An incident response plan the people in it can follow.
F Creative Studio 360 writes roles, severity and playbooks for organisations in any country. Counsel keeps the decision to notify.
A binder that names nobody is not a plan.
The structure follows NIST SP 800-61. Where a duty to notify exists, the plan records the questions counsel will ask. Examples include GDPR, the HIPAA Security Rule, the Notifiable Data Breaches scheme and the Security of Critical Infrastructure Act, each only when that organisation is subject to it.
- A plan is a decision map
- It says who is in charge, how an incident is classified, and who is allowed to take a system offline. It is not a promise that the incident will be small.
- The rules follow the entity
- A bank, a hospital and a software company do not share one notification clock. The plan names the clocks that apply to the entities in it.
- Counsel owns the notice
- The plan can include a workflow. The decision to notify a regulator, customers or law enforcement stays with counsel. F Creative Studio 360 does not file it.
- An untested plan is a draft
- A tabletop can be included when it is in scope. A fuller exercise is the cyber wargames service.
What the plan contains
Written for the entities in front of you. The same shape works in any country.
- The team
- Names and deputies for security, technology, legal, communications and the executive who can decide.
- Severity
- How an event is classed, and which class wakes which people.
- Playbooks
- Steps for the incident types in scope, such as ransomware, a compromised mailbox or a suspected insider. Each playbook stops at the point a person must decide.
- Evidence
- What is preserved, by whom, and when forensics is called.
- Notification workflow
- The questions counsel will need, and the external parties that might have to be told. The plan does not send the notice.
- Recovery
- Which services return first, aligned to the continuity arrangements the organisation already has.
How a plan is written
It can be done on site or remotely, including when legal, security and operations are in different places.
- 1
Read the duties
Which entities, which countries, and which notification rules those entities are actually subject to.
- 2
Draft the plan
Roles, severity, playbooks and the out-of-band way the team will talk if email is not safe.
- 3
Review it with the people who will use it
Security, technology, legal and the executive owner. A plan the operators reject is rewritten.
- 4
Test what was agreed
A tabletop when it is in scope. The notes come back into the plan. A live exercise is a separate written scope.
Common questions
What should the plan include?+
A team with deputies, severity levels, playbooks for the incidents you chose, a way to preserve evidence, a notification workflow for counsel, and a recovery order. F Creative Studio 360 writes those. Counsel owns the legal reading.
How often should it be tested?+
When the systems, the team or the rules change, and on the cycle your own obligation sets. CPS 234 asks some financial institutions for regular testing. That duty applies only if the institution is subject to it. A tabletop is not a penetration test.
Will the plan make us compliant?+
No. A plan can be aligned to NIST SP 800-61 and to the rules that apply to you. Alignment is not a certification, and holding a document is not the same as following it.
Where do you do this?+
For organisations in any country. Examples that are used only when the organisation is subject to them include GDPR, the HIPAA Security Rule, the Notifiable Data Breaches scheme, the Security of Critical Infrastructure Act and CPS 234.
How much does it cost, and how long does it take?+
It depends on how many entities and playbooks are in scope, and whether a tabletop is included. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Start with who is allowed to decide at 2am.
F Creative Studio 360 will look at the entities and the rules that apply, then say what the plan should contain.
