Incident Response Playbook Framework
Modular IR playbook framework covering preparation, detection, containment, eradication, recovery, and lessons learned.
SOC managers, IR leads, and consultants building IR capability for mid-market organisations.
A modular IR playbook framework aligned to NIST SP 800-61r2. Use it to build specific playbooks for the top incident types your organisation actually faces — not a generic one-size document that sits unread.
Why modular
A 60-page master playbook is the wrong shape. Teams need short, role-specific runbooks they can actually use at 2am. This framework gives you a common skeleton, then lets you fill in the specifics for the five incident types that matter most.
Prepare
- Named incident commander role — single point of decision authority
- Contact tree — internal (execs, legal, comms, tech leads) and external (MSSP, insurer, law enforcement, regulator)
- Out-of-band comms channel — Signal group, M365 Teams in a side tenant, or similar
- Pre-approved containment actions (isolate endpoint, disable account, block IP) with RACI
- Evidence preservation baseline — what logs, where, how long
Detect & analyse
- Source of alert captured with confidence score
- Initial scope set: user, host, tenant, data impacted
- Severity declared (P1/P2/P3) using a documented rubric
- Incident record opened with ticket ID, timestamps in UTC, and commander named
- First hypothesis recorded — reviewed every 30 min and updated
Contain
- Short-term: isolate endpoint, revoke sessions, reset credentials, block IP/domain
- Long-term: network segmentation, rebuild domain controllers, rotate service principals, re-image hosts
- Document every action in the incident record with a timestamp and actor
- Preserve volatile evidence before any destructive action
Eradicate & recover
- Identify root cause with evidence — not just symptom removal
- Remove persistence mechanisms (scheduled tasks, registry, service principals, forwarding rules)
- Restore from known-good backups only after the environment is verified clean
- Monitor intensively for 14 days after recovery — re-intrusion is common
- Formal exit criteria must be met before declaring closure
Lessons learned
- Post-incident review within 10 working days with everyone involved
- Timeline of events with decisions and rationale
- What went well / what didn't / what will change
- Tracked remediation actions with owners and due dates
- Distribution to leadership and retention as evidence for the ISMS
Top 5 playbook types to build first
- Business Email Compromise (BEC)
- Ransomware — early stage (encryption not yet run)
- Credential theft / phishing with session token replay
- Data exfiltration / insider access
- Cloud misconfiguration leading to exposure
CyberZonic runs engagements that turn material like this into evidence.
If you need help scoping the work, turning this into a project plan, or running the assessment itself, get in touch.


