Home EC-Council Certified Incident Handler (ECIH)

EC-Council Certified Incident Handler (ECIH)

EC-Council Certified Incident Handler (ECIH) logo

Global cybersecurity and incident handling/response specialists have worked together to build and produce the ECIH Certification. It is a specialist-level program, with CEH and CND serving as the "core" certifications that ECIH builds upon. ECIH educates security professionals on how to handle post-breach consequences by minimizing the impact of the incident, both financially and reputationally.

Exam Topics and Description
  • Introduction to Incident Handling and Response

    • Fundamentals of information security

    • Threats, attack vectors, and definition of an incident

  • Incident Management Process

    • Preparation, triage, and notification

    • Containment, evidence gathering, eradication, and recovery

  • First Response

    • Immediate actions during incidents

    • Evidence collection, documentation, and preservation

  • Incident Types

    • Handling malware incidents

    • Network security incidents

    • Web application incidents

    • Cloud security incidents

    • Insider threat incidents

  • Incident Response Automation & Orchestration

    • Tools and processes for automating response activities

  • Best Practices, Standards & Frameworks

    • Incident handling best practices

    • Standards and frameworks, including MITRE ATT&CK

  • Incident Handling Laws and Compliance

    • Legal and regulatory aspects of incident handling

    • Importance of compliance in response activities

  • Post-Incident Activities

    • Lessons learned and reporting

    • Information sharing and improvement of processes

Who Should Take This Exam?

The EC-Council Certified Incident Handler (ECIH) certification is designed for:

  • Incident Handlers
  • Risk Assessment Administrators
  • Penetration Testers
  • Cyber Forensic Investigators
  • Venerability Assessment Auditors
  • System Administrators
  • System Engineers
  • Firewall Administrators
  • Network Managers
  • IT Managers
Steps to Achieve Your EC-Council Certified Incident Handler (ECIH)
  1. Attend EC-Council Certified Incident Handler (ECIH)
  2. Pass the following exams:
  • ECIH (212-89)
Associated Courses and Exams
EC-Council Certified Incident Handler (ECIH)
EC-Council's Certified Incident Handler program equips students with the knowledge, skills, and abilities...
ECIH (212-89)
is designed to provide the fundamental skills to handle and respond to computer security incidents in an information system.
EC-Council Certified Incident Handler (ECIH) Renewal
  • No Renewal: Certification does not expire and requires no CPE credits.

  • Eligibility: About one year of information security experience recommended.

  • Focus: Skills for handling and responding to security incidents end-to-end.

  • Keep Current: Stay updated with new threats, tools, and future ECIH versions.

  • Next Steps: Consider advanced training or certifications like CHFI to stay relevant.

Do You Need Help? Please Fill Out The Form Below
First Name*
Last Name*
Business Email*
Phone Number*
What do you need assistance with?*
Best way to contact me*
How can we help you?*