The Security Incident Response Playbook gives a company a calm, prepared set of first steps for a suspected breach.
First-Response Flow
| Step | What to do | What not to do |
|---|
| 1. Detect and confirm | Recognize the signs and confirm something is wrong. | Do not ignore it or assume it is nothing. |
| 2. Contain | Disconnect or isolate affected systems and accounts. | Do not keep using the affected system. |
| 3. Call for help | Contact the MSP, security vendor, insurer, and advisor. | Do not handle a serious incident alone. |
| 4. Preserve | Keep logs and affected systems intact. | Do not wipe, rebuild, or delete anything yet. |
| 5. Communicate | Inform leadership; follow professional guidance on external notice. | Do not notify customers or the public before legal guidance. |
Key Contacts
| Role | Name | Phone | When to call |
|---|
| Internal incident owner | | | First |
| MSP / IT support | | | Contain and preserve |
| Security vendor | | | Medium and above |
| Cyber insurer | | | High and above, early |
| Legal counsel | | | Before external notice |
| Fractional CTO / advisor | | | To coordinate |
Severity Guide
| Level | What it looks like | Response |
|---|
| Low | Contained, no sensitive data, no business impact | Handle internally, log it |
| Medium | Limited spread or possible data exposure | Bring in MSP or security vendor |
| High | Active spread, likely data exposure, or disruption | Full response; call insurer and advisor |
| Critical | Business-stopping, confirmed sensitive breach, or ransomware | Full response plus legal and executive involvement |
Response Step Card
| Field | Entry |
|---|
| Step | |
| What to do | |
| What not to do | |
| Who owns this step | |
| Who to contact | |
Post-Incident Review
| Question | Notes |
|---|
| What happened and how did it start? | |
| How well did the first hour go? | |
| What would have reduced the impact? | |
| What do we change (risk register, controls, training)? | |