Incident Response Plan and Playbook
Drafts legally defensible IR plans for law firms and legal departments covering cybersecurity incidents, data breaches, privilege preservation, and professional responsibility compliance.
Prerequisites
Gather before drafting:
- Organization profile — firm structure, practice areas, office locations, operating jurisdictions
- Existing policies — infosec policies, business continuity plans, professional responsibility guidelines
- Regulatory landscape — state breach notification statutes, sector overlays (HIPAA, GLBA, CMMC)
- Technology environment — case management systems, DMS, email, backup infrastructure
- Insurance coverage — cyber insurance policy, carrier contact, claim procedures
Quick Start
- Map jurisdictions and applicable breach statutes
- Classify incident types by severity tier
- Define governance roles and escalation chains
- Draft phased response procedures (NIST 800-61 adapted)
- Build scenario-specific playbooks
- Set communication protocols and notification templates
- Establish training/testing cadence
Output Sections
1. Jurisdictional Analysis
Map per operating jurisdiction:
- Breach notification statutes — triggers, timeframes (typically 30–90 days), AG notification
- Professional conduct rules — ABA Model Rules 1.1 (tech competence), 1.4 (communication), 1.6 (confidentiality)
- Sector overlays — HIPAA, GLBA, CMMC, SEC as applicable
- Ethics opinions — relevant state bar opinions on cybersecurity duties
2. Incident Taxonomy
Four severity tiers:
| Tier |
Criteria |
Response Time |
| Critical |
Widespread client data compromise; privilege breach; mandatory reporting triggered |
Immediate (24/7) |
| High |
Multi-matter exposure; attorney email compromise |
≤2 hours |
| Medium |
Isolated access attempts; contained inadvertent disclosure |
≤4 hours |
| Low |
Blocked attempts; policy violations without data exposure |
Next business day |
Legal-specific incident types: inadvertent privilege disclosure, case management unauthorized access, conflicts data exposure, attorney email compromise, DMS ransomware, physical file breach.
3. Governance Structure
| Role |
Function |
Key Authority |
| IR Coordinator |
Activates plan, convenes team |
Isolate systems, engage external resources |
| General Counsel / Ethics Counsel |
Legal/ethical analysis, privilege protection |
Direct privileged investigation, approve notifications |
| CISO / IT Director |
Technical response, forensics |
Evidence preservation, restoration |
| Managing Partner |
Strategic decisions |
Expenditures, client relationship decisions |
| Communications Director |
Internal/external messaging |
Media responses (with counsel approval) |
Include after-hours contact roster and escalation chain for unavailable contacts.
4. Phased Response (NIST 800-61 Adapted)
Phase 1 — Preparation
- Preventive controls inventory
- Annual security awareness training + tabletop exercises
- External expert relationships (forensics, breach counsel, PR)
Phase 2 — Identification
Phase 3 — Containment
Phase 4 — Eradication
Phase 5 — Recovery
Phase 6 — Lessons Learned (within 14 days)
5. Scenario Playbooks
Ransomware on DMS:
- Isolate systems → notify cyber insurance carrier
- Assess backup integrity; evaluate exfiltration indicators (double extortion)
- Determine client notification obligations per jurisdiction
- Consider law enforcement (FBI IC3); document all decisions under privilege
Attorney Email Compromise:
- Reset credentials; revoke sessions; review forwarding/mailbox rules
- Identify accessed client communications; assess privilege implications
- Notify affected clients per Rule 1.4; implement MFA
Inadvertent Privilege Disclosure:
- Notify opposing counsel per FRE 502(b)
[VERIFY]; request return/destruction
- Document inadvertence; assess waiver risk under applicable law
- File clawback motion if necessary
6. Communication Protocols
| Audience |
Trigger |
Timing |
Approval |
| IR Team |
Any confirmed incident |
Immediate |
IR Coordinator |
| Senior Leadership |
High/Critical |
Within 1 hour |
IR Coordinator |
| Affected Clients |
Client data compromised |
Per statute + "prompt" ethics notice |
GC + Managing Partner |
| State AG / Regulators |
Statutory threshold met |
Per state (30–90 days) |
General Counsel |
| Law Enforcement |
Criminal activity; ransomware |
Case-by-case |
General Counsel |
| Media |
Public exposure/inquiry |
Reactive only |
GC + Communications |
Mark all investigation communications "Privileged & Confidential — Attorney Work Product." Client notifications must satisfy both breach statutes and professional conduct rules.
7. Training and Testing
| Activity |
Frequency |
| Security awareness training |
Annual (all personnel) |
| IR team specialized training |
Annual |
| Tabletop exercises |
Annual minimum |
| Phishing simulations |
Quarterly |
| Backup restoration tests |
Semi-annual |
| Plan review and update |
Annual + post-incident |
Track: time to detect, contain, eradicate, recover; notification compliance rate.
8. Appendices
Pitfalls and Checks
- Privilege preservation — all investigation activities directed by counsel; mark work product accordingly
- Jurisdiction specificity — map each state's breach notification statute; never rely on generic summaries
- Dual obligation — every notification must satisfy both statutory AND ethics requirements
- Cite authority — reference specific statutes, ABA Model Rules, ethics opinions; mark uncertain citations
[VERIFY]
- Defensibility — the plan itself evidences reasonable security measures under Rule 1.1 competence duty
- Internal only — this plan governs firm response; separate client advisory communications
1---2name: incident-response-plan3description: Drafts incident response plans and playbooks for legal organizations, adapting NIST SP 800-61 to law firm contexts including privilege preservation, ethics obligations, and state breach notification compliance. Use when creating IR plans, cybersecurity playbooks, breach response policies, or data incident procedures for law firms or legal departments.4---56# Incident Response Plan and Playbook78Drafts legally defensible IR plans for law firms and legal departments covering cybersecurity incidents, data breaches, privilege preservation, and professional responsibility compliance.910## Prerequisites1112Gather before drafting:13141. **Organization profile** — firm structure, practice areas, office locations, operating jurisdictions152. **Existing policies** — infosec policies, business continuity plans, professional responsibility guidelines163. **Regulatory landscape** — state breach notification statutes, sector overlays (HIPAA, GLBA, CMMC)174. **Technology environment** — case management systems, DMS, email, backup infrastructure185. **Insurance coverage** — cyber insurance policy, carrier contact, claim procedures1920## Quick Start21221. Map jurisdictions and applicable breach statutes232. Classify incident types by severity tier243. Define governance roles and escalation chains254. Draft phased response procedures (NIST 800-61 adapted)265. Build scenario-specific playbooks276. Set communication protocols and notification templates287. Establish training/testing cadence2930## Output Sections3132### 1. Jurisdictional Analysis3334Map per operating jurisdiction:3536- **Breach notification statutes** — triggers, timeframes (typically 30–90 days), AG notification37- **Professional conduct rules** — ABA Model Rules 1.1 (tech competence), 1.4 (communication), 1.6 (confidentiality)38- **Sector overlays** — HIPAA, GLBA, CMMC, SEC as applicable39- **Ethics opinions** — relevant state bar opinions on cybersecurity duties4041### 2. Incident Taxonomy4243Four severity tiers:4445| Tier | Criteria | Response Time |46|------|----------|---------------|47| **Critical** | Widespread client data compromise; privilege breach; mandatory reporting triggered | Immediate (24/7) |48| **High** | Multi-matter exposure; attorney email compromise | ≤2 hours |49| **Medium** | Isolated access attempts; contained inadvertent disclosure | ≤4 hours |50| **Low** | Blocked attempts; policy violations without data exposure | Next business day |5152Legal-specific incident types: inadvertent privilege disclosure, case management unauthorized access, conflicts data exposure, attorney email compromise, DMS ransomware, physical file breach.5354### 3. Governance Structure5556| Role | Function | Key Authority |57|------|----------|---------------|58| IR Coordinator | Activates plan, convenes team | Isolate systems, engage external resources |59| General Counsel / Ethics Counsel | Legal/ethical analysis, privilege protection | Direct privileged investigation, approve notifications |60| CISO / IT Director | Technical response, forensics | Evidence preservation, restoration |61| Managing Partner | Strategic decisions | Expenditures, client relationship decisions |62| Communications Director | Internal/external messaging | Media responses (with counsel approval) |6364Include after-hours contact roster and escalation chain for unavailable contacts.6566### 4. Phased Response (NIST 800-61 Adapted)6768**Phase 1 — Preparation**69- Preventive controls inventory70- Annual security awareness training + tabletop exercises71- External expert relationships (forensics, breach counsel, PR)7273**Phase 2 — Identification**74- [ ] Validate incident; preliminary scope assessment75- [ ] Determine if privileged or client-confidential materials involved76- [ ] Assign severity tier; activate response team77- [ ] Initiate investigation under counsel direction to preserve privilege7879**Phase 3 — Containment**80- [ ] Isolate systems; disable compromised accounts; block malicious IPs81- [ ] Enhanced monitoring; emergency patches; migrate to backups if needed8283**Phase 4 — Eradication**84- [ ] Remove malware/unauthorized access; close vulnerabilities85- [ ] Verify no persistent backdoors8687**Phase 5 — Recovery**88- [ ] Restore from verified clean backups89- [ ] System integrity testing; gradual return with heightened monitoring9091**Phase 6 — Lessons Learned** (within 14 days)92- [ ] Post-incident review; document timeline and findings93- [ ] Update IR plan; implement preventive measures9495### 5. Scenario Playbooks9697**Ransomware on DMS:**981. Isolate systems → notify cyber insurance carrier992. Assess backup integrity; evaluate exfiltration indicators (double extortion)1003. Determine client notification obligations per jurisdiction1014. Consider law enforcement (FBI IC3); document all decisions under privilege102103**Attorney Email Compromise:**1041. Reset credentials; revoke sessions; review forwarding/mailbox rules1052. Identify accessed client communications; assess privilege implications1063. Notify affected clients per Rule 1.4; implement MFA107108**Inadvertent Privilege Disclosure:**1091. Notify opposing counsel per FRE 502(b) `[VERIFY]`; request return/destruction1102. Document inadvertence; assess waiver risk under applicable law1113. File clawback motion if necessary112113### 6. Communication Protocols114115| Audience | Trigger | Timing | Approval |116|----------|---------|--------|----------|117| IR Team | Any confirmed incident | Immediate | IR Coordinator |118| Senior Leadership | High/Critical | Within 1 hour | IR Coordinator |119| Affected Clients | Client data compromised | Per statute + "prompt" ethics notice | GC + Managing Partner |120| State AG / Regulators | Statutory threshold met | Per state (30–90 days) | General Counsel |121| Law Enforcement | Criminal activity; ransomware | Case-by-case | General Counsel |122| Media | Public exposure/inquiry | Reactive only | GC + Communications |123124Mark all investigation communications "Privileged & Confidential — Attorney Work Product." Client notifications must satisfy both breach statutes and professional conduct rules.125126### 7. Training and Testing127128| Activity | Frequency |129|----------|-----------|130| Security awareness training | Annual (all personnel) |131| IR team specialized training | Annual |132| Tabletop exercises | Annual minimum |133| Phishing simulations | Quarterly |134| Backup restoration tests | Semi-annual |135| Plan review and update | Annual + post-incident |136137Track: time to detect, contain, eradicate, recover; notification compliance rate.138139### 8. Appendices140141- [ ] Contact roster (internal + external)142- [ ] Incident reporting form template143- [ ] Client notification letter templates (per jurisdiction)144- [ ] Regulatory filing templates145- [ ] Escalation matrix by severity146- [ ] Evidence preservation checklist147- [ ] Breach notification quick-reference table148- [ ] Version control and approval log149150## Pitfalls and Checks151152- **Privilege preservation** — all investigation activities directed by counsel; mark work product accordingly153- **Jurisdiction specificity** — map each state's breach notification statute; never rely on generic summaries154- **Dual obligation** — every notification must satisfy both statutory AND ethics requirements155- **Cite authority** — reference specific statutes, ABA Model Rules, ethics opinions; mark uncertain citations `[VERIFY]`156- **Defensibility** — the plan itself evidences reasonable security measures under Rule 1.1 competence duty157- **Internal only** — this plan governs firm response; separate client advisory communications