People and authority
- Named incident lead and alternates
- Clear severity and escalation criteria
- Executive, legal, communications, and business contacts
- Defined authority for containment actions
Technical access
- Emergency access to identity, endpoint, network, cloud, and logging platforms
- Known-good administrative accounts and MFA paths
- Evidence retention and export procedures
- Ability to isolate accounts, hosts, applications, and network paths
Communications
Define an out-of-band channel, contact trees, update cadence, and rules for what can be shared with employees, customers, partners, regulators, and law enforcement.
Decision paths
Pre-identify decisions that become expensive under pressure: shutting down systems, disabling identities, engaging outside counsel, notifying customers, preserving evidence, or restoring from backup.
Exercise the plan
A plan that has never been used is an assumption. Run a tabletop and targeted technical validation so missing access, unclear ownership, and brittle procedures appear before a real incident.
Related next step
Use this resource as a starting point, then adapt it to the systems, business constraints, and threat model that actually apply to your organization.