Crisis Playbooks
Response procedures for critical incidents and emergencies
Overview
Playbooks for handling crisis situations including security incidents, client emergencies, and business continuity events.
Crisis Categories
Security Incidents
| Crisis |
Playbook |
Response Time |
| Data breach (client) |
client-breach-response.md |
Immediate |
| Ransomware (client) |
ransomware-response.md |
Immediate |
| Insider threat |
insider-threat-response.md |
4 hours |
| Third-party breach |
vendor-breach-response.md |
24 hours |
Client Emergencies
| Crisis |
Playbook |
Response Time |
| Regulatory audit failure |
audit-failure-response.md |
24 hours |
| Critical system outage |
outage-response.md |
Immediate |
| Key person departure |
key-person-departure.md |
48 hours |
Business Continuity
| Crisis |
Playbook |
Response Time |
| SBK system outage |
sbk-outage.md |
Immediate |
| Key staff unavailability |
staff-backup.md |
4 hours |
| Client relationship crisis |
relationship-repair.md |
24 hours |
Playbook Structure
# [Crisis Type] Response Playbook
## Trigger Criteria
When to activate this playbook
## Immediate Actions (First 60 minutes)
- [ ] Action 1
- [ ] Action 2
## Short-term Response (First 24 hours)
- [ ] Action 1
- [ ] Action 2
## Communication Protocol
- Who to notify
- What to communicate
- Templates to use
## Escalation Path
[Escalation matrix]
## Recovery Actions
Steps to return to normal
## Post-Incident
- Documentation requirements
- Lessons learned process
- Process improvements
Activation Protocol
Crisis detected
↓
Severity assessment
↓
Playbook selection
↓
Team assembly
↓
Execute playbook
↓
Regular status updates
↓
Resolution and closeout
↓
Post-incident review