PPIVTR-D

P. Preparation

The model with the Prepare chevron highlighted.
Figure 29
STARTS WHENNo incident running. This is the default state.
DONE WHENNever closes. Every debrief reopens it with named owners.

Most of the team's hours belong here, and the work is hardest to fund when it is working, because nothing has gone wrong. Measurements make the case where a maturity model cannot: time to detect, how fast the last drill contained, what the last tabletop exposed.

Capability is what gets used. An intelligence feed nobody queries, a console nobody opens, and a playbook last edited by someone who has since left do not become useful when the incident starts.

Organization

#Item
1Policy covering mission, priorities, and when management gets pulled in
2Written position on paying ransom and on communicating with attackers
3Authority matrix filled in and signed, including the containment tiers
4Recovery time and recovery point objectives for critical systems
5Evidence retention and chain of custody procedures
6Critical asset list and risk tolerance thresholds for all four levels
7Classification matrix documented and reviewed annually
8Primary and backup communication channels, secured and tested
9Contact list covering internal teams, law enforcement, regulators, insurer, retainer providers, and cloud security contacts, reviewed quarterly
10Reporting SLAs, templates by audience, distribution lists
11Notification triggers, approval workflow, named spokespersons
12Regulatory notification requirements documented for every applicable regime
13security.txt published per RFC 9116, with internal routing for what it attracts
14Incident tracking platform selected, configured, trained on
15Cyber insurance policy read by the team and stored offline with carrier contacts, claims number, and policy number; preferred responders negotiated onto the approved panel; independent counsel identified separately from the carrier's breach coach
16Awareness training with clear reporting channels and simulated phishing

Team

#Item
17Training covering technical skills and the ones that get skipped: documentation, decisions under pressure, negotiation
18Backups immutable or air-gapped with separate authentication, integrity monitored, restores tested against RTO and RPO
19Working relationships with IT operations, SOC, help desk, legal, HR, communications, and business units, with a RACI agreed
20Playbooks for the incident types most likely to reach you, updated after every use
21Forensic workstations built and tested, including cloud workstations where the estate is cloud heavy
22Evidence storage with capacity, collection tools tested, jump bag packed
23Break-glass accounts in a vault or on hardware tokens, alerting on use, tested
24Access pre-authorized where possible; vendor and cloud support procedures documented
25Exercises scheduled: monthly tabletop, quarterly technical drill, annual full-scale

Prevention and detection

#Item
26Threat intelligence across commercial, ISAC, government, and open sources, operationalized into detection using STIX 2.1
27Risk-based patching with defined timelines and exception handling for what cannot be patched
28Software inventory with versions, SBOM data, end-of-life tracking, and shadow IT found through billing reviews
29Hardening baselines from CIS or DISA STIGs, automated in code, with drift monitored as a compromise indicator
30EDR across servers, workstations, and cloud instances, tuned, with isolation and collection enabled
31Supplemental telemetry where EDR coverage is thin, validated by adversary simulation
32Network monitoring at egress and segment boundaries, covering north-south and east-west traffic
33Detection rules tied to techniques and mapped to MITRE ATT&CK, simulation-tested, coverage tracked, stale rules retired
34Hunting program with a hypothesis catalog, target data sources, a cadence per hypothesis, an audit table of runs, and findings promoted into rules
35Asset inventory covering hardware, software, data, cloud, and third-party connections, with offline copies
36Attack surface monitoring reconciled against the internal inventory
37Remediation prioritized on CVSS severity alongside EPSS probability, asset criticality, exposure, and active exploitation intelligence