The reference tables that answer "who does what, who decides, and who do I wake up" — designed to be printed and read under pressure.
Who needs this: Incident Commander, Operations Lead, Communications Lead, Scribe, Legal Liaison, Executive Sponsor, on-call responders | Read time: 15 min | Maps to: CSF 2.0 GOVERN (GV.RR), RESPOND (RS.MA, RS.CO) | CIS v8.1 Control 17 | ISO/IEC 27001:2022 A.5.2, A.5.24, A.6.8
Every table in this appendix exists because of one line in CISA's post-incident guidance. Among the objectives it sets for a hotwash is "reviewing and updating roles, responsibilities, interfaces, and authority to ensure clarity" (CISA Federal Playbooks). It is on the list because it keeps coming off the back of real incidents. Nobody discovers mid-crisis that they lack a SIEM. They discover that four capable people are each waiting for one of the other three to say yes.
Everything below is a default. Adopt it whole if you have nothing; edit it if you have something. Where a row does not match how you actually work, change the row — in peacetime, in the document, with a date on it. Chapter 13 defines these roles and the severity scale; this appendix is the reference sheet you print.
Six core roles staff every SEV-1 and SEV-2. The supporting roles are called in by need, not by default. One person may hold two roles at SEV-3 and below; at SEV-1 the Incident Commander holds nothing else.
| Role | Responsibilities | Decisions owned | Must escalate | Deputized by |
|---|---|---|---|---|
| Incident Commander (IC) | Runs the response: sets the objective, assigns work to named people with time boxes, maintains the living incident document, controls the bridge | Severity; declaration and closure; task priority; who joins or leaves the bridge; anything in the pre-authorized register | Stopping a revenue or safety-critical service; spend beyond a set threshold; any external notification | Deputy IC, named at declaration |
| Operations Lead | Directs all technical workstreams; the only role that assigns hands-on-keyboard tasks; owns the technical plan and its sequencing | Tooling and method; which host to image first; sequencing of a remediation event; when a workstream is blocked | Any action affecting production availability or risking evidence; bringing in an external forensics firm | Named SME per workstream (identity, endpoint, network, cloud) |
| Communications Lead | Internal and external messaging; executive update cadence; holding statements; monitoring for misinformation | Wording and timing of approved internal updates; channel selection; which questions get "we do not yet know" | Any external statement or press response; anything naming a threat actor, cause or record count | Comms deputy from corporate communications |
| Scribe | Contemporaneous timeline: what happened, when, and what decisions were made and by whom; flags each entry observed or assessed | Nothing. The Scribe records | Any decision made with no named owner, or a clock started with no owner — to the IC immediately | Second scribe on shift rotation |
| Legal Liaison | Privilege posture, legal hold, regulator and law-enforcement engagement, insurer notification, contract obligations | Privilege structure; legal hold; whether counsel retains the forensics firm; what goes in a counsel-directed channel | Materiality determinations; regulatory filings; ransom-payment posture — to the Executive Sponsor with counsel | Outside breach counsel on the retainer |
| Executive Sponsor | Carries the business decisions the IC cannot; removes organizational blockers; owns the board relationship | Stopping a business service; unbudgeted spend; engaging third-party IR and insurers; approving external notification | Materiality determination and market disclosure, to the CEO, General Counsel and board | A named alternate executive holding the same delegated authority, in writing |
Supporting roles, activated by need:
| Role | Called in when | Owns | Must escalate |
|---|---|---|---|
| Forensics Lead | Evidence may be needed for regulators, insurers, litigation or law enforcement | Acquisition order (volatile first), imaging, hashing, chain of custody, the evidence log | Any request to act on a system before evidence is captured |
| Threat Intel Lead | Attribution, campaign context or a hunting hypothesis is needed | TTP mapping, indicator enrichment, external sharing under agreed markings | Anything shared outside the organization; any attribution claim leaving the bridge |
| HR Liaison | An employee or contractor is a subject, a witness, or materially affected | Employment-law process, interview protocol, welfare provision, staff comms interlock | Any account action against a named individual; any monitoring of a specific employee |
| Vendor Liaison | A supplier, MSP or cloud provider is involved as cause, victim or responder | Contractual evidence-access and notification rights; single point of contact per vendor | Any contractual commitment; any grant of provider access to internal systems |
And one role that is not an incident seat at all. The IR Lead owns the program in peacetime — the plan, the playbooks, the contact list and the improvement plan that comes out of each review — and hands the response itself to the IC at declaration. That is why the IR Lead appears as Responsible on the preparation and post-incident rows below and nowhere in between. In a small team the IR Lead and the IC are the same person; write down which hat they are wearing, because the two jobs are never done at the same time.
This table is the one people argue with in peacetime and thank you for at 04:00.
| Role | Never |
|---|---|
| Incident Commander | Touch a keyboard. PagerDuty is blunt about it — "You should not be performing any actions or remediations, checking graphs, or investigating logs" (PagerDuty); CISA is blunter — "the IM does not perform any technical duties" (CISA IRP Basics) |
| Operations Lead | Brief executives, regulators or media; run containment ahead of the evidence-capture gate; change scope without telling the IC |
| Communications Lead | Make a response decision; speculate on cause or attribution; state that no personal data was affected before that is verified |
| Scribe | Investigate, analyze, or edit the timeline retroactively. Corrections are appended with a timestamp, never overwritten |
| Legal Liaison | Direct technical work; use privilege as a reason not to write down facts the response needs |
| Executive Sponsor | Run the incident, join the technical bridge as a participant, or reverse an IC decision inside the IC's authority without taking command formally |
| Forensics Lead | Release findings outside the counsel-directed channel |
| HR Liaison | Initiate a disciplinary conversation with a subject while the investigation is live, without Legal |
R does the work, A is accountable and answers for the outcome (exactly one per row), C is consulted before, I is informed after. Presented as rows rather than a grid so it stays readable when printed.
| Activity (phase) | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Maintain plan, playbooks, contact list (Preparation) | IR Lead | CISO | Legal, HR, Vendor Liaison | All responders |
| Triage an alert; deconflict against authorized activity | On-call analyst | SOC Lead | System owner | — |
| Declare an incident and set initial severity | IC | IC | On-call analyst, Ops Lead | Exec Sponsor, Legal |
| Scope the incident; run technical analysis | Ops Lead | IC | Forensics Lead, Threat Intel | Exec Sponsor |
| Preserve evidence and open chain of custody | Forensics Lead | Legal Liaison | Ops Lead | IC, Scribe |
| Select and execute containment | Ops Lead | IC | Legal, service owner, Forensics | Exec Sponsor, Comms |
| Eradication planning and the remediation event | Ops Lead | IC | Forensics, Threat Intel, Vendor Liaison | Exec Sponsor |
| Recovery sequencing and validation | Ops Lead | Exec Sponsor | IC, service owners, Forensics | Board via Comms |
| Internal communications | Comms Lead | Comms Lead | IC, Legal, HR | All staff |
| External and customer communications | Comms Lead | Exec Sponsor | Legal, IC | Board, all staff |
| Regulator and law-enforcement engagement | Legal Liaison | Exec Sponsor | Outside counsel, IC | Board, Comms |
| Post-incident review and improvement plan | IR Lead | CISO | Every role that played | Board |
| Decision | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Raise or lower severity | IC | IC | Ops Lead, Legal | Exec Sponsor |
| Take a revenue or safety-critical service offline | Ops Lead | Exec Sponsor | IC, service owner, Legal | Board |
| Enterprise-wide credential and token reset | Ops Lead | Exec Sponsor | IC, identity owner | All staff |
| Engage third-party IR / DFIR firm | Legal Liaison | Exec Sponsor | IC, insurer, procurement | Board |
| Assert privilege; counsel retains forensics | Legal Liaison | Legal Liaison | Outside counsel | IC, Exec Sponsor |
| Materiality determination | Legal Liaison | Exec Sponsor | CFO, outside counsel, IC | Board |
| Notify regulators, customers, or the market | Legal Liaison | Exec Sponsor | Comms, outside counsel | All staff, board |
| Engage law enforcement | Legal Liaison | Exec Sponsor | Outside counsel, IC | Board |
| Ransom-payment posture | Legal Liaison | Exec Sponsor | Outside counsel, insurer, IC | Board |
| Declare the incident closed | IC | Exec Sponsor | Ops Lead, Legal, Forensics | All responders |
"Notified" means a page or a call, not an email into a queue. "Acknowledge" means a human replies in the incident channel with their name and an ETA to join. An automated delivery receipt is not an acknowledgement, and neither is a thumbs-up.
| Severity | Notified | Within | Channel | Must acknowledge |
|---|---|---|---|---|
| SEV-1 | IC and Deputy IC, Ops Lead, Comms Lead, Scribe, Legal Liaison, Executive Sponsor | 15 min | Paging tool + voice bridge; out-of-band if the identity plane is in scope | IC, Ops Lead, Legal, Exec Sponsor — all four, in 15 min |
| SEV-2 | IC, Ops Lead, Scribe; Legal and Comms on standby; Exec Sponsor at first update | 30 min | Paging tool + incident channel | IC and Ops Lead in 30 min |
| SEV-3 | Security on-call and a named workstream lead | 1 h (business hours), 4 h (out of hours) | Paging tool | Named lead |
| SEV-4 | Ticket queue owner | Next business day | Ticketing system | Queue owner at triage |
If nobody acknowledges, walk the ladder: primary → secondary on rota → role deputy → Executive Sponsor, one step per full notification interval. The Scribe logs every skipped step as a finding for the post-incident review, not as a complaint about a person.
And build two upward moves, not one. NIST separates them: "Escalation generally refers to increasing resources or time frames, while elevation usually indicates involving a higher level of management" (NIST SP 800-61r3). A SEV-3 grinding into its second day needs escalation — more hands. A SEV-3 that has just touched regulated data needs elevation — a different pay grade in the room. Without both, you will keep throwing analysts at a problem that needed a decision.
This is the most useful single artefact in an IR program. It converts the sentence "should I be allowed to do this?" — asked at 03:14 by someone with a decrypting file share in front of them — into a lookup.
No approval required at SEV-2 or above. The actor logs the action in the incident channel within five minutes, and the Scribe records it.
| Action | Authorized role | Constraint |
|---|---|---|
| Isolate a single endpoint via EDR | Ops Lead, SOC on-call | Capture volatile evidence first where the tooling allows; notify the user by phone, never email |
| Block a C2 domain or IP at egress | Ops Lead, network on-call | Log the indicator and its source; no public attribution |
| Disable a single user or service account | Ops Lead, identity on-call | HR Liaison informed within 1 h if the subject is an employee |
| Revoke sessions and refresh tokens for a compromised identity | Ops Lead, identity on-call | Revoke tokens before resetting the password — see Chapter 4 |
| Snapshot a volume; capture memory | Forensics Lead, Ops Lead | Hash on capture; chain of custody opened |
| Force MFA re-registration for a named account | Identity on-call | Verify the human out of band before re-enrolment |
| Preserve and extend log retention on affected systems | Ops Lead | Before any retention window can expire |
| Quarantine a mail message or campaign tenant-wide | SOC on-call | — |
| Open the bridge, declare an incident, set severity | Any responder | Declaring is always safe; round up under uncertainty |
| Action | Approver | Out-of-hours reach path | If unreachable in 15 min |
|---|---|---|---|
| Take a revenue or safety-critical service offline | Executive Sponsor | Personal mobile → alternate executive → CEO | Alternate executive decides; IC may act unilaterally if life-safety is engaged |
| Disconnect a site or the internet edge | Executive Sponsor | As above | IC proceeds if the alternative is enterprise-wide encryption; log the reasoning |
| Enterprise-wide credential or token reset | Executive Sponsor, with IC | Exec rota → identity service owner | Defer to the scheduled remediation event unless the identity plane is confirmed compromised |
| Rebuild or wipe a fleet | Executive Sponsor | Exec rota | No default — this one waits |
| Engage a third-party IR firm | Executive Sponsor, on Legal's advice | Retainer hotline → outside counsel duty line | Retainer activation only; scope agreed when counsel is reached |
| Notify a regulator, customer or the market | Executive Sponsor, on Legal's advice | Outside counsel duty line → General Counsel | No default. Nothing goes out |
| Engage law enforcement | Executive Sponsor, on Legal's advice | Outside counsel duty line | No default |
| Pay anything, including a ransom | Executive Sponsor, board-informed | Outside counsel → insurer duty line | No default. Never a field decision |
Three rules that make the register survive contact:
Actionable takeaway: Take these two tables into a room with your Executive Sponsor and your General Counsel, and do not leave until every row has a named role and every approver has a number that rings out of hours. Ninety minutes, and it is the highest-return ninety minutes in your program.
Chapter 13 carries the full incident-handover document. This is the per-role card that goes with it, for incidents running past one shift. Handover is a scripted event, not a conversation: FEMA requires transfer of command to include "a briefing that captures all essential information for continuing safe and effective operations" (FEMA ICS), and Google requires explicit verbal confirmation of the transition, particularly across time zones (Google SRE Book).
| Role | Hands over | Verification the incoming holder performs |
|---|---|---|
| IC | Current objective, open decisions with deadlines and defaults, external commitments, running clocks | Re-states the objective in their own words on the bridge |
| Operations Lead | Workstreams with owner, state and blocker; what has been touched; what must not be touched | Confirms each workstream owner is awake and on-shift |
| Comms Lead | What was said to whom and when; next scheduled update; unanswered questions | Reads the last external statement verbatim |
| Scribe | Timeline current to the minute; unresolved observed-vs-assessed flags | Confirms no decision in the log lacks a named decider |
| Legal Liaison | Clocks, hold status, privilege boundaries, regulator contacts made | Confirms which channels are counsel-directed |
| Forensics Lead | Evidence held, custody position, still-volatile items | Signs the custody transfer |
TRANSFER OF COMMAND — script, read aloud on the bridge
Outgoing IC: "Everyone on the call, be advised: at this time I am
handing over command to [NAME]."
Incoming IC: "This is [NAME]. I am the Incident Commander for this call.
Current severity is SEV-[n]. Our objective this shift is
[objective] by [time]. Open decisions are [list]."
Scribe: Logs both statements with UTC timestamps.Rotate the IC on a schedule, not on exhaustion. Sleep-deprivation research found that well-practiced, rule-based tasks hold up under fatigue, but decision-making involving "the unexpected, innovation, revising plans, competing distraction, and effective communication" does not (Harrison & Horne, 2000). That list is the IC's entire job description. The tired IC will still run the checklist beautifully while failing to notice the incident has changed shape.
The contact list is a control, and like every other control it fails silently until it is tested.
What it must contain, per entry: role (not just person), name, primary mobile, secondary mobile, personal email outside the corporate tenant, time zone, named deputy, and the escalation step above them. Plus standing entries for the outside counsel duty line, the cyber insurer's notification line, the retained DFIR firm's activation number and contract reference, each critical vendor's incident contact and contract reference, the law-enforcement field-office contact, and the out-of-band bridge details. Federal continuity guidance requires this same shape — a designated primary and secondary point of contact, with "names, phone numbers, and email addresses" (CISA Federal Playbooks).
Where the out-of-band copy lives. CISA's instruction is unfashionable and correct: "Print these documents and the associated contact list and give a copy to everyone you expect to play a role in an incident. During an incident, your internal email, chat, and document storage services may be down or inaccessible" (CISA IRP Basics). Keep a printed copy in each responder's go-bag and at each primary site, plus an encrypted copy on a device that does not authenticate against the corporate identity plane. Treat the print-out as sensitive — it is a target list — and destroy superseded versions.
Who tests it, and how often. The IR Lead owns the list; the test is a call-tree cascade with a measured completion time. NIST reserves the word "test" for exactly this kind of measurable exercise, and gives call-tree cascade timing as its example (NIST SP 800-84). Federal continuity guidance sets a defensible cadence: annual continuity exercises, with alert, notification and accountability testing quarterly (CISA Federal Playbooks). Score it on reach rate and time-to-quorum, not on attendance.
Equifax, 2017. GAO records that when patches for the Apache Struts vulnerability were being installed across the company, the vulnerability "was not properly identified as being present on the online dispute portal" — because "the recipient list for the notice was out-of-date and, as a result, the notice was not received by the individuals who would have been responsible for installing the necessary patch" (GAO-18-559). A stale distribution list, on an ordinary Tuesday, ahead of one of the largest breaches on record.
The British Library, 2023. With website and intranet both down, the Library ran stakeholder communications over social media plus email and WhatsApp cascades, and held to the rule that staff saw updated external communications before the public did (British Library, Learning Lessons from the Cyber-Attack). That worked because the fallback existed. NCSC states the assumption plainly: "During a cyber incident, your usual communications channels may not be available" (NCSC).
Actionable takeaway: Test the call tree this quarter, unannounced, at 22:00 on a weeknight, and publish the reach rate. If it is under 90%, you do not have a contact list. You have a spreadsheet with some phone numbers in it.
Keep the roles named, the deputies awake, and the printed copy where the fire drill would take you — because the plan that only exists inside the network is the plan you lose first.