PPIVTR-D

Decide these before the incident

Settle these in advance and refer to them during the response. Working out who can authorize taking production offline while the file shares are encrypting spends the only time that matters on a phone tree.

Who authorizes what

Structure from p. 97. The role names and containment tiers are placeholders. Replace them with yours before anyone relies on this.

DecisionAuthorityDelegateRecord required
Declare an incidentIncident commanderSenior analyst on dutyTicket with declaration time and rationale
Isolate an endpointSOC or IR analystNone neededContainment decision record
Isolate a server or serviceService owner with incident commanderIncident commander alone if the owner is unreachable inside the response windowContainment decision record with impact assessment
Shut down production, or anything touching regulated servicesNamed executiveCISO after hours, ratified next business dayContainment decision record plus executive approval
Expand scope to other business unitsIncident commander, CISO notifiedNoneScope expansion entry with the trigger
Exit the loop, technical closureIncident commander on eradication validationSenior analyst with written approvalSigned technical closure record
Accept residual riskCISO or named risk ownerBoard-level executive for significant incidentsSigned risk acceptance naming the risks
Notify a regulatorLegal counsel with the CISOGeneral counselDecision log with timeline and regulator named
Speak to media or the publicCommunications lead with legal sign-offCEO for material incidentsApproved statement under version control
Pay a ransomWritten position agreed in advance, then named executive with counselNoneDecision log naming counsel and carrier consulted

When containment cannot wait

Table 17, p. 227. Map each trigger to an approved action during preparation.

TriggerIndicatorsApproved action
Active destructionEncryption spreading across shares, event logs wiped, database tables droppedIsolate immediately
ExfiltrationLarge transfers to cloud storage, bulk queries against personal data, archives sent to external sitesContain urgently to cap exposure
Safety or critical systemsICS, medical devices, payment processing, other safety-critical infrastructureAct immediately and accept the loss of intelligence
Regulatory clockData or services under HIPAA, PCI DSS, GDPR, NIS2, DORA, CRA, or a local equivalentContain rapidly to limit affected records

Which containment posture

Table 16, p. 223. Deceptive containment is drawn from the same chapter's step-by-step reference.

SituationPosture
Destruction or ransomware underwayActive, required
Regulated data with a compliance clockActive, required
Safety-critical or high-availability system at riskActive, required
Attacker shows awareness of defendersActive, strongly favored
Short dwell time, limited monitoring maturityActive, strongly favored
Extended dwell time, mature monitoringAdaptive, strongly favored
Unknown scope, uncertain sophisticationAdaptive, preferred
Commodity malware on a low-value assetPassive, possible
Controlled deception environmentPassive or deceptive, possible
Three panels: Passive Containment with honeypots and deception, Active Containment with segmentation and isolation, Adaptive Containment with progressive restrictions, above an arrow showing movement between them.
Figure 75. The arrow matters. Posture changes within a single incident as understanding improves.

Risk levels and what they trigger

Levels from p. 171. The trigger column is mine, and the thresholds should be yours.

LevelMeaningWhat it triggers
LowMinor anomaly, minimal impactAnalyst handles it, logged only
MediumWorth investigating, operations unaffectedIncident commander informed, daily update
HighConfirmed incident affecting operations or data integrityTeam activated, decision makers briefed, update cadence set
CriticalMajor incidentExecutive escalation, immediate containment authority granted, counsel engaged
Adapts material from Dynamic Incident Response: A Framework for Security Teams by Joshua Wright, © 2026 The Escal Institute of Advanced Technologies, Inc. d/b/a SANS Institute, licensed under CC BY 4.0. Figures reproduced under that license. Changes were made. Not published by, endorsed by, or affiliated with the SANS Institute.