Blog post

On Three IR Gaps

By Anton Chuvakin | August 20, 2013 | 2 Comments

securityincident response

A useful concept that emerged in my security incident response research is a one of THREE IR GAPS.

  1. Detection gap
  2. Triage gap
  3. Remediation gap

Here is what I mean:

Stage before Gap Gap length Stage after
“Everything is fine!” Detection gap Days to years
“Oh no, this looks like an incident!”
We are having an incident Triage gap Hours to weeks We know the full scope of this one and we know how they got in
Investigation mostly complete, ready to fix it Remediation gap Days to weeks Incident remediated – next?


Posts related to the same research project:

The Gartner Blog Network provides an opportunity for Gartner analysts to test ideas and move research forward. Because the content posted by Gartner analysts on this site does not undergo our standard editorial review, all comments or opinions expressed hereunder are those of the individual contributors and do not represent the views of Gartner, Inc. or its management.

Comments are closed


  • H. Carvey says:

    There’s not really a great deal on which to comment….

  • That’s really not that much of a comment… 🙂