← All resources
Guide18 min read · Updated 2026-04-06

Incident Response Playbook Framework

Modular IR playbook framework covering preparation, detection, containment, eradication, recovery, and lessons learned.

Who this is for

SOC managers, IR leads, and consultants building IR capability for mid-market organisations.

A modular IR playbook framework aligned to NIST SP 800-61r2. Use it to build specific playbooks for the top incident types your organisation actually faces — not a generic one-size document that sits unread.

Why modular

A 60-page master playbook is the wrong shape. Teams need short, role-specific runbooks they can actually use at 2am. This framework gives you a common skeleton, then lets you fill in the specifics for the five incident types that matter most.

Prepare

  • Named incident commander role — single point of decision authority
  • Contact tree — internal (execs, legal, comms, tech leads) and external (MSSP, insurer, law enforcement, regulator)
  • Out-of-band comms channel — Signal group, M365 Teams in a side tenant, or similar
  • Pre-approved containment actions (isolate endpoint, disable account, block IP) with RACI
  • Evidence preservation baseline — what logs, where, how long

Detect & analyse

  • Source of alert captured with confidence score
  • Initial scope set: user, host, tenant, data impacted
  • Severity declared (P1/P2/P3) using a documented rubric
  • Incident record opened with ticket ID, timestamps in UTC, and commander named
  • First hypothesis recorded — reviewed every 30 min and updated

Contain

  • Short-term: isolate endpoint, revoke sessions, reset credentials, block IP/domain
  • Long-term: network segmentation, rebuild domain controllers, rotate service principals, re-image hosts
  • Document every action in the incident record with a timestamp and actor
  • Preserve volatile evidence before any destructive action

Eradicate & recover

  • Identify root cause with evidence — not just symptom removal
  • Remove persistence mechanisms (scheduled tasks, registry, service principals, forwarding rules)
  • Restore from known-good backups only after the environment is verified clean
  • Monitor intensively for 14 days after recovery — re-intrusion is common
  • Formal exit criteria must be met before declaring closure

Lessons learned

  • Post-incident review within 10 working days with everyone involved
  • Timeline of events with decisions and rationale
  • What went well / what didn't / what will change
  • Tracked remediation actions with owners and due dates
  • Distribution to leadership and retention as evidence for the ISMS

Top 5 playbook types to build first

  • Business Email Compromise (BEC)
  • Ransomware — early stage (encryption not yet run)
  • Credential theft / phishing with session token replay
  • Data exfiltration / insider access
  • Cloud misconfiguration leading to exposure
Need help applying this?

CyberZonic runs engagements that turn material like this into evidence.

If you need help scoping the work, turning this into a project plan, or running the assessment itself, get in touch.