P. Preparation
STARTS WHENNo incident running. This is the default state.
DONE WHENNever closes. Every debrief reopens it with named owners.
Most of the team's hours belong here, and the work is hardest to fund when it is working, because nothing has gone wrong. Measurements make the case where a maturity model cannot: time to detect, how fast the last drill contained, what the last tabletop exposed.
Capability is what gets used. An intelligence feed nobody queries, a console nobody opens, and a playbook last edited by someone who has since left do not become useful when the incident starts.
Organization
| # | Item |
|---|---|
| 1 | Policy covering mission, priorities, and when management gets pulled in |
| 2 | Written position on paying ransom and on communicating with attackers |
| 3 | Authority matrix filled in and signed, including the containment tiers |
| 4 | Recovery time and recovery point objectives for critical systems |
| 5 | Evidence retention and chain of custody procedures |
| 6 | Critical asset list and risk tolerance thresholds for all four levels |
| 7 | Classification matrix documented and reviewed annually |
| 8 | Primary and backup communication channels, secured and tested |
| 9 | Contact list covering internal teams, law enforcement, regulators, insurer, retainer providers, and cloud security contacts, reviewed quarterly |
| 10 | Reporting SLAs, templates by audience, distribution lists |
| 11 | Notification triggers, approval workflow, named spokespersons |
| 12 | Regulatory notification requirements documented for every applicable regime |
| 13 | security.txt published per RFC 9116, with internal routing for what it attracts |
| 14 | Incident tracking platform selected, configured, trained on |
| 15 | Cyber insurance policy read by the team and stored offline with carrier contacts, claims number, and policy number; preferred responders negotiated onto the approved panel; independent counsel identified separately from the carrier's breach coach |
| 16 | Awareness training with clear reporting channels and simulated phishing |
Team
| # | Item |
|---|---|
| 17 | Training covering technical skills and the ones that get skipped: documentation, decisions under pressure, negotiation |
| 18 | Backups immutable or air-gapped with separate authentication, integrity monitored, restores tested against RTO and RPO |
| 19 | Working relationships with IT operations, SOC, help desk, legal, HR, communications, and business units, with a RACI agreed |
| 20 | Playbooks for the incident types most likely to reach you, updated after every use |
| 21 | Forensic workstations built and tested, including cloud workstations where the estate is cloud heavy |
| 22 | Evidence storage with capacity, collection tools tested, jump bag packed |
| 23 | Break-glass accounts in a vault or on hardware tokens, alerting on use, tested |
| 24 | Access pre-authorized where possible; vendor and cloud support procedures documented |
| 25 | Exercises scheduled: monthly tabletop, quarterly technical drill, annual full-scale |
Prevention and detection
| # | Item |
|---|---|
| 26 | Threat intelligence across commercial, ISAC, government, and open sources, operationalized into detection using STIX 2.1 |
| 27 | Risk-based patching with defined timelines and exception handling for what cannot be patched |
| 28 | Software inventory with versions, SBOM data, end-of-life tracking, and shadow IT found through billing reviews |
| 29 | Hardening baselines from CIS or DISA STIGs, automated in code, with drift monitored as a compromise indicator |
| 30 | EDR across servers, workstations, and cloud instances, tuned, with isolation and collection enabled |
| 31 | Supplemental telemetry where EDR coverage is thin, validated by adversary simulation |
| 32 | Network monitoring at egress and segment boundaries, covering north-south and east-west traffic |
| 33 | Detection rules tied to techniques and mapped to MITRE ATT&CK, simulation-tested, coverage tracked, stale rules retired |
| 34 | Hunting program with a hypothesis catalog, target data sources, a cadence per hypothesis, an audit table of runs, and findings promoted into rules |
| 35 | Asset inventory covering hardware, software, data, cloud, and third-party connections, with offline copies |
| 36 | Attack surface monitoring reconciled against the internal inventory |
| 37 | Remediation prioritized on CVSS severity alongside EPSS probability, asset criticality, exposure, and active exploitation intelligence |