The 2026 InfoSec Playbook · Daniel Ramos

#Chapter 19 — Departmental Playbooks

Seven one-page playbooks — Finance, HR, Legal, Communications, Sales/CS, Engineering, Executive and Board — that give the people outside security a role they can actually perform, and that plug cleanly into the central incident response plan.

Who needs this: CISO, Incident Commander, CFO, CHRO, General Counsel, CCO, CRO, VP Engineering, CEO, Board Chair | Read time: 16 min | Maps to: CSF 2.0 GOVERN, RESPOND, RECOVER (GV.RR, GV.PO, PR.AT, RS.CO, RC.CO) | CIS 14, 17 | ISO/IEC 27001:2022 A.5.24, A.5.2, A.6.3, A.6.8

Fellow defenders, a confession to open with: most of us have written a beautiful incident response plan that exactly one department has ever read. Ours. It has an incident command structure, a severity schema, a decision tree and a version number. And on the morning it matters, the accounts payable clerk looking at a supplier email asking to update bank details has never heard of it, does not know they are the last control in the chain, and has fourteen minutes before the payment run closes.

That is not a plan failure. It is a distribution failure. A central plan nobody outside security has read is a document, not a capability — a document has a page count, a capability has a response time. NIST is blunt about where readiness lives: Preparation maps to three whole Functions (GOVERN, IDENTIFY, PROTECT), and 800-61r3 says those Functions "are not part of the incident response itself" (NIST SP 800-61r3). Translation? Most of your readiness is owned by people who do not report to you and will never read sixty pages.

So stop asking them to. The unit of distribution is one page per department, answering five questions in the same order: what will you notice first; what is your job in someone else's incident; what may you do without asking; how do you escalate; what do you check. Two rules govern all seven. The page never contradicts the plan — same severity scale (SEV-1 to SEV-4), same role names (Incident Commander, Operations Lead, Communications Lead, Scribe, Legal Liaison, Executive Sponsor), same clocks. And every page has a named owner in that department, exercised annually (Chapter 18 covers how).


#Finance

Finance is not a supporting department in a payment fraud incident. Finance is the control. There is no security tool between a convincing email and a released wire — there is a person, a procedure and a phone.

FBI IC3 recorded $20.877 billion in reported losses across 1,008,597 complaints in 2025, with BEC alone at $3.047 billion across 24,768 complaints (FBI). At Arup, a finance employee's scepticism about an email impersonating the UK-based CFO was overcome by a video conference in which every other participant was AI-generated; roughly US$25.6 million left in 15 transfers in one day (CNN).

Now the part that should decide your control design. Three documented deepfake attempts were stopped — Ferrari (an executive challenged the CEO voice clone with a shared-secret question about a recently recommended book), LastPass (an employee flagged that the CEO would not contact them by WhatsApp voicemail) and WPP (AI Incident Database; Adaptive Security; OECD AI Incidents). Every one was stopped by a human process check — a callback, a shared secret, a channel anomaly. Not one by detection technology. You cannot buy your way out of this; you can only proceduralize it.

Incidents Finance notices first: a supplier requesting a bank-detail change; urgency or secrecy framing on a payment; an invoice with correct references but a new remittance account; a payroll direct-deposit change; a duplicate invoice from a slightly different domain; an executive requesting a transfer over a channel they have never used; a customer insisting they paid an invoice you never received.

Verification procedure — payments and bank-detail changes. A control, not advice. No judgement calls.

#ActionWhoDone whenEvidence
1Freeze the request. No payment released, no vendor master edited, while verification is open.AP clerkMarked HELD-VERIFYReference, UTC timestamp
2Retrieve the counterparty phone number from the vendor master record or a signed contract only — never from the email, its signature block, its attachments, or a web search.AP clerkNumber sourced and recorded with its sourceRecord ID or contract ref
3Call that number; speak to a named, previously known contact; confirm verbally.AP clerkVerbal confirmation from a known individualName, number dialled, time
4For an internal executive request, apply the same callback to their known number plus the agreed challenge phrase. Video and voice are not identity.AP clerk or Finance ManagerChallenge answered correctlyChannel used, result
5Second-person approval by someone with independent access to the vendor record.Finance ManagerDual approval recordedBoth approver identities
6Release, or reject and report. A failed verification goes to security as suspected BEC, whether or not money moved.Finance ManagerReleased, or incident ticket raisedIncident ticket ID

The recovery clock. If money has moved, call the originating bank's fraud line first — before internal escalation, before counsel, before the CFO. Ask explicitly for a recall of the wire and a freeze at the receiving institution. Then report to law enforcement; in the US that is the FBI's Internet Crime Complaint Center at ic3.gov. Report even if the amount seems small — recovery works by aggregation across banks.

Ransom mechanics and the sanctions problem. OFAC's advisory applies strict liability — a U.S. person can face civil penalties for a sanctions-nexus transaction "regardless of intent or knowledge" — license applications carry a presumption of denial, and it is aimed explicitly at victims and at financial institutions, cyber-insurance firms, and forensic/IR firms (OFAC advisory, PDF; Morgan Lewis). Mitigating factors include prompt, complete reporting to law enforcement and CISA — documented diligence is the defense. So: Finance never initiates a payment; Finance executes one counsel has cleared. Gate order: sanctions screening via counsel → counsel sign-off → insurer notification → law enforcement report → disbursement. Payment triggers duties non-payment does not — NYDFS covered entities notify the Superintendent within 24 hours of an extortion payment, plus a 30-day written description of why it was necessary, alternatives considered, and diligence on sanctions and OFAC compliance (23 NYCRR 500.17); Australian reporting businesses have 72 hours (Home Affairs, PDF). Chapter 15 holds the full matrix.

Cyber insurance. Finance owns the policy, and the policy holds the clock that gets missed: notice is typically required "as soon as practicable," late notice is a live coverage-denial argument, and carriers commonly mandate panel vendors for forensics and breach counsel — engaging your own firm first can strand the cost outside coverage. Put the policy number, claims line and panel list on the same page as the bank fraud line. Chapter 12 covers coverage design.

Pre-authorized actions — Finance

ActionWho may authorizeLogged to
Hold any payment pending verification, at any valueAny AP staff member, unilaterallyFinance system + ticket
Call the bank's fraud line to attempt recallFinance Manager or above, without waiting for the ICIncident ticket
Freeze all outbound payments to a named counterpartyFinance ManagerIncident ticket
Suspend the entire payment runCFO or Executive SponsorIncident ticket + IC notified
Notify the cyber insurance carrier of a potential claimCFO or Legal LiaisonIncident ticket
Disburse any extortion paymentNobody without counsel sign-off and documented OFAC screeningCounsel file

Escalation: suspected BEC or payment fraud goes to the security escalation line immediately, at SEV-2 minimum if funds moved, regardless of amount. Finance hands the Operations Lead the full email headers, the vendor record change history, the payment reference, and the mailbox of everyone who touched the request.

Actionable takeaway: print the six-step procedure, tape it inside the AP cabinet, and run one unannounced test payment-change request per quarter against your own AP team. If a clerk releases it, you found a training gap for the price of an afternoon instead of the price of a wire.

The one-page checklist — Finance


#Human Resources

HR holds the two things an insider investigation needs most and the incident team is least equipped to supply: the authoritative record of who a person is, and the obligation to treat them like one.

Incidents HR notices first: a resignation from someone with privileged access, especially to a competitor; a performance case turning hostile; an employee reporting that a colleague asked for their credentials; a new hire whose identity documents, address or interview presence do not reconcile; a contractor whose working hours do not match their stated location. That last one matters more than it used to — Mandiant's 2026 data puts espionage and DPRK IT-worker cases at a 122-day median dwell (M-Trends 2026). A fraudulent employee is not a hiring problem security inherits later. It is an intrusion that entered through the applicant tracking system.

Joiner/mover/leaver is a security control, and mover is the one you are failing. Joiner and leaver get attention because they have tickets. Mover — the internal transfer — quietly accumulates entitlements, because new access is granted and old access is never removed. Ten years of movers is how you end up with a marketing manager who can still approve purchase orders. HR owns the trigger: a role change in the HRIS fires an access review for that individual, not merely a new-access request.

Offboarding, and the order that works. Two facts drive the sequence. A password reset alone does not evict a modern attacker or a determined leaver — refresh tokens are independent bearer credentials, access tokens can stay valid for up to 28 hours, and consented OAuth grants live indefinitely (Microsoft — Revoke user access; Continuous access evaluation), so sessions and credentials are revoked in the same action. And preservation precedes revocation — legal holds are not retroactive, and identity log retention windows are short.

#ActionWhoDone whenEvidence
1Confirm the termination time to the minute; notify IT and Legal before the conversationHR Business PartnerIT and Legal acknowledge in writingTimestamped notification
2Legal hold placed on mailbox, file storage and collaboration accountsLegal LiaisonHold confirmed in the eDiscovery toolHold reference and scope
3Export identity and access logs for the preceding retention windowOperations LeadExport complete and hashedManifest, hashes, UTC times
4Revoke sessions and reset credentials in one action; remove OAuth grants, devices, MFA methods, inbox rules, forwardingOperations LeadNo new tokens issued for the principalAction log, verification query
5Disable the account; retain it — do not delete — for the hold periodOperations LeadDisabled, retention flag setAccount state record
6Collect building credentials and hardware tokensHR / FacilitiesBadge deactivatedReturn receipt

Insider handling and the dignity requirement. An anomaly is not an accusation. Most insider signals resolve into something mundane — someone downloading their own portfolio, someone working odd hours because of childcare, someone querying an unfamiliar dataset because a manager asked them to. Encode this:

Evidence and privacy constraints. Monitoring and evidence collection sit inside employment law, works-council agreements and data protection, and the boundaries differ enormously by country — the page names which jurisdictions require consultation before monitoring and which require notice. The British Library recorded a lesson worth stealing: acceptable-use policy on personal data in network storage matters, because "the level of intrusion into the lives of individual staff members can be exacerbated where the use of network storage is allowed for personal use." When a breach hits, staff personal files are in the exfiltrated set.

When employee data is breached, employees are data subjects. Same clocks as anyone else, harder delivery, because the recipients are also the people executing the response: 72 hours to the supervisory authority under GDPR from becoming aware, and notice to individuals without undue delay where there is likely high risk to their rights and freedoms (Art. 33 GDPR), with US state floors on top — New York runs a hard 30 days, California's SB 446 sets 30 calendar days from discovery to notify residents, plus a sample notice to the AG within 15 calendar days of notifying consumers where more than 500 California residents are affected (Hunton; leginfo.ca.gov). Chapter 15 owns the decision tree; HR owns making sure employees are in it, and that HR delivers the message, with a staffed channel for the questions that follow.

The burnout dimension. NCSC notes incidents "often start with an intense period of activity, but many also have a 'long tail' with the impact lasting for months," and asks for deputy arrangements and out-of-hours coverage in the plan itself, plus a culture where people feel safe saying they are overwhelmed and safe raising concerns about a colleague (NCSC — staff welfare in incident response). The research says why rotation is a control and not a kindness: sleep deprivation leaves rule-following relatively intact but degrades exactly "the unexpected, innovation, revising plans, competing distraction, and effective communication" (Harrison & Horne 2000, PDF). A tired responder can still run your playbook. They cannot notice that the playbook stopped applying. HR's deliverables: a shift roster with named deputies, explicit authority to send someone home, pre-approved catering and transport, and an EAP contact printed on the page.

Pre-authorized actions — HR

ActionWho may authorizeLogged to
Request a legal hold on a departing or suspected employee's accountsHR Business Partner, via Legal LiaisonLegal hold register
Confirm identity and employment status for a security verification callbackAny HR team memberVerification log
Stand down a responder for rest, overriding their managerHR Business Partner or Executive SponsorIncident log
Approve emergency welfare spend (catering, transport, accommodation)HR DirectorFinance system
Initiate a suspension pending investigationHR Director with LegalHR case file
Disclose an insider investigation to a line managerNobody without HR Director and Legal agreementHR case file

Escalation: any credible insider signal goes to the Legal Liaison and the Incident Commander simultaneously — never to security alone, because the moment it becomes an employment matter the evidence rules change.

Actionable takeaway: measure one number and report it to the board — median minutes from termination time to session revocation, across the last twenty leavers. If you cannot compute it, that is the finding.

The one-page checklist — HR


Counsel's page is short, because counsel's job is to make about eight decisions nobody else may make — on day one, not retroactively.

Structure privilege before the first substantive assessment, or you will not have it. Three decisions narrowed privilege over forensic reports until the old habits stopped working. In re Capital One (E.D. Va. 2020): work-product held not to apply, report ordered produced to plaintiffs. Guo Wengui v. Clark Hill (D.D.C. 2021): no privilege, because the firm's "principal objective in securing the report was utilizing the external security consulting firm's expertise in cybersecurity, not in obtaining legal advice." In re Rutter's (M.D. Pa. 2021): no privilege, because the report "only discussed facts and did not involve 'opinions and tactics'" (Morrison Foerster).

What follows (Morrison Foerster, Six Considerations to Preserve Privilege): outside counsel retains the forensics firm, under a separate engagement for each incident, scoped explicitly to legal advice or anticipated litigation — telling an existing vendor to "report to counsel" is not sufficient. Keep any remediation report genuinely distinct rather than a summary of the protected one, to avoid waiver by derivation. Sharing privileged material with federal agencies can trigger broad waiver under FRE 502 — use confidentiality agreements or seek a Rule 502(d) order. And Austria, the Czech Republic, France, Italy, Luxembourg and Sweden do not extend privilege to in-house counsel, so structure cross-border matters with outside counsel as the hub.

Litigation hold runs before containment. The eDiscovery hold is the legal preservation instrument — it preserves content against deletion and retention expiry, including deletion by the attacker — while access telemetry is the scoping instrument. Different jobs; run the hold first (Microsoft — Create holds in eDiscovery). Holds are not retroactive, and log retention windows are short enough that a day's delay is a permanent loss. Where DFARS 252.204-7012 applies you also owe 90-day media preservation.

Discipline the record while it is being made. In the SEC's action against SolarWinds and its CISO, the complaint drew on internal presentations, emails and instant messages — including a 2018 internal presentation stating the remote-access setup was "not very secure" and that an attacker "can basically do whatever without us detecting it until it's too late" (SEC press release 2023-227). Counsel issues channel rules at declaration and the Scribe enforces them: facts and timestamps in the incident channel; opinions, blame, speculation and legal characterization nowhere. Distinguish "observed" from "assessed." No estimated record counts before they are verified. Assume every message is read aloud in a deposition — and record decision-making offline or on systems unaffected by the incident, because you still need a contemporaneous record for regulators (NCSC, PDF).

The contractual clocks are the ones you actually miss. Business associate agreements routinely compress HIPAA's 60 days to 5–15 days; customer MSAs increasingly demand 24–48 hour notification; DFARS §7012 flows down to subcontractors; cyber policies require notice "as soon as practicable." Counsel's peacetime deliverable is a contractual notification inventory alongside the statutory matrix in Chapter 15, tiered by customer and refreshed at each renewal.

The conflict to anticipate. SEC Item 1.05 delay is available only where the U.S. Attorney General determines disclosure poses a substantial risk to national security or public safety and so notifies the Commission — a narrow door, not available for ordinary law-enforcement convenience (SEC press release 2023-139). Meanwhile HIPAA, FCC rules and most state laws permit law-enforcement-directed delay of customer notice. You can be legally required to disclose on Form 8-K while the FBI is asking you to hold customer notification. Escalate the moment law enforcement is engaged.

Actionable takeaway: today — not after the next incident — put outside breach counsel on retainer, agree the per-incident forensic engagement template, and confirm the after-hours number works by dialling it. CISA's plain version: "Review your plan with an attorney. Your attorney may instruct you to use a completely different IRP template" (CISA IRP Basics, PDF).

The one-page checklist — Legal


#Communications and Marketing

The first public statement sets the tone for the entire incident — not the first week, the entire incident, including the litigation and the renewals eighteen months later. It is the sentence quoted in every subsequent article, and if it turns out to be wrong, the story stops being about the attack and becomes about you.

Which is why the most valuable thing Communications can do is refuse to say the reassuring thing. NCSC's rule is specific enough to laminate: "avoid saying anything that may have to be retracted later. For example… stating that there is no known impact on staff or personal data can be problematic later down the line if this understanding changes" (NCSC — effective communications in a cyber incident, PDF). At hour four you do not know the scope. Saying "no customer data was affected" then is a bet placed with the company's credibility at odds you have not calculated.

Incidents Comms notices first: a journalist calling with details you have not published; your name on a leak site; a customer posting a screenshot; a support-volume spike about a service engineering says is healthy. Each is an incident trigger in its own right — the reporter's call is often the earliest breach notification an organization gets.

The holding statement. Pre-draft it, pre-approve it with counsel, keep it under 100 words. It confirms you are aware and investigating; states what you are doing; says when you will next update, and then you hit that time; gives a channel for concerned customers; and stops. NCSC's standard is that communications be "clear, consistent, authoritative, accessible and timely," with accurate impact information and no hyperbole, avoiding speculation about cause, extent or attribution that could compromise future regulatory or law-enforcement investigations. Acknowledge the real-world human impact, not just technical facts — NCSC's example is a healthcare provider acknowledging canceled appointments.

Sequence: staff before public. Always. The British Library's rule is the one to copy — "staff always saw updated external communications… before the public, giving them the opportunity to digest the latest developments in advance of user queries," with comms designed to keep people updated "without sharing detail that could aid the attackers." Your employees get asked at the school gate. Send them the external statement fifteen minutes early, with a line saying what they may repeat and where to send everything else. And plan for the aftershocks: NCSC's earthquake metaphor has an initial shockwave, then leaked data, a regulator's penalty, a class action — each resurfacing the story months later. Name now the person who owns the story in month nine.

Pre-authorized actions — Communications

ActionWho may authorizeLogged to
Publish the pre-approved holding statement, unmodifiedCommunications Lead, unilaterallyIncident log
Publish a status-page update on availability only (no cause, no data claims)Communications LeadIncident log
Monitor and log media and social activity; escalate misinformationAny comms team memberIncident log
Modify the holding statement in any wayLegal Liaison + Incident CommanderCounsel file
Make any statement about cause, attribution, scope or dataNobody without Legal Liaison and Executive Sponsor sign-offCounsel file
Respond to a specific journalist questionCommunications Lead with Legal LiaisonCounsel file

Escalation: an inbound press query referencing non-public detail escalates immediately to the Incident Commander and Legal Liaison, and is itself a potential detection event.

Actionable takeaway: write the holding statement now, get counsel to approve it now, and put it where the Communications Lead can reach it from a personal phone when the corporate network is gone. A statement that needs the intranet to retrieve does not exist. Chapter 15 owns the customer notification content and template set.

The one-page checklist — Communications


#Sales and Customer Success

Sales and CS occupy an uncomfortable seat: the closest relationships with the people most affected, the least information, and the strongest personal incentive to reassure. That combination is how an incident acquires a second, self-inflicted problem.

Incidents Sales and CS notice first: a customer reporting invoices from you with unfamiliar bank details; a customer receiving a strange email from your domain; several accounts reporting the same anomaly on the same day; a request to authorize a new connected application in the CRM. That last is not hypothetical. In the 2025 Salesforce campaign, attackers vished employees posing as internal IT and induced them to authorize a malicious Connected App granting OAuth access — no platform vulnerability involved, roughly 91 organizations claimed as victims (Krebs on Security; ReliaQuest). The CRM is a crown-jewel data store and the person holding the consent button usually sits in Sales Ops. Changing a password does not revoke a consented OAuth grant (FBI IC3 warning via Help Net Security).

"Were we affected?" — the most important script on the page. Every account manager will be asked, often before scoping is complete. One acceptable answer, memorized:

"I don't have that answer, and I'm not going to guess with something this important. We have a dedicated team working on exactly this question, and I'm logging your request right now so you get a definitive answer from the right people. Here is what I can tell you today: [approved status statement]. I'll come back to you by [committed time], even if the answer then is still 'we're working on it.'"

Then log it. Every such question is a data point for the response team — the pattern of who is asking often reveals scope faster than telemetry does.

May sayMay not say
The approved public status statement, verbatimAnything about cause, attribution or the attacker
"We are investigating and I will come back to you by [time]"Any estimate of records, accounts or customers affected
"Your request is logged with the response team""You were not affected" / "Your data is safe"
Where to find the official status pageAnything from the internal incident channel
Confirmed availability facts already publishedAny commitment on remediation dates or compensation

Security questionnaires during an incident. The sharpest legal edge in the department. A questionnaire answer is a written representation by your company, and an answer that was true last quarter can be a misrepresentation today — the SolarWinds action shows how internal statements and customer-facing security claims get read together in enforcement. So: during a declared SEV-1 or SEV-2, all outbound security questionnaires, trust-centre updates, audit responses and contractual security representations pause and route to the Legal Liaison. Not "reviewed by security." Paused. A delay is explainable; a false attestation is not.

The security-review bottleneck. Outside incidents, the questionnaire queue adds three weeks to every enterprise deal — and it is also a security asset, a live inventory of what customers contractually expect of you. Fix it structurally: a current answer library owned by security, a trust centre publishing the evidence customers ask for most (SOC 2 or ISO certificate, pen test summary, subprocessor list, DPA), and only genuine exceptions routed to a human. Then measure median days from questionnaire receipt to response and report it as a security metric, because it is one. A slow queue produces bypass, and bypass produces salespeople answering security questions themselves.

Pre-authorized actions — Sales and CS

ActionWho may authorizeLogged to
Read the approved status statement to any customerAny account managerCRM activity log
Log a customer "were we affected" request into the response queueAny account managerIncident ticket
Escalate a customer report of fraud or a suspicious email from your domainAny account manager, immediatelyIncident ticket
Send any written incident-related communication to a customerCommunications Lead + Legal LiaisonCounsel file
Answer a security questionnaire during a declared SEV-1/SEV-2Nobody — routed to Legal LiaisonCounsel file
Offer credits, remediation commitments or contractual concessionsExecutive Sponsor with LegalCounsel file

Escalation: customer-reported fraud goes to the Incident Commander directly, not through the account team's manager. "Let me check with my manager first" costs hours, and in a payment-fraud case hours are money.

Actionable takeaway: print the "were we affected" script on a card and give it to every customer-facing employee this quarter. Then test it — have someone from marketing call three account managers posing as an anxious customer, and count how many improvise a reassurance.

The one-page checklist — Sales / CS


#Engineering and IT Operations

Engineering's page is the shortest and the hardest, because engineering's instincts are correct for outages and wrong for intrusions. In an outage you restore service as fast as possible. In an intrusion, restoring service as fast as possible destroys evidence, tips off the adversary and frequently reintroduces the intrusion. The muscle memory that makes a great SRE is exactly the muscle memory that has to be interrupted.

Preserve before you remediate. CISA gates eradication explicitly: before moving to eradication, ensure "(1) all means of persistent access into the network have been accounted for, (2) the adversary activity is sufficiently contained, and (3) all evidence has been collected," and "coordinate with ICT service providers, commercial vendors, and law enforcement prior to the initiation of eradication efforts" (CISA Playbooks, PDF). AWS's EKS security guidance states the cloud-native version even more directly — gather forensic evidence before removing a node, because an attacker may attempt to destroy evidence through termination. Deleting a pod destroys the container writable layer and in-memory state, and with a Deployment triggers a replacement that may re-run the attacker's payload from the same compromised image.

The minimum capture set before any wipe, ordered by volatility: physical memory image; process and network state; the EDR investigation package; Windows event logs (Security, System, PowerShell Operational with script-block and module logging, Sysmon if present); Prefetch, Amcache, SRUM, ShimCache, registry hives, $MFT and $UsnJrnl; scheduled tasks, services and autoruns; browser artefacts; and a disk image or cloud snapshot where the host is materially in scope. Preserve the reason too — artefact hashes, collector version, operator name, UTC timestamps.

Change freeze authority. During a declared SEV-1 or SEV-2, routine change stops — not because change is dangerous, but because unlogged change destroys your ability to distinguish attacker activity from your own. Deployments, config pushes, patch rollouts, IaC applies and schema migrations pause; the exception path is a single named approver (Operations Lead), and every approved change goes into the incident log with its purpose.

Do not play whack-a-mole. Mandiant's account of piecemeal containment describes the chain precisely: responders remove known compromised systems and feel accomplished, "the responders 'tip their hand' to the attacker," and the attacker — using backdoors on systems the responders do not know about — abandons the burned tooling and takes steps to ensure continued access. The alternative is a posturing phase in which "administrators should not change compromised accounts' passwords, block C2 infrastructure or rebuild compromised systems," used instead to appoint a remediation lead, secure executive support, build the plan and enhance logging — followed by a single remediation event, typically 24–48 hours, that does everything at once and then validates it was actually done (Mandiant / Aldridge, Black Hat USA 2012, PDF). Aldridge is explicit that whack-a-mole remains correct in some cases — cash being stolen in near real time, for instance. That is the Incident Commander's call, not engineering's.

The interface with IR. Engineering does not run the incident; it executes containment and recovery under the Incident Commander. Two boundaries need writing down. Who can stop a production service: Colonial Pipeline's CEO testified the company learned of the attack shortly before 5am and within roughly an hour decided to shut down the entire pipeline (Blount testimony, PDF). The lesson is not "shut down fast." It is that the decision was made in under an hour by a named person who already knew it was theirs. Write it per critical service: who can stop it, who must be told, what evidence justifies it, and the default if that person is unreachable in 15 minutes. And your MSSP's authority boundary — NIST r3 warns the contract must state restrictions on a provider "making and implementing operational decisions (e.g., immediately deactivating certain services to contain an incident)." That boundary is almost always undefined until it is tested at 2am by someone else's analyst.

Pre-authorized actions — Engineering / IT Ops (log after the fact; no approval needed)

ActionWho may authorizeLogged to
Isolate a single endpointOn-call engineerIncident log
Block a C2 IP or domain at egressOn-call engineerIncident log
Disable a single user account or revoke its sessionsOn-call engineerIncident log
Snapshot a volume; capture memoryOn-call engineerEvidence manifest
Enterprise-wide credential resetIncident CommanderIncident log + counsel file
Disconnect a site or the internet edge; stop a production service; rebuild a fleetIncident Commander, escalating to Executive SponsorIncident log + exec brief

Escalation: declare by observable triggers rather than judgement — a second team is required, customers see a disruption, or the issue persists beyond one hour of focused analysis (Google SRE Book). Declare early; managed incidents resolve faster.

Actionable takeaway: add a hard gate to your incident tooling so a host cannot be reimaged nor a node terminated while an incident ticket is open unless an evidence manifest is attached. Make the correct order the path of least resistance, because at hour nine nobody reads the page.

The one-page checklist — Engineering


#The Executive Team and the Board

Executives get the shortest page and the heaviest decisions. The failure mode here is not ignorance; it is presence. Executives join the war room, ask for real-time detail, and the Incident Commander spends the incident briefing rather than commanding. The fix is structural: a fixed cadence, a named liaison, and a short list of what only they may decide.

The briefing cadence. Roughly every 30 minutes during the acute phase, delivered by the Internal Liaison and not by the Incident Commander, kept short and to the point (PagerDuty). The IC's most important responsibility is maintaining a single living incident document (Google SRE Book); the executive brief is a read of that document, not a separate investigation. Four items, every time: what we know, what we have done, what we need a decision on, when we brief next. Anything outside those four waits.

Materiality, and what the clock actually measures. The most misunderstood clock in the book. SEC Item 1.05 requires a Form 8-K within four business days — but the four days run from the registrant's determination that the incident is material, not from discovery, and the determination must itself be made "without unreasonable delay" after discovery (SEC press release 2023-139). Three consequences belong on the executive page. You cannot stop the clock by not deciding — an indefinitely deferred determination is itself a violation, and undisclosed material facts create Rule 10b-5 exposure independent of Item 1.05. Convene the assessment on a documented cadence from the first hours, recording attendees, inputs and conclusion each time; the record of how you assessed matters as much as the conclusion. And Item 1.05 is for material incidents only — SEC staff clarified that voluntary disclosure of non-material incidents belongs under Item 8.01 (Gerding statement, May 2024).

Decisions reserved to the executive team. One screen: stopping a revenue-generating service; approving an enterprise-wide reset or fleet rebuild; authorizing an extortion payment subject to counsel's sanctions clearance; approving any public statement about cause, scope or attribution; engaging law enforcement; notifying regulators; declaring the incident closed and the recovery accepted.

On the payment decision, NCSC's joint guidance with the insurance industry gets the process right: "the ultimate decision whether to pay the ransom is with the victim," and — the design instruction — "make sure the options aren't presented prematurely and that you provide the strongest possible evidence base." Don't panic; attackers engineer time pressure. Investigate root cause first, because paying "without clarifying the original source for the compromise… leaves your organization open to further incidents." And note the ICO "doesn't consider a payment to criminals… as a risk mitigation" and it "wouldn't reduce the amount of any penalty" (NCSC, PDF).

Exercise the executives separately first. NIST SP 800-84 is explicit: "senior-level teams and operational-level teams should participate in separate tabletop exercises initially because of their different levels of responsibility," combining them only afterwards to validate coordination (SP 800-84, PDF). If your only tabletop is a combined one, the executives watch the technical team work and learn nothing about their own decisions. Chapter 18 has the design.

Actionable takeaway: put the reserved-decision list and the four-item brief format in front of the leadership team at the next meeting, and ask each person to name the one decision that is theirs. If two people claim the same decision, or nobody claims one, you have found the gap that will cost you an hour when an hour is the whole budget.

The one-page checklist — Executives and Board


#Making the pages real

Seven pages, one owner each, one exercise a year each. That is the whole program, and it works without a budget line; the expensive version buys you a facilitator and a printing bill.

Three habits keep them alive. Version them with the plan, so a change to the severity schema propagates to every page in the same change. Test by observation, not attestation — do not ask Finance whether they verify bank changes; pull ten changes and look for the call log. And fix findings with owners and due dates, the CISA after-action discipline: every exercise finding becomes an issue with an owner and a due date, tracked to closure (CISA CTEP).

One last framing, and it comes from the fatigue research rather than from security. Playbooks work because they convert novel judgement into rule-following, and rule-following is the mode that survives stress and sleep loss — as true for an accounts payable clerk at 4:45pm on a Friday as for a responder at hour fourteen. The departmental page is not a simplified plan for people who cannot handle the real one. It is the part of the plan that actually executes.

Distribute widely, verify by callback, and remember: the plan you handed out beats the plan you wrote.


#Chapter checklist


#Sources

  1. NIST SP 800-61r3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management — https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf
  2. NIST SP 800-84, Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities — https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-84.pdf
  3. CISA, Federal Government Cybersecurity Incident and Vulnerability Response Playbooks — https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
  4. CISA, Incident Response Plan (IRP) Basics — https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf
  5. CISA, I've Been Hit By Ransomware! — https://www.cisa.gov/stopransomware/ive-been-hit-ransomware
  6. CISA, CTEP Package Documents — https://www.cisa.gov/resources-tools/resources/ctep-package-documents
  7. FBI, Cryptocurrency and AI scams bilk Americans of billions (IC3 2025 report) — https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
  8. FBI Internet Crime Complaint Center — https://www.ic3.gov
  9. CNN, Arup deepfake scam — https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
  10. AI Incident Database, Ferrari voice-clone attempt — https://incidentdatabase.ai/cite/966/
  11. OECD AI Incidents Monitor, WPP deepfake attempt — https://oecd.ai/en/incidents/2024-05-10-e24d
  12. Adaptive Security, deepfake attack case summaries (LastPass) — https://www.adaptivesecurity.com/blog/11-deepfake-attack-examples-2026
  13. Mandiant / Google Cloud, M-Trends 2026 — https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
  14. Coveware by Veeam, Cyber extortion payment trends Q2 2026 — https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
  15. Sophos, State of Ransomware 2026 — https://www.sophos.com/en-us/blog/sophos-state-of-ransomware-2026
  16. OFAC, Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments — https://ofac.treasury.gov/system/files/126/ofac_ransomware_advisory.pdf
  17. Morgan Lewis, analysis of the OFAC updated advisory — https://www.morganlewis.com/pubs/2021/10/ofac-issues-updated-advisory-on-sanctions-risks-for-facilitating-ransomware-payments
  18. NCSC, Guidance for organizations considering payment in ransomware incidents — https://www.ncsc.gov.uk/files/Guidance-for-organizations-considering-payment-in-ransomware-incidents.pdf
  19. NCSC, Guidance on effective communications in a cyber incident — https://www.ncsc.gov.uk/files/NCSC-Guidance-on-effective-communications-in-a-cyber-incident.pdf
  20. NCSC, Putting staff welfare at the heart of incident response — https://www.ncsc.gov.uk/guidance/putting-staff-welfare-at-the-heart-of-incident-response
  21. British Library, Cyber Incident Review (8 March 2024) — https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf/
  22. Harrison, Y. & Horne, J.A. (2000), The impact of sleep deprivation on decision making: A review — https://fatiguemanagersnetwork.org/wp-content/uploads/Harrison-et-al.2000_-The-Impact-of-Sleep-Deprivation-on-Decision-Making.pdf
  23. NYDFS, 23 NYCRR 500.17 (Cornell LII) — https://www.law.cornell.edu/regulations/new-york/23-NYCRR-500.17
  24. Australian Department of Home Affairs, ransomware payment reporting factsheet — https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf
  25. Directive (EU) 2022/2555 (NIS2), EUR-Lex — https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555
  26. Article 33 GDPR — https://gdpr-info.eu/art-33-gdpr/
  27. Hunton, New York data breach notification law updated — https://www.hunton.com/privacy-and-information-security-law/new-york-data-breach-notification-law-updated
  28. California SB 446 (leginfo.ca.gov) — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB446
  29. SEC press release 2023-139, cybersecurity disclosure rules — https://www.sec.gov/newsroom/press-releases/2023-139
  30. SEC small-entity compliance guide, cybersecurity risk management and incident disclosure — https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/cybersecurity-risk-management-strategy-governance-incident-disclosure
  31. SEC, Gerding statement on cybersecurity incident disclosure (May 2024) — https://www.sec.gov/newsroom/speeches-statements/gerding-cybersecurity-incidents-05212024
  32. SEC rulemaking activity, 2026 — https://www.sec.gov/rules-regulations/rulemaking-activity?year=2026
  33. Sidley, SEC Chair Atkins announces initiative to reform Regulation S-K — https://www.sidley.com/en/insights/newsupdates/2026/01/sec-chair-atkins-announces-initiative-to-reform-regulation-s-k
  34. SEC press release 2023-227, SolarWinds and CISO charges — https://www.sec.gov/newsroom/press-releases/2023-227
  35. Morrison Foerster, Six Considerations to Preserve Privilege — https://www.mofo.com/resources/insights/231010-six-considerations-to-preserve-privilege
  36. Morrison Foerster, Federal court decision underscores (privilege over forensic reports) — https://www.mofo.com/resources/insights/231010-six-considerations-to-preserve-privilege
  37. Microsoft Purview, Create holds in eDiscovery — https://learn.microsoft.com/en-us/purview/edisc-hold-create
  38. Microsoft Entra, Revoke user access — https://learn.microsoft.com/en-us/entra/identity/users/users-revoke-access
  39. Microsoft Entra, Continuous access evaluation — https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-continuous-access-evaluation
  40. Krebs on Security, ShinyHunters wage broad corporate extortion spree — https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/
  41. ReliaQuest, Threat spotlight: ShinyHunters data breach targets Salesforce — https://reliaquest.com/blog/threat-spotlight-shinyhunters-data-breach-targets-salesforce-amid-scattered-spider-collaboration/
  42. Help Net Security, FBI IC3 warning on OAuth consent phishing — https://www.helpnetsecurity.com/2026/09/02/oauth-consent-phishing-fbi-warning/
  43. Mandiant / Aldridge, Remediating Targeted-threat Intrusions, Black Hat USA 2012 — https://media.blackhat.com/bh-us-12/Briefings/Aldridge/BH_US_12_Aldridge_Targeted_Intrustion_WP.pdf
  44. Broadcom/VMware, What is an IRE/Clean Room? — https://techdocs.broadcom.com/us/en/vmware-cis/live-recovery/live-cyber-recovery/saas/configuring-the-ransomware-recovery-isolated-recovery-environment/what-is-an-ire-clean-room.html
  45. Joseph Blount, testimony to the U.S. Senate Homeland Security and Governmental Affairs Committee, 8 June 2021 — https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/Testimony-Blount-2021-06-08.pdf
  46. Google, Site Reliability Engineering — Managing Incidents — https://sre.google/sre-book/managing-incidents/
  47. PagerDuty Incident Response documentation — https://response.pagerduty.com/during/during_an_incident/
This page is one chapter of The 2026 InfoSec Playbook, a free field manual by Daniel Ramos. Checklist statuses and the live coverage model are in the full manual. Free, in full, no email wall.