The 2026 InfoSec Playbook · Daniel Ramos

#Appendix D — Roles, RACI and Escalation

The reference tables that answer "who does what, who decides, and who do I wake up" — designed to be printed and read under pressure.

Who needs this: Incident Commander, Operations Lead, Communications Lead, Scribe, Legal Liaison, Executive Sponsor, on-call responders | Read time: 15 min | Maps to: CSF 2.0 GOVERN (GV.RR), RESPOND (RS.MA, RS.CO) | CIS v8.1 Control 17 | ISO/IEC 27001:2022 A.5.2, A.5.24, A.6.8

Every table in this appendix exists because of one line in CISA's post-incident guidance. Among the objectives it sets for a hotwash is "reviewing and updating roles, responsibilities, interfaces, and authority to ensure clarity" (CISA Federal Playbooks). It is on the list because it keeps coming off the back of real incidents. Nobody discovers mid-crisis that they lack a SIEM. They discover that four capable people are each waiting for one of the other three to say yes.

Everything below is a default. Adopt it whole if you have nothing; edit it if you have something. Where a row does not match how you actually work, change the row — in peacetime, in the document, with a date on it. Chapter 13 defines these roles and the severity scale; this appendix is the reference sheet you print.


#D.1 Role definitions

Six core roles staff every SEV-1 and SEV-2. The supporting roles are called in by need, not by default. One person may hold two roles at SEV-3 and below; at SEV-1 the Incident Commander holds nothing else.

RoleResponsibilitiesDecisions ownedMust escalateDeputized by
Incident Commander (IC)Runs the response: sets the objective, assigns work to named people with time boxes, maintains the living incident document, controls the bridgeSeverity; declaration and closure; task priority; who joins or leaves the bridge; anything in the pre-authorized registerStopping a revenue or safety-critical service; spend beyond a set threshold; any external notificationDeputy IC, named at declaration
Operations LeadDirects all technical workstreams; the only role that assigns hands-on-keyboard tasks; owns the technical plan and its sequencingTooling and method; which host to image first; sequencing of a remediation event; when a workstream is blockedAny action affecting production availability or risking evidence; bringing in an external forensics firmNamed SME per workstream (identity, endpoint, network, cloud)
Communications LeadInternal and external messaging; executive update cadence; holding statements; monitoring for misinformationWording and timing of approved internal updates; channel selection; which questions get "we do not yet know"Any external statement or press response; anything naming a threat actor, cause or record countComms deputy from corporate communications
ScribeContemporaneous timeline: what happened, when, and what decisions were made and by whom; flags each entry observed or assessedNothing. The Scribe recordsAny decision made with no named owner, or a clock started with no owner — to the IC immediatelySecond scribe on shift rotation
Legal LiaisonPrivilege posture, legal hold, regulator and law-enforcement engagement, insurer notification, contract obligationsPrivilege structure; legal hold; whether counsel retains the forensics firm; what goes in a counsel-directed channelMateriality determinations; regulatory filings; ransom-payment posture — to the Executive Sponsor with counselOutside breach counsel on the retainer
Executive SponsorCarries the business decisions the IC cannot; removes organizational blockers; owns the board relationshipStopping a business service; unbudgeted spend; engaging third-party IR and insurers; approving external notificationMateriality determination and market disclosure, to the CEO, General Counsel and boardA named alternate executive holding the same delegated authority, in writing

Supporting roles, activated by need:

RoleCalled in whenOwnsMust escalate
Forensics LeadEvidence may be needed for regulators, insurers, litigation or law enforcementAcquisition order (volatile first), imaging, hashing, chain of custody, the evidence logAny request to act on a system before evidence is captured
Threat Intel LeadAttribution, campaign context or a hunting hypothesis is neededTTP mapping, indicator enrichment, external sharing under agreed markingsAnything shared outside the organization; any attribution claim leaving the bridge
HR LiaisonAn employee or contractor is a subject, a witness, or materially affectedEmployment-law process, interview protocol, welfare provision, staff comms interlockAny account action against a named individual; any monitoring of a specific employee
Vendor LiaisonA supplier, MSP or cloud provider is involved as cause, victim or responderContractual evidence-access and notification rights; single point of contact per vendorAny contractual commitment; any grant of provider access to internal systems

And one role that is not an incident seat at all. The IR Lead owns the program in peacetime — the plan, the playbooks, the contact list and the improvement plan that comes out of each review — and hands the response itself to the IC at declaration. That is why the IR Lead appears as Responsible on the preparation and post-incident rows below and nowhere in between. In a small team the IR Lead and the IC are the same person; write down which hat they are wearing, because the two jobs are never done at the same time.

#What each role must never do

This table is the one people argue with in peacetime and thank you for at 04:00.

RoleNever
Incident CommanderTouch a keyboard. PagerDuty is blunt about it — "You should not be performing any actions or remediations, checking graphs, or investigating logs" (PagerDuty); CISA is blunter — "the IM does not perform any technical duties" (CISA IRP Basics)
Operations LeadBrief executives, regulators or media; run containment ahead of the evidence-capture gate; change scope without telling the IC
Communications LeadMake a response decision; speculate on cause or attribution; state that no personal data was affected before that is verified
ScribeInvestigate, analyze, or edit the timeline retroactively. Corrections are appended with a timestamp, never overwritten
Legal LiaisonDirect technical work; use privilege as a reason not to write down facts the response needs
Executive SponsorRun the incident, join the technical bridge as a participant, or reverse an IC decision inside the IC's authority without taking command formally
Forensics LeadRelease findings outside the counsel-directed channel
HR LiaisonInitiate a disciplinary conversation with a subject while the investigation is live, without Legal

#D.2 The RACI matrix

R does the work, A is accountable and answers for the outcome (exactly one per row), C is consulted before, I is informed after. Presented as rows rather than a grid so it stays readable when printed.

#Lifecycle activities

Activity (phase)ResponsibleAccountableConsultedInformed
Maintain plan, playbooks, contact list (Preparation)IR LeadCISOLegal, HR, Vendor LiaisonAll responders
Triage an alert; deconflict against authorized activityOn-call analystSOC LeadSystem owner
Declare an incident and set initial severityICICOn-call analyst, Ops LeadExec Sponsor, Legal
Scope the incident; run technical analysisOps LeadICForensics Lead, Threat IntelExec Sponsor
Preserve evidence and open chain of custodyForensics LeadLegal LiaisonOps LeadIC, Scribe
Select and execute containmentOps LeadICLegal, service owner, ForensicsExec Sponsor, Comms
Eradication planning and the remediation eventOps LeadICForensics, Threat Intel, Vendor LiaisonExec Sponsor
Recovery sequencing and validationOps LeadExec SponsorIC, service owners, ForensicsBoard via Comms
Internal communicationsComms LeadComms LeadIC, Legal, HRAll staff
External and customer communicationsComms LeadExec SponsorLegal, ICBoard, all staff
Regulator and law-enforcement engagementLegal LiaisonExec SponsorOutside counsel, ICBoard, Comms
Post-incident review and improvement planIR LeadCISOEvery role that playedBoard

#The major decisions

DecisionResponsibleAccountableConsultedInformed
Raise or lower severityICICOps Lead, LegalExec Sponsor
Take a revenue or safety-critical service offlineOps LeadExec SponsorIC, service owner, LegalBoard
Enterprise-wide credential and token resetOps LeadExec SponsorIC, identity ownerAll staff
Engage third-party IR / DFIR firmLegal LiaisonExec SponsorIC, insurer, procurementBoard
Assert privilege; counsel retains forensicsLegal LiaisonLegal LiaisonOutside counselIC, Exec Sponsor
Materiality determinationLegal LiaisonExec SponsorCFO, outside counsel, ICBoard
Notify regulators, customers, or the marketLegal LiaisonExec SponsorComms, outside counselAll staff, board
Engage law enforcementLegal LiaisonExec SponsorOutside counsel, ICBoard
Ransom-payment postureLegal LiaisonExec SponsorOutside counsel, insurer, ICBoard
Declare the incident closedICExec SponsorOps Lead, Legal, ForensicsAll responders

#D.3 Escalation matrix (default)

"Notified" means a page or a call, not an email into a queue. "Acknowledge" means a human replies in the incident channel with their name and an ETA to join. An automated delivery receipt is not an acknowledgement, and neither is a thumbs-up.

SeverityNotifiedWithinChannelMust acknowledge
SEV-1IC and Deputy IC, Ops Lead, Comms Lead, Scribe, Legal Liaison, Executive Sponsor15 minPaging tool + voice bridge; out-of-band if the identity plane is in scopeIC, Ops Lead, Legal, Exec Sponsor — all four, in 15 min
SEV-2IC, Ops Lead, Scribe; Legal and Comms on standby; Exec Sponsor at first update30 minPaging tool + incident channelIC and Ops Lead in 30 min
SEV-3Security on-call and a named workstream lead1 h (business hours), 4 h (out of hours)Paging toolNamed lead
SEV-4Ticket queue ownerNext business dayTicketing systemQueue owner at triage

If nobody acknowledges, walk the ladder: primary → secondary on rota → role deputy → Executive Sponsor, one step per full notification interval. The Scribe logs every skipped step as a finding for the post-incident review, not as a complaint about a person.

And build two upward moves, not one. NIST separates them: "Escalation generally refers to increasing resources or time frames, while elevation usually indicates involving a higher level of management" (NIST SP 800-61r3). A SEV-3 grinding into its second day needs escalation — more hands. A SEV-3 that has just touched regulated data needs elevation — a different pay grade in the room. Without both, you will keep throwing analysts at a problem that needed a decision.


#D.4 The pre-authorized action register

This is the most useful single artefact in an IR program. It converts the sentence "should I be allowed to do this?" — asked at 03:14 by someone with a decrypting file share in front of them — into a lookup.

#Pre-authorized: do it, then log it

No approval required at SEV-2 or above. The actor logs the action in the incident channel within five minutes, and the Scribe records it.

ActionAuthorized roleConstraint
Isolate a single endpoint via EDROps Lead, SOC on-callCapture volatile evidence first where the tooling allows; notify the user by phone, never email
Block a C2 domain or IP at egressOps Lead, network on-callLog the indicator and its source; no public attribution
Disable a single user or service accountOps Lead, identity on-callHR Liaison informed within 1 h if the subject is an employee
Revoke sessions and refresh tokens for a compromised identityOps Lead, identity on-callRevoke tokens before resetting the password — see Chapter 4
Snapshot a volume; capture memoryForensics Lead, Ops LeadHash on capture; chain of custody opened
Force MFA re-registration for a named accountIdentity on-callVerify the human out of band before re-enrolment
Preserve and extend log retention on affected systemsOps LeadBefore any retention window can expire
Quarantine a mail message or campaign tenant-wideSOC on-call
Open the bridge, declare an incident, set severityAny responderDeclaring is always safe; round up under uncertainty

#Approval-gated: named approver, reachable, with a default

ActionApproverOut-of-hours reach pathIf unreachable in 15 min
Take a revenue or safety-critical service offlineExecutive SponsorPersonal mobile → alternate executive → CEOAlternate executive decides; IC may act unilaterally if life-safety is engaged
Disconnect a site or the internet edgeExecutive SponsorAs aboveIC proceeds if the alternative is enterprise-wide encryption; log the reasoning
Enterprise-wide credential or token resetExecutive Sponsor, with ICExec rota → identity service ownerDefer to the scheduled remediation event unless the identity plane is confirmed compromised
Rebuild or wipe a fleetExecutive SponsorExec rotaNo default — this one waits
Engage a third-party IR firmExecutive Sponsor, on Legal's adviceRetainer hotline → outside counsel duty lineRetainer activation only; scope agreed when counsel is reached
Notify a regulator, customer or the marketExecutive Sponsor, on Legal's adviceOutside counsel duty line → General CounselNo default. Nothing goes out
Engage law enforcementExecutive Sponsor, on Legal's adviceOutside counsel duty lineNo default
Pay anything, including a ransomExecutive Sponsor, board-informedOutside counsel → insurer duty lineNo default. Never a field decision

Three rules that make the register survive contact:

Actionable takeaway: Take these two tables into a room with your Executive Sponsor and your General Counsel, and do not leave until every row has a named role and every approver has a number that rings out of hours. Ninety minutes, and it is the highest-return ninety minutes in your program.


#D.5 Shift handover

Chapter 13 carries the full incident-handover document. This is the per-role card that goes with it, for incidents running past one shift. Handover is a scripted event, not a conversation: FEMA requires transfer of command to include "a briefing that captures all essential information for continuing safe and effective operations" (FEMA ICS), and Google requires explicit verbal confirmation of the transition, particularly across time zones (Google SRE Book).

RoleHands overVerification the incoming holder performs
ICCurrent objective, open decisions with deadlines and defaults, external commitments, running clocksRe-states the objective in their own words on the bridge
Operations LeadWorkstreams with owner, state and blocker; what has been touched; what must not be touchedConfirms each workstream owner is awake and on-shift
Comms LeadWhat was said to whom and when; next scheduled update; unanswered questionsReads the last external statement verbatim
ScribeTimeline current to the minute; unresolved observed-vs-assessed flagsConfirms no decision in the log lacks a named decider
Legal LiaisonClocks, hold status, privilege boundaries, regulator contacts madeConfirms which channels are counsel-directed
Forensics LeadEvidence held, custody position, still-volatile itemsSigns the custody transfer
TRANSFER OF COMMAND — script, read aloud on the bridge
Outgoing IC:  "Everyone on the call, be advised: at this time I am
               handing over command to [NAME]."
Incoming IC:  "This is [NAME]. I am the Incident Commander for this call.
               Current severity is SEV-[n]. Our objective this shift is
               [objective] by [time]. Open decisions are [list]."
Scribe:        Logs both statements with UTC timestamps.

Rotate the IC on a schedule, not on exhaustion. Sleep-deprivation research found that well-practiced, rule-based tasks hold up under fatigue, but decision-making involving "the unexpected, innovation, revising plans, competing distraction, and effective communication" does not (Harrison & Horne, 2000). That list is the IC's entire job description. The tired IC will still run the checklist beautifully while failing to notice the incident has changed shape.


#D.6 Contact list requirements

The contact list is a control, and like every other control it fails silently until it is tested.

What it must contain, per entry: role (not just person), name, primary mobile, secondary mobile, personal email outside the corporate tenant, time zone, named deputy, and the escalation step above them. Plus standing entries for the outside counsel duty line, the cyber insurer's notification line, the retained DFIR firm's activation number and contract reference, each critical vendor's incident contact and contract reference, the law-enforcement field-office contact, and the out-of-band bridge details. Federal continuity guidance requires this same shape — a designated primary and secondary point of contact, with "names, phone numbers, and email addresses" (CISA Federal Playbooks).

Where the out-of-band copy lives. CISA's instruction is unfashionable and correct: "Print these documents and the associated contact list and give a copy to everyone you expect to play a role in an incident. During an incident, your internal email, chat, and document storage services may be down or inaccessible" (CISA IRP Basics). Keep a printed copy in each responder's go-bag and at each primary site, plus an encrypted copy on a device that does not authenticate against the corporate identity plane. Treat the print-out as sensitive — it is a target list — and destroy superseded versions.

Who tests it, and how often. The IR Lead owns the list; the test is a call-tree cascade with a measured completion time. NIST reserves the word "test" for exactly this kind of measurable exercise, and gives call-tree cascade timing as its example (NIST SP 800-84). Federal continuity guidance sets a defensible cadence: annual continuity exercises, with alert, notification and accountability testing quarterly (CISA Federal Playbooks). Score it on reach rate and time-to-quorum, not on attendance.

#When the notification list was the failure

Equifax, 2017. GAO records that when patches for the Apache Struts vulnerability were being installed across the company, the vulnerability "was not properly identified as being present on the online dispute portal" — because "the recipient list for the notice was out-of-date and, as a result, the notice was not received by the individuals who would have been responsible for installing the necessary patch" (GAO-18-559). A stale distribution list, on an ordinary Tuesday, ahead of one of the largest breaches on record.

The British Library, 2023. With website and intranet both down, the Library ran stakeholder communications over social media plus email and WhatsApp cascades, and held to the rule that staff saw updated external communications before the public did (British Library, Learning Lessons from the Cyber-Attack). That worked because the fallback existed. NCSC states the assumption plainly: "During a cyber incident, your usual communications channels may not be available" (NCSC).

Actionable takeaway: Test the call tree this quarter, unannounced, at 22:00 on a weeknight, and publish the reach rate. If it is under 90%, you do not have a contact list. You have a spreadsheet with some phone numbers in it.

Keep the roles named, the deputies awake, and the printed copy where the fire drill would take you — because the plan that only exists inside the network is the plan you lose first.


#Sources

  1. https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
  2. https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf
  3. https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf/
  4. https://response.pagerduty.com/training/incident_commander/
  5. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf
  6. https://www.ncsc.gov.uk/collection/incident-management/cyber-incident-response-processes
  7. https://media.blackhat.com/bh-us-12/Briefings/Aldridge/BH_US_12_Aldridge_Targeted_Intrustion_WP.pdf
  8. https://ofac.treasury.gov/system/files/126/ofac_ransomware_advisory.pdf
  9. https://www.ncsc.gov.uk/files/Guidance-for-organizations-considering-payment-in-ransomware-incidents.pdf
  10. https://training.fema.gov/emiweb/is/icsresource/assets/ics%20review%20document.pdf
  11. https://sre.google/sre-book/managing-incidents/
  12. https://fatiguemanagersnetwork.org/wp-content/uploads/Harrison-et-al.2000_-The-Impact-of-Sleep-Deprivation-on-Decision-Making.pdf
  13. https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-84.pdf
  14. https://www.gao.gov/assets/gao-18-559.pdf
  15. https://www.ncsc.gov.uk/files/NCSC-Guidance-on-effective-communications-in-a-cyber-incident.pdf
This page is one chapter of The 2026 InfoSec Playbook, a free field manual by Daniel Ramos. Checklist statuses and the live coverage model are in the full manual. Free, in full, no email wall.