Eradication is the step in the Incident Response Process that determines whether you resolve an incident or prolong it. Containment stops the spread; recovery brings things back online. Eradication is the work in between: finding and removing the underlying cause so you are not dealing with the same problem weeks later.
Once containment puts out the immediate fire, recovery may appear to be in sight. But starting recovery before eradication is complete can restore the underlying cause. The cleanup you just did can be undone, accompanied by less patience from leadership and more public attention.
Symptom Versus Cause
Consider this example: an election staff member clicks a phishing link, and their account is used to send more phishing emails. The symptom is the outbound emails. The cause is the entry path that lets the click succeed.
Eradication of that incident is not just about stopping the emails. It also includes resetting credentials, checking settings the attacker may have changed, revoking active sessions, looking for any other accounts affected by the same source, and tackling whatever made the original click effective. That is often a missing multi-factor prompt, a filter rule that should have caught the message, or a permission that was broader than necessary.
If you only stop the outbound email, the account is still reachable, the rules are still in place, and the next phishing wave finds the door propped open.
Actions You Can Take
Containment is dramatic, recovery is satisfying, and eradication is quiet. Review the following actions with your IT, incident response team, and Election Security Working Group to support thorough eradication in the event of a cyber attack.
- Build a short eradication checklist for the most likely scenarios: phishing, ransomware, website defacement, and insider misuse. For each, write down what “root cause removed” specifically requires. That definition will help keep the incident response team honest under pressure.
- Name the eradication owner. One person must confirm the cause is gone before recovery begins. That person can use outside help, but the accountability is theirs.
- Require the two-question test before any recovery action. Before declaring eradication complete, two questions must be answered:
- How did this incident start?
- Is whatever allowed it to start no longer present?
If you cannot answer both clearly, you are not finished. That is not a failure; it is a signal to keep working or bring in help. Prematurely declaring eradication complete is the single most expensive mistake in this phase. Put this test in your incident response plan as a checkpoint, not a suggestion.
- Plan for help. Some root causes are beyond in-house capacity. Know in advance which incident types trigger a call to your State Fusion Center, FBI, or your contracted incident response firm.
- Keep eradication notes with the containment log. Our previous Planning Desk’s action steps described a containment log. Expand that same log to include notes on the eradication actions completed. This log serves as your audit trail and your post-incident learning record. Again, a shared or handwritten document with timestamps is fine. Memory is not.
Next week’s issue moves to recovery, the step that finally puts the office back together, carefully.
The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.
