🎉 Launch offer — 20% off every workbook & bundle. Applied automatically at checkout.
ciso.diy
Pillar 05 — The Incident Response Operating System preview
Security Program Pillars incident responsepillar 05IRNIST 800-61

Pillar 05 — The Incident Response Operating System

An operating system for the worst day — the right people in one room, on one clock, with 90% of the hardest choices already made. Built on NIST 800-61 Rev. 3, with the offline runbook, the notification clocks and a ready-to-run tabletop.

Pillar 05 of the CISO Marketplace AI Security Department, built DIY. The managed incident response pillar is the done-for-you version.

An IR program is not a binder you file. It is an operating system for the worst day — one that puts the right people in one room, on one clock, and has already made 90% of its hardest choices before the incident lands.

Built on NIST 800-61 Rev. 3 — the 2025 rewrite most guides missed. If your plan still follows the retired revision, it is describing a lifecycle that no longer matches the current framework. That alone is worth the re-read.

90% of incident response is preparation, and the guide is structured that way. Name the CSIRT as roles with backups rather than as people who might be on a plane. Pre-grant emergency isolation authority, so nobody is hunting for permission at 2am. Establish a DFIR retainer — and understand what a retainer does and does not buy you before you need to find out.

The offline runbook is the cheapest, highest-value artifact in the guide — a break-glass one-pager carrying hotlines, contacts, architecture and credential locations, filled in, printed, and stored offline. It is the one artifact that still works when everything else you own is encrypted or unreachable. Most programs discover they needed it at the exact moment they cannot produce it.

Runbooks and tabletops. Scenario playbooks for ransomware, breach, BEC and insider threat, with idempotent containment steps and explicit decision points — then rehearsed, because coordination is a muscle and the fire is a bad place to build it. 90% of organisations say they would struggle to coordinate; 75% report that legal and communications delays slow their decisions. A tested IR plan cuts average breach cost by $2.66M.

The first 72 hours, and the clocks. The response sequence — detect, secure communications, activate, contain, preserve evidence, notify — with the notification clocks computed from their actual triggers. The SEC's is four business days and starts at materiality, not at discovery, which is the distinction that catches people. GDPR, HIPAA and your carrier's own reporting requirement all run on different clocks from different starting guns, and the guide has you know them cold rather than reconstruct them under pressure.

When it fires, IR coordinates every pillar. Pillar 04 detects the incident and hands it off with a full evidence trail; Pillar 06 runs the board materiality call and owns the risk narrative. This is the pillar the others hand off to.

Includes the fillable offline runbook one-pager, a notification-clock worksheet computing every deadline from its trigger, the P1–P4 severity matrix with escalation criteria, a ready-to-run 60–90 minute ransomware tabletop with five injects, and the incident register schema.

Not legal advice — and the guide is explicit about where counsel and privilege belong in the sequence.

What's included

  • PDF — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-01
Pages 24