The Security Incident Response Playbook gives a company a calm, prepared set of first steps for a suspected breach.

First-Response Flow

StepWhat to doWhat not to do
1. Detect and confirmRecognize the signs and confirm something is wrong.Do not ignore it or assume it is nothing.
2. ContainDisconnect or isolate affected systems and accounts.Do not keep using the affected system.
3. Call for helpContact the MSP, security vendor, insurer, and advisor.Do not handle a serious incident alone.
4. PreserveKeep logs and affected systems intact.Do not wipe, rebuild, or delete anything yet.
5. CommunicateInform leadership; follow professional guidance on external notice.Do not notify customers or the public before legal guidance.

Key Contacts

RoleNamePhoneWhen to call
Internal incident ownerFirst
MSP / IT supportContain and preserve
Security vendorMedium and above
Cyber insurerHigh and above, early
Legal counselBefore external notice
Fractional CTO / advisorTo coordinate

Severity Guide

LevelWhat it looks likeResponse
LowContained, no sensitive data, no business impactHandle internally, log it
MediumLimited spread or possible data exposureBring in MSP or security vendor
HighActive spread, likely data exposure, or disruptionFull response; call insurer and advisor
CriticalBusiness-stopping, confirmed sensitive breach, or ransomwareFull response plus legal and executive involvement

Response Step Card

FieldEntry
Step
What to do
What not to do
Who owns this step
Who to contact

Post-Incident Review

QuestionNotes
What happened and how did it start?
How well did the first hour go?
What would have reduced the impact?
What do we change (risk register, controls, training)?