The organization
One commander at the top, a Command Staff beside them for the things only command should own, and a General Staff below who run the work. Positions are filled only when the incident needs them. An empty box on the chart is a job the IC still holds.
Command
Incident Commander
Owns. Objectives and priorities, approval of the Incident Action Plan, orders for resources beyond the sections' authority, what goes to executives and the public, transfer of command, and the call to demobilize.
First hour. Takes command out loud, sizes up, writes objectives, names an Operations lead, opens communications and sets the first briefing.
Stays off. The keyboard. An IC doing technical work leaves nobody watching the whole incident.
In cyber. The IC needs authority agreed in advance to isolate systems, suspend accounts, activate retainers and spend money. Write it into policy with business-impact and spending limits.
Deputy Incident Commander
Owns. The same qualification as the IC. Runs command while the IC rests, takes delegated work such as coordinating unified command members, and is the default relief at shift change.
Public Information Officer
Owns. Every message leaving the incident organization: executive updates, staff notices, customer and partner statements, media, status pages.
In cyber. Drafts from the incident status summary so every audience gets the same numbers. Clears wording with Legal. Routes attacker contact, extortion notes and leak-site posts to the IC and Legal, unanswered.
Safety Officer
Owns. Authority to stop any action that puts people at risk, and the plan that keeps responders fit to work.
In cyber. Watches three risks. Responder fatigue: shift lengths, rest, handover. Physical processes: where containment touches operational technology, isolating a controller or a segment can stop a process or disable a safety system, so engineering signs off first. Personal safety: staff named in extortion or doxxing get support and, where needed, protection.
Liaison Officer
Owns. The single point of contact for outside parties that are not in command.
In cyber. The outside response firm's engagement lead, the insurer and breach coach, law enforcement, regulators, the ISAC, managed service providers, suppliers, and key customers' security teams. Keeps a log of every commitment made to them.
Legal advisor
Owns. NIMS lets command add technical specialists as advisors. Counsel is the one every cyber incident needs: privilege, notification obligations and their clocks, law enforcement engagement, contracts with responders, and review of anything said outside the organization.
General Staff
Operations Section Chief
Owns. The response work, organized to meet the IAP's objectives. Builds groups, names their supervisors, keeps span of control inside three to seven.
In cyber. This is where the PIVTR-D response loop runs: investigation and scope, containment, eradication and recovery, with an OT group where plant systems are involved. Reports status to Planning on the cadence the IAP sets.
Planning Section Chief
Owns. The situation picture, the Incident Action Plan and the planning cycle, resource status, documentation, and the demobilization plan.
Units. Situation: scope, attack timeline, status summary. Resources: who is assigned, resting, and relieving whom. Documentation: activity logs, decision records, the evidence register index. Demobilization: release plan and check-out.
In cyber. Owns the attack timeline and the incident record, the two documents every later review depends on.
Logistics Section Chief
Owns. Everything responders need to do the work.
In cyber. Clean administrative workstations, break-glass accounts, access for outside responders, forensic licences and storage, spare hardware for rebuilds, the out-of-band channel, the war room, food, and places to rest.
Finance/Admin Section Chief
Owns. Time, cost, procurement, contracts and claims.
In cyber. Tracks every responder hour and outside invoice from the first hour, approves emergency purchases, activates retainers, and keeps the insurer's claim file. Read the cyber policy's notice deadline and panel-vendor terms before the incident, then track them during it.
Intelligence/Investigations
Where it sits. NIMS lets the intelligence and investigations function sit inside Planning, inside Operations, as its own General Staff section, or with the Command Staff.
In cyber. Forensic analysis, threat intelligence and evidence custody. Give it its own section when the investigation is the main effort, when law enforcement works alongside, or when counsel directs the investigation for privilege. Otherwise it stays as the investigation group in Operations.
Branches, groups and task forces
ICS gives the pieces under a section fixed names, so a request for a task force means the same thing to everyone.
| Term | In ICS | Cyber example |
|---|---|---|
| Branch | Added when a section outgrows its span of control. Functional or geographic | A technical branch and an OT branch under Operations |
| Division | A geographic or physical area | A data centre, a site, a cloud tenant, a subsidiary |
| Group | A functional area | Containment group, identity group |
| Task force | Mixed resources under one leader with shared communications | Identity task force: directory engineer, IAM administrator, detection analyst |
| Strike team | Resources of the same kind and type under one leader | Five endpoint analysts working the rebuild queue |
| Single resource | One person or item with an assignment | The malware reverse engineer |
Who usually fills each seat
| Position | Draw from |
|---|---|
| Incident Commander | Security operations leadership or a senior incident handler trained in ICS |
| Operations | The incident response lead |
| Planning | A senior analyst or program manager who writes well under pressure |
| Logistics | IT operations or service desk leadership |
| Finance/Admin | A finance partner with procurement authority |
| Public Information | Corporate communications, paired with a security writer |
| Liaison | Vendor management or third-party risk |
| Safety | Health and safety or HR, with OT engineering where plants are involved |
| Legal advisor | In-house counsel, with outside counsel as needed |
Train two people for every seat you expect to fill. Incidents run longer than one person can.