Prepare
Incident command is mostly people and paperwork, and both have to exist before the incident does. The technical preparation lives in the PIVTR-D preparation playbook. This page covers what the incident organization needs in place before anyone stands it up.
People
Name at least two trained people for every seat you expect to fill, so the incident survives its first shift change. Training covers the role, the forms and the meetings. Weight it toward the incident commander, the one job nobody does day to day.
Practise in the seats. Google runs Wheel of Misfortune exercises, role-playing past incidents so less experienced on-callers build skill somewhere safe. Run tabletops the same way: replay real incidents, rotate who holds command, communications and operations, and time the first objectives and the first executive update.
Authority
Write down what the incident commander can do without asking: isolate systems, suspend accounts, take services offline, activate retainers, spend up to a set amount, engage law enforcement. Put the limits in business terms. Name who approves anything above them, and their backups.
Detection that reaches someone
The incident organization starts when someone is paged. Google's guide asks four things of an alert: it arrives in time, it covers what users depend on, it measures what users experience, and someone can act on it. For security, read that as detections that fire early enough to contain, cover the systems and identities that matter most, carry enough context to size the incident, and route to someone who can take command. The PIVTR-D identification playbook covers the detection side.
Tools that open the incident for you
Automate the first ten minutes so responders spend them thinking. One action should open the incident record from the ICS 201 template, create the command bridge and the out-of-band room, page the incident commander and on-call, start a timestamped activity log, and post the first internal notice. Google's guide points the same way: automate common tasks and the first read of impact so on-callers can work the problem.
Contracts and outside help
- Incident response retainer: how to activate it, response times, who can sign.
- Cyber insurance: notice deadline, panel vendors, what the insurer must approve.
- Counsel: who to call, and when counsel directs the investigation.
- Managed providers: which containment actions they take on their own authority.
- Law enforcement: named contacts, agreed before you need them.
Ready to run an incident
| # | Item |
|---|---|
| 1 | Two trained people named for incident commander, operations, communications and planning |
| 2 | Incident commander authority written, with limits and approvers |
| 3 | Incident types mapped to your severity scale and published |
| 4 | Forms and the incident record template ready to copy |
| 5 | Out-of-band channel and accounts provisioned outside the main identity provider |
| 6 | Contact roster for internal and outside parties, kept offline and tested |
| 7 | Retainer, insurer and counsel details in the roster |
| 8 | One action that opens a new incident |
| 9 | Shift length and relief rules agreed |
| 10 | A tabletop in the last quarter, with the seats rotated |