You're now leaving SANS.org for dynamicincidentresponse.com, the book's official page, to read online, download a copy, or explore companion resources.
Free for the community

Dynamic Incident Response

A practical framework for security teams handling real-world incidents where new findings, shifting priorities, and active attackers make response anything but linear.

Joshua Wright headshot Author Joshua Wright SANS Faculty Fellow · View SANS profile
  • Contributors on ransomware, cloud, and operational technology
  • AI-accelerated response, including MCP and agentic workflows
  • Maps directly to NIST CSF 2.0

Free to read, share, and adapt · CC BY 4.0, no purchase required

Why this book matters

Incident response rarely follows the linear path that traditional response models describe.

Traditional frameworks like PICERL and NIST SP 800-61 treat response as a clean sequence: prepare, identify, contain, eradicate, recover. In practice, that sequence breaks down constantly. Attackers return after containment. Scope gets underestimated. Eradication efforts miss the persistence mechanisms that quietly restore access. The models aren't wrong, but they were built for a simpler era, and they don't hold up against how incidents actually unfold today.

Dynamic Incident Response introduces DAIR, a model built around explicit verification, triage, and iterative scoping steps, so responders can adapt as new evidence surfaces instead of forcing an incident into a sequence it never agreed to follow.

Traditional approach

Linear, and confident until it isn't

Useful for teaching the basics, but the sequence assumes attackers stay contained once you act, and that scope is knowable up front. Neither is reliably true.

DAIR approach

Built around verification, triage, and scope

DAIR treats those three steps as explicit parts of the model, not afterthoughts, so response can adjust as the picture of the incident changes.

What you’ll learn

A framework, and the specific situations it has to hold up in.

Twenty chapters across three parts: the elements of incident response, the DAIR model itself, and how it plays out in the domains giving security teams the most trouble right now.

01

The DAIR model

The waypoints, outcomes, and response actions loop that replace a fixed sequence with a cycle responders can re-enter as new evidence appears.

02

Verify, triage, and scope

The explicit steps most frameworks skip: confirming an event is real before committing resources, and understanding the true extent of a compromise before declaring it contained.

03

Ransomware response

Applying DAIR to ransomware and multi-vector extortion, from exfiltration detection to decryption assessment and backup strategy. Ransomware appears in 48% of breaches, up from 44% last year.

04

Cloud incident response

Identity-first containment, ephemeral resource investigation, and cloud-native recovery. Weak credentials, misconfigurations, and API compromises account for more than 80% of observed cloud initial access.

05

Operational technology

Where safety requirements and physical processes introduce constraints that don't exist in a typical IT incident.

06

AI-accelerated response

Practical uses of generative AI in log analysis, playbook generation, and agentic workflows, with direct guidance on where to trust the output and where not to.

Contributors

Domain expertise in the areas giving responders the most trouble.

Full bios and headshots pending from the campaign team — specialties below are confirmed from the book itself.

Joshua Wright headshot

Joshua Wright

Author · SANS Faculty Fellow, SEC504 author and instructor

Ryan Chapman headshot

Ryan Chapman

SANS Certified Instructor · Ransomware and cyber extortion response

Megan Roddie-Fonseca headshot

Megan Roddie-Fonseca

SANS Certified Instructor · Cloud incident response

Dean Parsons headshot

Dean Parsons

SANS Principal Instructor · Operational technology and control systems

Launch event recording

Launch Party: Dynamic Incident Response Book

For 20 months, a team of SANS instructors and industry experts worked on a hard question: what would incident response look like if it matched how incidents actually unfold? The answer is Dynamic Incident Response, a free 720-page book introducing DAIR, a model built for incidents that don't follow a linear script.

Watch the recording of our launch livestream, where the panel walked through the DAIR model, took audience questions, and explained why the old response playbook needed rewriting.

DateSeptember 15 Time12:00 PM ET (16:00 UTC)
Host
Rich Greene
Panelists
  • Joshua Wright — SANS Faculty Fellow
  • Megan Roddie-Fonseca — SANS Certified Instructor
  • Dean Parsons — SANS Principal Instructor
  • Ryan Chapman — SANS Certified Instructor
From the foreword

John Strand, Owner of Black Hills Information Security, on watching Josh Wright teach.

Strand has known Wright for 20 years. Wright took over SANS SEC504 as author from Strand, just as Strand had taken it over from Ed Skoudis. His foreword traces that lineage and introduces the book.

The first time I ever saw Josh Wright, he was standing on a conference table in a hotel somewhere in Florida, acting out a scene where he had a suitcase in one hand and was rappelling from a helicopter with the other. It was completely ridiculous and absolutely perfect.

Right then and there, I knew something important. No matter how hard I worked to become the best instructor that SANS ever produced, that title was already taken. Josh had it. — John Strand, Owner, Black Hills Information Security
Go deeper

The book is free. The path to going deeper runs through SANS.

Dynamic Incident Response draws directly on the same real-world incident response practice taught in SANS SEC504, the course Josh has led for years. If the framework in this book is useful, the course is where it gets hands-on.

02

Free DAIR model poster

A two-page visual reference covering the five DAIR waypoints, the Response Actions Loop, and domain guidance for ransomware, cloud, OT/ICS, and AI-accelerated incidents.

Coming Soon
Ready when you are

Modern incident response is iterative. Your framework should be too.

Free to read, share, and adapt under CC BY 4.0 — no purchase, no login required.