Define what the plan is for
An event is something observed in a system or network. A cybersecurity incident involves actual or imminent harm to the confidentiality, integrity or availability of information or systems, or a violation or threatened violation of relevant security rules. The organisation’s plan should define how suspected incidents are assessed, escalated and declared. NIST SP 800-61 Rev. 3, Introduction. A plan describes responsibilities and decision arrangements; a playbook provides more detailed procedures for a particular scenario. These distinctions help people understand when to escalate and which document to use. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
A contact list is useful, but it cannot answer who is authorised to restrict access, interrupt a service or speak externally. The plan should connect those decisions with accountable roles and alternatives when the usual decision-maker is unavailable.
Prepare for disruption to normal communications
Consider how people will coordinate if email or the main identity service cannot be trusted or accessed. Record appropriate provider contacts, escalation routes and the information people need to make an initial assessment. Decide how incident decisions and actions will be recorded. ACSC’s planning guidance addresses roles, communications and readiness. Cyber security incident response planning: Practitioner guidance
Do not turn a general article into a universal containment instruction. Disconnecting equipment, shutting systems down or deleting material can have operational and evidentiary consequences. The plan should identify who evaluates those actions for the actual incident.
Keep legal assessment visible
A cyber incident and a legally notifiable data breach are not interchangeable terms. Australia’s Notifiable Data Breaches scheme concerns entities covered by the Privacy Act and eligible breaches. Whether a particular situation creates notification duties requires assessment; the OAIC overview is a starting source, not a decision for every organisation or event. About the Notifiable Data Breaches scheme
Assign legal and privacy questions to the appropriate advisers, including any relevant contractual or sector-specific matters. Do not assume one external report satisfies every obligation.
An invented tabletop discussion
An organisation discusses a scenario in which a mailbox may be compromised. The facilitator asks who assesses the initial report, who may restrict access, how staff would communicate if email were distrusted and who would coordinate with the provider. The group also identifies who considers notification questions and who approves the transition into recovery.
This is a proposed tabletop: a discussion of an imagined event. No account is changed, no suspicious content is opened and no security test is performed. A useful result is a list of missing decisions and assigned follow-up work, not a claim that operational recovery has been demonstrated.
A plan-readiness checklist
- Define incident criteria, decision authority and substitutes.
- Record internal and provider contacts with a fallback route.
- Identify who manages triage, communications and decision records.
- Assign evidence-handling and legal-assessment responsibilities.
- Define how response hands over to recovery.
- Exercise a relevant scenario and track the resulting actions.
Optional depth: connect response to risk management
NIST SP 800-61 Rev. 3 connects incident response to CSF 2.0 outcomes and ongoing cybersecurity risk management. Preparation and lessons learned belong in the wider programme, not solely in an emergency document. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
An incident-response specialist should review the plan’s authority, evidence handling and recovery handover. Operations and communications owners need to confirm that the proposed arrangements can work in practice.
Related reading
- Recognizing and reporting suspicious messages — Make staff reporting usable.
- Recovery planning and business continuity — Plan recovery and resumption.
- Evaluating IT and security suppliers — Clarify supplier incident arrangements.