a cycle responders can re-enter as new evidence appears.
Traditional frameworks like PICERL and NIST SP 800-61 treat response as a clean sequence: prepare, identify, contain, eradicate, recover. In practice, that sequence breaks down constantly. Attackers return after containment. Scope gets underestimated. Eradication efforts miss the persistence mechanisms that quietly restore access. The models aren't wrong, but they were built for a simpler era, and they don't hold up against how incidents actually unfold today.
Dynamic Incident Response introduces DAIR, a model built around explicit verification, triage, and iterative scoping steps, so responders can adapt as new evidence surfaces instead of forcing an incident into a sequence it never agreed to follow.
Useful for teaching the basics, but the sequence assumes attackers stay contained once you act, and that scope is knowable up front. Neither is reliably true.
DAIR treats those three steps as explicit parts of the model, not afterthoughts, so response can adjust as the picture of the incident changes.
Twenty chapters across three parts: the elements of incident response, the DAIR model itself, and how it plays out in the domains giving security teams the most trouble right now.
The waypoints, outcomes, and response actions loop that replace a fixed sequence with a cycle responders can re-enter as new evidence appears.
The explicit steps most frameworks skip: confirming an event is real before committing resources, and understanding the true extent of a compromise before declaring it contained.
Applying DAIR to ransomware and multi-vector extortion, from exfiltration detection to decryption assessment and backup strategy. Ransomware appears in 48% of breaches, up from 44% last year.
Identity-first containment, ephemeral resource investigation, and cloud-native recovery. Weak credentials, misconfigurations, and API compromises account for more than 80% of observed cloud initial access.
Where safety requirements and physical processes introduce constraints that don't exist in a typical IT incident.
Practical uses of generative AI in log analysis, playbook generation, and agentic workflows, with direct guidance on where to trust the output and where not to.
Full bios and headshots pending from the campaign team — specialties below are confirmed from the book itself.

Author · SANS Faculty Fellow, SEC504 author and instructor

SANS Certified Instructor · Ransomware and cyber extortion response

SANS Certified Instructor · Cloud incident response

SANS Principal Instructor · Operational technology and control systems
For 20 months, a team of SANS instructors and industry experts worked on a hard question: what would incident response look like if it matched how incidents actually unfold? The answer is Dynamic Incident Response, a free 720-page book introducing DAIR, a model built for incidents that don't follow a linear script.
Watch the recording of our launch livestream, where the panel walked through the DAIR model, took audience questions, and explained why the old response playbook needed rewriting.
Strand has known Wright for 20 years. Wright took over SANS SEC504 as author from Strand, just as Strand had taken it over from Ed Skoudis. His foreword traces that lineage and introduces the book.
The first time I ever saw Josh Wright, he was standing on a conference table in a hotel somewhere in Florida, acting out a scene where he had a suitcase in one hand and was rappelling from a helicopter with the other. It was completely ridiculous and absolutely perfect.
Right then and there, I knew something important. No matter how hard I worked to become the best instructor that SANS ever produced, that title was already taken. Josh had it. — John Strand, Owner, Black Hills Information Security
Dynamic Incident Response draws directly on the same real-world incident response practice taught in SANS SEC504, the course Josh has led for years. If the framework in this book is useful, the course is where it gets hands-on.
The SANS course Joshua Wright teaches, covering the practice this book's framework is drawn from.
A two-page visual reference covering the five DAIR waypoints, the Response Actions Loop, and domain guidance for ransomware, cloud, OT/ICS, and AI-accelerated incidents.
Free to read, share, and adapt under CC BY 4.0 — no purchase, no login required.