1---2name: security-incident-response3description: Use when performing security incident response — security-specific incident response playbook covering breach detection, compromised credentials response, data leak containment, evidence preservation, regulatory notification requirements, forensic investigation coordination, and communication protocols. Provides structured workflows for security incidents distinct from operational incidents.4---56# Security Incident Response Playbook78Type: **{{ incident_type }}**9Description: **{{ incident_description }}**10Affected Systems: **{{ affected_systems }}**1112## CRITICAL: Security Incident Differs from Operational Incident1314- **Preserve evidence** — do not destroy logs, do not reimage systems without forensic capture15- **Limit communication** — use secure channels, need-to-know basis only16- **Legal involvement** — notify legal counsel early for breach/data exposure events17- **Regulatory obligations** — data breaches may have mandatory notification timelines1819## Phase 1 — Detection and Triage (0-15 min)2021### Immediate Actions22- [ ] Confirm the security event is real (not a false positive)23- [ ] Classify the incident type:24 - [ ] Unauthorized access25 - [ ] Compromised credentials26 - [ ] Data exfiltration/exposure27 - [ ] Malware/ransomware28 - [ ] Insider threat29 - [ ] DDoS attack30 - [ ] Supply chain compromise31- [ ] Assign severity based on data sensitivity and blast radius32- [ ] Open a PRIVATE incident channel (not public)33- [ ] Notify Security team lead and CISO3435### Triage Questions361. What data or systems are potentially compromised?372. Is the attack still active or historical?383. What is the blast radius (users, data, systems)?394. Is there evidence of data exfiltration?405. Are any regulatory requirements triggered (PII, PHI, PCI)?4142## Phase 2 — Containment (15-60 min)4344### Short-Term Containment (stop the bleeding)45- [ ] Revoke compromised credentials/API keys/tokens46- [ ] Block malicious IP addresses or user accounts47- [ ] Isolate affected systems (network segmentation, not shutdown)48- [ ] Disable compromised integrations or webhooks49- [ ] Enable enhanced logging on affected systems5051### Evidence Preservation52- [ ] Capture system memory dumps before any changes53- [ ] Snapshot affected disk volumes54- [ ] Export relevant logs to secure, immutable storage55- [ ] Record network flow data56- [ ] Screenshot active sessions or dashboards57- [ ] Document chain of custody for all evidence5859**WARNING:** Do NOT reimage, wipe, or restart systems before evidence is captured.6061### Compromised Credentials Response62If credentials are compromised:63- [ ] Rotate ALL credentials for affected accounts immediately64- [ ] Rotate API keys, tokens, and secrets that may have been exposed65- [ ] Force password reset for affected user accounts66- [ ] Revoke all active sessions for compromised accounts67- [ ] Review access logs for unauthorized actions during exposure window68- [ ] Check if compromised credentials were used to access other systems6970## Phase 3 — Investigation7172### Forensic Investigation73- [ ] Establish timeline of attacker activity74- [ ] Identify initial access vector (how did they get in?)75- [ ] Map lateral movement (what else did they access?)76- [ ] Determine data accessed or exfiltrated77- [ ] Identify persistence mechanisms (backdoors, new accounts)78- [ ] Check for indicators of compromise (IoCs) across other systems7980### Key Log Sources to Review81| Source | What to Look For |82|--------|-----------------|83| Authentication logs | Failed/successful logins, unusual locations, impossible travel |84| API access logs | Unusual patterns, bulk data access, new API consumers |85| Cloud audit logs | IAM changes, new resources, policy modifications |86| Network logs | Data exfiltration patterns, C2 communication, unusual destinations |87| Application logs | SQL injection attempts, privilege escalation, unauthorized actions |88| VPN/SSH logs | Unauthorized remote access, unusual connection times |8990## Phase 4 — Eradication and Recovery9192### Eradication93- [ ] Remove attacker access (all identified access vectors)94- [ ] Remove any persistence mechanisms (backdoors, cron jobs, new accounts)95- [ ] Patch the vulnerability that allowed initial access96- [ ] Verify no remaining unauthorized access97- [ ] Scan for IoCs across the environment9899### Recovery100- [ ] Restore affected systems from known-good backups (if needed)101- [ ] Validate data integrity102- [ ] Re-enable services in a controlled manner103- [ ] Implement additional monitoring for the affected area104- [ ] Verify clean operation for 24-48 hours105106## Phase 5 — Notification and Reporting107108### Internal Notification109| Stakeholder | When to Notify | Method |110|------------|---------------|--------|111| CISO | Immediately | Phone + secure channel |112| Legal counsel | Within 1 hour for data breaches | Phone |113| Executive team | Within 4 hours for SEV1 security | Secure briefing |114| Engineering teams | As needed for containment | Private Slack |115116### Regulatory Notification (if applicable)117| Regulation | Data Type | Notification Deadline | Authority |118|-----------|-----------|----------------------|-----------|119| GDPR | EU personal data | 72 hours | Supervisory authority |120| HIPAA | Protected health info | 60 days | HHS |121| PCI DSS | Cardholder data | Immediately | Card brands + acquirer |122| State breach laws | PII (varies by state) | Varies (24h-60 days) | State AG |123124### Customer Notification125- [ ] Determine which customers are affected126- [ ] Draft notification with legal review127- [ ] Include: what happened, what data was affected, what we are doing, what they should do128- [ ] Provide identity monitoring if PII was exposed129130## Post-Incident131132- [ ] Conduct security post-incident review (separate from ops postmortem)133- [ ] Update threat model based on findings134- [ ] Implement additional security controls135- [ ] Update incident response playbook with lessons learned136- [ ] Schedule penetration test to validate fixes137- [ ] Review and update security monitoring rules138139## Counter-Rationalizations140141| Shortcut | Counter | Why |142|----------|---------|-----|143| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |144| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |145| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |146| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |147| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |148