Incident Response Plan and Playbook
Drafts legally defensible IR plans for law firms and legal departments covering cybersecurity incidents, data breaches, privilege preservation, and professional responsibility compliance.
Prerequisites
Gather before drafting:
- Organization profile — firm structure, practice areas, office locations, operating jurisdictions
- Existing policies — infosec policies, business continuity plans, professional responsibility guidelines
- Regulatory landscape — state breach notification statutes, sector overlays (HIPAA, GLBA, CMMC)
- Technology environment — case management systems, DMS, email, backup infrastructure
- Insurance coverage — cyber insurance policy, carrier contact, claim procedures
Quick Start
- Map jurisdictions and applicable breach statutes
- Classify incident types by severity tier
- Define governance roles and escalation chains
- Draft phased response procedures (NIST 800-61 adapted)
- Build scenario-specific playbooks
- Set communication protocols and notification templates
- Establish training/testing cadence
Output Sections
1. Jurisdictional Analysis
Map per operating jurisdiction:
- Breach notification statutes — triggers, timeframes (typically 30–90 days), AG notification
- Professional conduct rules — ABA Model Rules 1.1 (tech competence), 1.4 (communication), 1.6 (confidentiality)
- Sector overlays — HIPAA, GLBA, CMMC, SEC as applicable
- Ethics opinions — relevant state bar opinions on cybersecurity duties
2. Incident Taxonomy
Four severity tiers:
| Tier |
Criteria |
Response Time |
| Critical |
Widespread client data compromise; privilege breach; mandatory reporting triggered |
Immediate (24/7) |
| High |
Multi-matter exposure; attorney email compromise |
≤2 hours |
| Medium |
Isolated access attempts; contained inadvertent disclosure |
≤4 hours |
| Low |
Blocked attempts; policy violations without data exposure |
Next business day |
Legal-specific incident types: inadvertent privilege disclosure, case management unauthorized access, conflicts data exposure, attorney email compromise, DMS ransomware, physical file breach.
3. Governance Structure
| Role |
Function |
Key Authority |
| IR Coordinator |
Activates plan, convenes team |
Isolate systems, engage external resources |
| General Counsel / Ethics Counsel |
Legal/ethical analysis, privilege protection |
Direct privileged investigation, approve notifications |
| CISO / IT Director |
Technical response, forensics |
Evidence preservation, restoration |
| Managing Partner |
Strategic decisions |
Expenditures, client relationship decisions |
| Communications Director |
Internal/external messaging |
Media responses (with counsel approval) |
Include after-hours contact roster and escalation chain for unavailable contacts.
4. Phased Response (NIST 800-61 Adapted)
Phase 1 — Preparation
- Preventive controls inventory
- Annual security awareness training + tabletop exercises
- External expert relationships (forensics, breach counsel, PR)
Phase 2 — Identification
Phase 3 — Containment
Phase 4 — Eradication
Phase 5 — Recovery
Phase 6 — Lessons Learned (within 14 days)
5. Scenario Playbooks
Ransomware on DMS:
- Isolate systems → notify cyber insurance carrier
- Assess backup integrity; evaluate exfiltration indicators (double extortion)
- Determine client notification obligations per jurisdiction
- Consider law enforcement (FBI IC3); document all decisions under privilege
Attorney Email Compromise:
- Reset credentials; revoke sessions; review forwarding/mailbox rules
- Identify accessed client communications; assess privilege implications
- Notify affected clients per Rule 1.4; implement MFA
Inadvertent Privilege Disclosure:
- Notify opposing counsel per FRE 502(b)
[VERIFY]; request return/destruction
- Document inadvertence; assess waiver risk under applicable law
- File clawback motion if necessary
6. Communication Protocols
| Audience |
Trigger |
Timing |
Approval |
| IR Team |
Any confirmed incident |
Immediate |
IR Coordinator |
| Senior Leadership |
High/Critical |
Within 1 hour |
IR Coordinator |
| Affected Clients |
Client data compromised |
Per statute + "prompt" ethics notice |
GC + Managing Partner |
| State AG / Regulators |
Statutory threshold met |
Per state (30–90 days) |
General Counsel |
| Law Enforcement |
Criminal activity; ransomware |
Case-by-case |
General Counsel |
| Media |
Public exposure/inquiry |
Reactive only |
GC + Communications |
Mark all investigation communications "Privileged & Confidential — Attorney Work Product." Client notifications must satisfy both breach statutes and professional conduct rules.
7. Training and Testing
| Activity |
Frequency |
| Security awareness training |
Annual (all personnel) |
| IR team specialized training |
Annual |
| Tabletop exercises |
Annual minimum |
| Phishing simulations |
Quarterly |
| Backup restoration tests |
Semi-annual |
| Plan review and update |
Annual + post-incident |
Track: time to detect, contain, eradicate, recover; notification compliance rate.
8. Appendices
Pitfalls and Checks
- Privilege preservation — all investigation activities directed by counsel; mark work product accordingly
- Jurisdiction specificity — map each state's breach notification statute; never rely on generic summaries
- Dual obligation — every notification must satisfy both statutory AND ethics requirements
- Cite authority — reference specific statutes, ABA Model Rules, ethics opinions; mark uncertain citations
[VERIFY]
- Defensibility — the plan itself evidences reasonable security measures under Rule 1.1 competence duty
- Internal only — this plan governs firm response; separate client advisory communications
1---2name: incident-response-plan3description: Drafts incident response plans and playbooks for legal organizations, adapting NIST SP 800-61 to law firm contexts including privilege preservation, ethics obligations, and state breach notification compliance. Use when creating IR plans, cybersecurity playbooks, breach response policies, or data incident procedures for law firms or legal departments.4license: Apache-2.05---67# Incident Response Plan and Playbook89Drafts legally defensible IR plans for law firms and legal departments covering cybersecurity incidents, data breaches, privilege preservation, and professional responsibility compliance.1011## Prerequisites1213Gather before drafting:14151. **Organization profile** — firm structure, practice areas, office locations, operating jurisdictions162. **Existing policies** — infosec policies, business continuity plans, professional responsibility guidelines173. **Regulatory landscape** — state breach notification statutes, sector overlays (HIPAA, GLBA, CMMC)184. **Technology environment** — case management systems, DMS, email, backup infrastructure195. **Insurance coverage** — cyber insurance policy, carrier contact, claim procedures2021## Quick Start22231. Map jurisdictions and applicable breach statutes242. Classify incident types by severity tier253. Define governance roles and escalation chains264. Draft phased response procedures (NIST 800-61 adapted)275. Build scenario-specific playbooks286. Set communication protocols and notification templates297. Establish training/testing cadence3031## Output Sections3233### 1. Jurisdictional Analysis3435Map per operating jurisdiction:3637- **Breach notification statutes** — triggers, timeframes (typically 30–90 days), AG notification38- **Professional conduct rules** — ABA Model Rules 1.1 (tech competence), 1.4 (communication), 1.6 (confidentiality)39- **Sector overlays** — HIPAA, GLBA, CMMC, SEC as applicable40- **Ethics opinions** — relevant state bar opinions on cybersecurity duties4142### 2. Incident Taxonomy4344Four severity tiers:4546| Tier | Criteria | Response Time |47|------|----------|---------------|48| **Critical** | Widespread client data compromise; privilege breach; mandatory reporting triggered | Immediate (24/7) |49| **High** | Multi-matter exposure; attorney email compromise | ≤2 hours |50| **Medium** | Isolated access attempts; contained inadvertent disclosure | ≤4 hours |51| **Low** | Blocked attempts; policy violations without data exposure | Next business day |5253Legal-specific incident types: inadvertent privilege disclosure, case management unauthorized access, conflicts data exposure, attorney email compromise, DMS ransomware, physical file breach.5455### 3. Governance Structure5657| Role | Function | Key Authority |58|------|----------|---------------|59| IR Coordinator | Activates plan, convenes team | Isolate systems, engage external resources |60| General Counsel / Ethics Counsel | Legal/ethical analysis, privilege protection | Direct privileged investigation, approve notifications |61| CISO / IT Director | Technical response, forensics | Evidence preservation, restoration |62| Managing Partner | Strategic decisions | Expenditures, client relationship decisions |63| Communications Director | Internal/external messaging | Media responses (with counsel approval) |6465Include after-hours contact roster and escalation chain for unavailable contacts.6667### 4. Phased Response (NIST 800-61 Adapted)6869**Phase 1 — Preparation**70- Preventive controls inventory71- Annual security awareness training + tabletop exercises72- External expert relationships (forensics, breach counsel, PR)7374**Phase 2 — Identification**75- [ ] Validate incident; preliminary scope assessment76- [ ] Determine if privileged or client-confidential materials involved77- [ ] Assign severity tier; activate response team78- [ ] Initiate investigation under counsel direction to preserve privilege7980**Phase 3 — Containment**81- [ ] Isolate systems; disable compromised accounts; block malicious IPs82- [ ] Enhanced monitoring; emergency patches; migrate to backups if needed8384**Phase 4 — Eradication**85- [ ] Remove malware/unauthorized access; close vulnerabilities86- [ ] Verify no persistent backdoors8788**Phase 5 — Recovery**89- [ ] Restore from verified clean backups90- [ ] System integrity testing; gradual return with heightened monitoring9192**Phase 6 — Lessons Learned** (within 14 days)93- [ ] Post-incident review; document timeline and findings94- [ ] Update IR plan; implement preventive measures9596### 5. Scenario Playbooks9798**Ransomware on DMS:**991. Isolate systems → notify cyber insurance carrier1002. Assess backup integrity; evaluate exfiltration indicators (double extortion)1013. Determine client notification obligations per jurisdiction1024. Consider law enforcement (FBI IC3); document all decisions under privilege103104**Attorney Email Compromise:**1051. Reset credentials; revoke sessions; review forwarding/mailbox rules1062. Identify accessed client communications; assess privilege implications1073. Notify affected clients per Rule 1.4; implement MFA108109**Inadvertent Privilege Disclosure:**1101. Notify opposing counsel per FRE 502(b) `[VERIFY]`; request return/destruction1112. Document inadvertence; assess waiver risk under applicable law1123. File clawback motion if necessary113114### 6. Communication Protocols115116| Audience | Trigger | Timing | Approval |117|----------|---------|--------|----------|118| IR Team | Any confirmed incident | Immediate | IR Coordinator |119| Senior Leadership | High/Critical | Within 1 hour | IR Coordinator |120| Affected Clients | Client data compromised | Per statute + "prompt" ethics notice | GC + Managing Partner |121| State AG / Regulators | Statutory threshold met | Per state (30–90 days) | General Counsel |122| Law Enforcement | Criminal activity; ransomware | Case-by-case | General Counsel |123| Media | Public exposure/inquiry | Reactive only | GC + Communications |124125Mark all investigation communications "Privileged & Confidential — Attorney Work Product." Client notifications must satisfy both breach statutes and professional conduct rules.126127### 7. Training and Testing128129| Activity | Frequency |130|----------|-----------|131| Security awareness training | Annual (all personnel) |132| IR team specialized training | Annual |133| Tabletop exercises | Annual minimum |134| Phishing simulations | Quarterly |135| Backup restoration tests | Semi-annual |136| Plan review and update | Annual + post-incident |137138Track: time to detect, contain, eradicate, recover; notification compliance rate.139140### 8. Appendices141142- [ ] Contact roster (internal + external)143- [ ] Incident reporting form template144- [ ] Client notification letter templates (per jurisdiction)145- [ ] Regulatory filing templates146- [ ] Escalation matrix by severity147- [ ] Evidence preservation checklist148- [ ] Breach notification quick-reference table149- [ ] Version control and approval log150151## Pitfalls and Checks152153- **Privilege preservation** — all investigation activities directed by counsel; mark work product accordingly154- **Jurisdiction specificity** — map each state's breach notification statute; never rely on generic summaries155- **Dual obligation** — every notification must satisfy both statutory AND ethics requirements156- **Cite authority** — reference specific statutes, ABA Model Rules, ethics opinions; mark uncertain citations `[VERIFY]`157- **Defensibility** — the plan itself evidences reasonable security measures under Rule 1.1 competence duty158- **Internal only** — this plan governs firm response; separate client advisory communications