Mission and audience
Make incident response a coordinated operating capability rather than a document opened after something goes wrong.
Strong response depends on decision rights, evidence, communication, third parties, containment, and recovery criteria that are tested before the crisis.
Guided phase
Prepare people, plans, and partners
Establish maintained plans, roles, authorities, and third-party coordination before an incident.
Actions to take
- Define incident command, technical, legal, privacy, communications, and business roles.
- Maintain contact paths and third-party obligations.
- Exercise decisions, not just technical procedures.
Improve Incident Response and Cybersecurity Plans
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Roles, Responsibilities, and Authorities
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Include Suppliers in Incident Activities
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
Guided phase
Declare and triage incidents
Use consistent criteria to validate, categorize, prioritize, and begin incident management.
Actions to take
- Define what constitutes an incident and who can declare one.
- Create severity and prioritization criteria tied to mission impact.
- Record assumptions, confidence, and immediate actions.
Declare Incidents Using Defined Criteria
Incidents are declared when adverse events meet the defined incident criteria
Execute the Incident Response Plan
The incident response plan is executed in coordination with relevant third parties once an incident is declared
Triage and Validate Incident Reports
Incident reports are triaged and validated
Categorize and Prioritize Incidents
Incidents are categorized and prioritized
Guided phase
Manage and communicate
Escalate decisions and keep internal and external stakeholders informed with approved, accurate information.
Actions to take
- Define escalation triggers and executive decision points.
- Coordinate legal, regulatory, customer, insurer, supplier, and public communications.
- Protect sensitive investigative information.
Escalate or Elevate Incidents
Incidents are escalated or elevated as needed
Notify Stakeholders
Internal and external stakeholders are notified of incidents
Share Incident Information
Information is shared with designated internal and external stakeholders
Guided phase
Analyze, contain, and eradicate
Establish facts, preserve evidence, determine scope, contain impact, and remove the cause.
Actions to take
- Preserve evidence provenance and investigation records.
- Validate scope across identity, endpoint, network, cloud, and suppliers.
- Use containment and eradication criteria that account for business impact.
Establish Incident Facts and Root Cause
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
Preserve Investigation Action Records
Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved
Preserve Incident Data and Metadata
Incident data and metadata are collected, and their integrity and provenance are preserved
Estimate and Validate Incident Magnitude
An incident’s magnitude is estimated and validated
Contain Incidents
Incidents are contained
Eradicate Incidents
Incidents are eradicated
Guided phase
Recover and improve
Transition deliberately into recovery and convert lessons into measurable improvement.
Actions to take
- Apply recovery initiation criteria and prioritize services.
- Verify restored assets, monitoring, and business operations.
- Assign owners and deadlines to lessons learned.
Apply Recovery Initiation Criteria
The criteria for initiating incident recovery are applied
Execute the Recovery Plan
The recovery portion of the incident response plan is executed once initiated from the incident response process
Select and Perform Recovery Actions
Recovery actions are selected, scoped, prioritized, and performed
Improvements from Evaluations
Improvements are identified from evaluations
Completion evidence
What should exist when this playbook is working?
- Approved incident-response plan with named roles and authorities.
- Severity, declaration, escalation, containment, and recovery criteria.
- Current internal and external contact and notification matrix.
- Investigation logging, evidence preservation, and chain-of-custody procedures.
- Technical containment and eradication runbooks.
- Exercise and after-action records with completed improvements.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.