Incident Command
A NIMS-based guide to running incidents. Written for cybersecurity. Works for anything.
Any organization large enough to have incidents will eventually have one that outgrows the team that found it. How that incident goes depends on three things: whether someone is clearly in charge, whether everyone hears the same facts, and whether the work is planned or improvised. The National Incident Management System answers all three, and emergency services in the United States have run on it for two decades.
This guide adapts NIMS to cybersecurity. The structure, vocabulary and paperwork carry over almost unchanged. What changes is who fills each seat and what each section does. It is laid out the way Google's SRE team presents its own ICS-based process, in three stages: prepare, respond and manage, learn. Nothing here depends on the incident being cyber.
Prepare
Most of what decides an incident is settled before it starts. The people for each seat are trained and have practised in it. The authority to isolate systems, suspend accounts and spend money is agreed. The channels, forms, contracts and playbooks are ready to use at two in the morning. Prepare lists what to have in place.
Respond and manage
The first qualified person takes command out loud. Three roles cover most incidents: an incident commander who coordinates, a communications lead who keeps every audience informed, and an operations lead who runs the technical work. When the incident outgrows one shift or one team, the rest of the ICS organization fills in around them: planning, logistics, finance, liaison, safety.
Each operational period gets written objectives and an Incident Action Plan. Command changes hands by briefing. Nobody joins the response without an assignment. Respond and manage covers the organization, sizing, the planning cycle, unified command, communications and handover.
Learn
The after-action review starts as soon as the incident closes, while memory is fresh. It is blameless: people acted on what they knew at the time, so findings go to systems, procedures and training. Every corrective action gets an owner and a date and is tracked to done. Across many incidents, recurring findings show where larger investment belongs. Learn has the review questions and the improvement plan.
NIMS in one picture
ICS is one part of NIMS. The rest adds a crisis team and an executive group above the incident, one joint voice to the public, and common ways to handle resources and information at every level.
NIMS at a glance walks through the three components and the four structures.
How it pairs with PIVTR-D
PIVTR-D covers the response lifecycle, the technical work from preparation to debrief. This guide covers the management around that work: who decides, how the team is organized, how the plan is written and handed over, and how the effort holds up past the first night.
| PIVTR-D phase | Where it sits in incident command |
|---|---|
| Preparation | Prepare: people qualified for each seat, pre-agreed authority, the forms, the communications plan |
| Identification | Outside the incident organization until an event of interest is raised |
| Verification and triage | Initial response and assessment. The first qualified responder takes command and sizes the incident |
| Response loop | The Operations Section, working to one set of objectives per operational period, carried in the Incident Action Plan |
| Debrief | Demobilization, then Learn |
When to stand it up
Use the structure when an incident needs more than one team, will run past one shift, or will draw in executives, counsel or outside parties. An analyst closing a phishing report needs none of it beyond knowing they are in command. An enterprise ransomware event needs most of it by the end of the first day. Sizing the response sets the thresholds.
Further reading
- National Incident Management System, Third Edition, FEMA, 2017
- Incident Management Guide, Google SRE
- Managing Incidents, Site Reliability Engineering, chapter 14
- Incident Response, The Site Reliability Workbook, chapter 9
- Postmortem Culture, Site Reliability Engineering, chapter 15
- PIVTR-D, the companion incident response field manual