patch&proof.
← Research library

Response / Research chapter

Incident Response: Program, Lifecycle, and Eleven Playbooks

Research date: September 14–15, 2026. Defensive material. These playbooks describe how to respond to attacks, not how to conduct them.

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Research date: September 14–15, 2026. Defensive material. These playbooks describe how to respond to attacks, not how to conduct them.


Part A — Building the capability

A1. SOC operating models

Four models, and most organizations under about 1,000 employees land on hybrid or fully outsourced.

In-house SOC. Full internal team, tooling, and 24/7 coverage. The realistic minimum for true round-the-clock coverage is eight to twelve analysts — four shifts plus leads plus engineering. Industry estimates put a minimally viable internal SOC above $1.4M–$1.75M per year: more than $1M in personnel, $300K–$500K in tooling, plus training and overhead. Appropriate for enterprises, banks, and regulated critical infrastructure.

Hybrid or co-managed SOC. The internal team owns strategy, context, and escalations while an MDR provider covers 24/7 monitoring and first-line triage. The most common pattern for mid-market organizations of 500 to 5,000 employees, with two to six internal staff focused on detection engineering, incident command, and vendor management.

MDR or MSSP. Managed detection and response typically prices at $10–$30 per endpoint per month, with total annual costs running roughly $50K for small businesses to $300K+ for large environments. The differentiators that matter when buying: response authority (will they contain, or only notify?), coverage of cloud and identity rather than endpoints alone, transparent SLAs on time-to-notify, and whether detections are portable if you leave. MSSPs — log monitoring and device management — are generally cheaper but alert-forwarding-oriented; MDR includes investigation and guided or active response.

Virtual SOC with fractional leadership. For small organizations: no dedicated team, a vCISO at roughly $2K–$10K per month, MDR for monitoring, and an IR retainer for emergencies. Note that CISA's CPG 2.0 specifically added goals addressing risks from third-party providers with deep system access — outsourcing shifts risk, it does not eliminate it.

Choosing. Under about 200 staff: MDR plus a vCISO. 200 to 1,000: MDR plus one to three internal security staff. 1,000 to 5,000: hybrid co-managed. Above 5,000 or heavily regulated: in-house or a heavily instrumented hybrid.

A2. Detection engineering and detection-as-code

Detection engineering treats detections as software: version-controlled rules, peer review, CI/CD testing, and metrics.

Store rules in Git — Sigma, YARA, or vendor query languages — with pull-request review, automated linting and unit tests against sample logs, and automated deployment to the SIEM or EDR. Map every detection to MITRE ATT&CK and track coverage; a pragmatic 2026 benchmark is roughly 65% coverage of relevant techniques, with detections at three or more points in a typical attack chain. Lifecycle each rule from hypothesis through prototype, test, deploy, tune, and retire, recording false-positive rates and last-fired dates, and actually retiring dead rules.

Prioritize by threat model. With exploitation the leading initial access vector and prior compromise the top ransomware vector at 30%, edge devices, VPNs, identity providers, and infostealer-related logins deserve first-class detections — not just endpoint malware.

A3. Threat hunting

Proactive, hypothesis-driven searches for behavior that evaded automated detection. A practical program has three elements: hypotheses drawn from current intelligence such as CISA #StopRansomware advisories; scheduled hunts — weekly or monthly — over identity logs, VPN and edge appliances, cloud control planes, and egress data; and an output from every hunt, whether a new detection, a hardening fix, or a documented negative result.

The core argument for hunting is in the data: espionage intrusions dwell for roughly 122 days, and some edge-device implants have persisted around 400 days. Automated detection alone misses long-dwell activity on appliances that cannot run EDR.

A4. IR team structure and retainers

Per NIST SP 800-61r3 and long-standing SANS practice, team models are central, distributed-but-coordinated, or a coordinating CSIRT. The roles that must exist regardless of size: incident commander, technical leads (endpoint, network, cloud and identity, forensics), scribe and timeline keeper, communications lead, legal counsel, and executive liaison. Even a 20-person company should name a decision-maker, a technical lead, and a communicator in its plan.

Retainers are pre-negotiated contracts guaranteeing SLA'd response, commonly two to four hours for remote engagement. Types: prepaid hours, often convertible to proactive work such as tabletops; zero-dollar retainers with no prepayment but guaranteed rates; and insurer-panel arrangements. The 2025–26 buying advice: verify the firm is on your cyber insurer's approved panel, engage through counsel to preserve privilege, and check that the SLA covers cloud and OT if relevant. Most cyber policies designate a breach coach — a privacy attorney who quarterbacks the response and manages privilege.

A5. Forensics capability

Minimum viable internal capability: EDR with 30 to 90 days of historical telemetry; centralized logs with twelve-plus months retention for identity, VPN, email, and cloud audit sources; a documented evidence-handling procedure with chain-of-custody forms and imaging capability for key cases; and a relationship with an external DFIR firm for anything beyond triage.

Preservation basics belong in every playbook: do not wipe or reimage before imaging; preserve volatile data where feasible; export and protect logs immediately, because attackers delete them; and record all response actions with timestamps. NIST 800-61r3 emphasizes deciding evidence-preservation standards before incidents, as part of preparation.

A6. Crisis communications

Prepare in advance: pre-approved holding statements for the top three or four scenarios, a single-spokesperson policy, out-of-band communication channels on the assumption that email and Teams are compromised, a notification matrix covering customers, regulators, insurer, and board, and legal review of all external statements.

The lesson from the first year of SEC Item 1.05 filings is worth publishing: 50% of filers had to amend their disclosures with later detail. Draft initial statements that are accurate without over-claiming — "no evidence of X at this time" rather than "no data was taken." The common failures are speculating on scope early, promising outcomes before forensics conclude, and letting the 72-hour and 30-day notification clocks surprise the communications team.

A7. Business continuity and disaster recovery

RTO is maximum tolerable downtime; RPO is maximum tolerable data loss, which drives backup frequency. Both come out of a business impact analysis that tiers systems: Tier 0 for identity, backups, and payment processing with RTO in hours; Tier 1 for core line-of-business with RTO around a day; Tier 2 and below in days.

Backup architecture is 3-2-1 plus at least one offline or immutable copy — CISA's #StopRansomware Guide makes "maintain offline, encrypted backups and regularly test them" its first best practice. Test restores, not just backups: timed restoration exercises are the only way to know whether an RTO is achievable, and 800-61r3's Recover guidance stresses verifying backup integrity before restoration and validating restored systems before returning them to production.

Plan for identity-out recovery. Modern ransomware frequently compromises Active Directory or Entra, so the rebuild order — identity, then backups, then core applications — should be documented before it is needed.

A8. Tabletop exercises

CISA's Tabletop Exercise Packages are free, downloadable, and customizable, covering ransomware, insider threat, industry-specific, and cyber-physical scenarios with facilitator guides. That removes the most common excuse for not exercising.

Cadence: at least annually for executives, focused on decisions — pay or not, disclose or not, downtime tolerance — and twice yearly for technical teams, walking playbooks. Many insurers and frameworks now expect documented annual testing.

Good exercises inject realistic complications: the backups are also encrypted, the insurer and counsel are unavailable for four hours, a journalist calls mid-incident, and two regulatory deadlines conflict.

A9. Metrics and current benchmarks

Metric Definition 2026 benchmark (mature SOC)
MTTD Activity start to alert 30 minutes–4 hours
MTTA Alert to analyst acknowledgment Critical ≤20 minutes (top decile)
MTTI Acknowledgment to investigation resolved 10 minutes–1 hour
MTTR Detection to containment Critical ≤1 hour; high ≤2 hours; medium ≤4 hours
False-positive rate Per severity tier Critical <25%; high <50%
Dwell time Compromise to detection (industry-wide) Median 14 days (M-Trends 2026)
Identify plus contain Full breach lifecycle (industry-wide) 241 days mean (IBM 2025)

Context metrics worth publishing internally: alerts per analyst per day, with burnout risk above roughly 10 to 15 investigations per analyst per day; percentage of alerts auto-triaged; detection coverage against ATT&CK; and percentage of incidents with completed lessons-learned. Warn readers about MTTR gamification — closing tickets fast is a known anti-pattern. Pair every speed metric with a quality metric such as reopen rate or false-negative review.


Part B — The incident lifecycle

B1. What changed in NIST SP 800-61 Revision 3

NIST published SP 800-61r3 in April 2025, and the change is conceptual rather than cosmetic. The classic four-phase lifecycle is reframed around the six CSF 2.0 functions: Govern, Identify, and Protect constitute preparation; Detect, Respond, and Recover constitute active response; and Improvement, sitting under Identify, feeds lessons learned continuously into all functions rather than only after a formal post-mortem.

IR is positioned as continuous cybersecurity risk management rather than an episodic activity. The publication deliberately drops step-by-step technical procedures — they age quickly — in favor of outcomes mapped to CSF 2.0 and prioritized High, Medium, and Low.

Its recommendations include putting IR requirements in vendor contracts, maintaining automated asset and software inventories, building playbooks for common scenarios, combining continuous monitoring with threat intelligence, prioritizing incidents by risk rather than first-come-first-served, pre-authorizing automated containment, verifying backup integrity before restore, and holding structured lessons-learned meetings.

The SANS PICERL model remains the most teachable phase model and coexists comfortably with this. Present both: SANS phases for "what do I do now," the CSF 2.0 mapping for "how do I build the program."

B2. The phases in practice

Preparation. A written plan with roles and a 24/7 contact tree; playbooks for top scenarios; logging enabled and centralized before you need it; asset inventory; IR retainer and insurer contacts on file; legal counsel identified; offline backups; exercises. The UK NCSC's small-business guide condenses this to five steps — prepare, identify, resolve, report, learn — which is a good frame for a beginner audience.

Detection and analysis. Validate the alert; scope which accounts, hosts, and data are involved; classify severity against pre-agreed criteria (data sensitivity, operational impact, spread); start the incident timeline document immediately; preserve evidence as you go. Declare an incident early — renaming a breach an "event" to avoid triggering process is a classic failure mode.

Containment. Choose a strategy by trade-off: evidence preservation versus damage limitation versus business continuity. Typical actions are isolating hosts through EDR (network-contain rather than power off, to preserve memory), disabling or resetting compromised accounts and revoking tokens and sessions, blocking indicators, and segmenting networks. NIST r3 endorses pre-authorized automated containment for speed — with access-broker hand-offs measured at 22 seconds, human-speed containment increasingly loses.

Eradication. Remove persistence — accounts, scheduled tasks, malicious OAuth applications, web shells, implants — patch the exploited weakness, and rebuild rather than clean where feasible. Identify all affected systems before eradicating; tipping off an attacker who retains other footholds prolongs the incident.

Recovery. Restore from verified-clean backups; validate systems before returning them to production; reset credentials in the right order — privileged first, then service accounts, then users, rotating Kerberos-relevant secrets twice where AD was compromised; and maintain heightened monitoring for re-entry, because attackers return through the same door. Prior compromise is now the leading ransomware vector at 30%.

Lessons learned. A blameless review within roughly two weeks, producing tracked corrective actions, metric updates, and a leadership briefing. Under 800-61r3, improvements feed in continuously rather than waiting for the formal meeting.

B3. Notification and regulatory timelines (US-centric, as of September 2026)

Regime Who Clock Notes
SEC cyber disclosure US public companies Form 8-K Item 1.05 within 4 business days of determining materiality (not of discovery) May 2024 guidance: use Item 1.05 only for material incidents; voluntary disclosures go under Item 8.01. First-year data: median 4.5 business days from detection to disclosure; 50% later amended
GDPR Organizations processing EU personal data 72 hours to the supervisory authority after becoming aware; individuals without undue delay if high risk Applies to US companies serving EU residents
HIPAA breach notification Covered entities and business associates Individuals within 60 days; HHS within 60 days, and for 500+ records also media The proposed Security Rule overhaul would separately mandate MFA, encryption, and inventories
State breach laws All 50 states Tightening: 30-day deadlines now in California (signed Oct 2025, with AG sample notice within 15 days for 500+ residents), Colorado, Florida, Maine, New York, Washington; Oklahoma updated effective Jan 1, 2026 Definitions and triggers vary; encryption safe harbors are common
CIRCIA (once final rule is in force) Critical infrastructure entities 72 hours for covered incidents; 24 hours for ransom payments Final rule still in late-stage rulemaking as of Sept 2026
NYDFS Part 500 NY-regulated financial firms 72 hours for cybersecurity events; 24 hours for ransomware payment notice
GLBA Safeguards Rule Non-bank financial institutions FTC notification within 30 days for breaches affecting 500+ consumers Effective May 2024
EU NIS2 Essential and important entities 24-hour early warning, 72-hour notification, one-month final report Via national transpositions
FBI / CISA (voluntary) Everyone As soon as possible Reporting to law enforcement is an OFAC mitigating factor

The teaching point: notification is a parallel workstream from hour one, run by counsel — not a post-recovery afterthought.


Part C — Eleven response playbooks

Every playbook shares a spine: triggers → first hour → containment → notify → eradicate and recover → preserve evidence → common mistakes → reporting obligations.

Universal first-hour rules. Start a timestamped incident log. Assemble the core team on an out-of-band channel. Do not power off machines — network-isolate instead, to preserve memory. Call counsel and the insurer early: most policies require insurer consent before engaging vendors or making any payment.

C1. Ransomware

Triggers. Ransom notes; mass file renaming or encryption; EDR alerts for shadow-copy deletion or backup-service tampering; sudden backup job failures; precursor infections such as infostealers and loaders. Remember that 30% of ransomware now begins with prior compromise or resold access — an infostealer alert is a ransomware precursor.

First hour. Isolate affected systems from the network but leave them powered on. Disconnect and protect backups immediately, because attackers hunt them. Disable suspected-compromised privileged accounts. Identify the variant from the note and file extensions. Activate the IR retainer, insurer, and counsel.

Containment. Segment or take down shares and hypervisors under active encryption; block command-and-control indicators; reset privileged credentials; and assume data was stolen before encryption, because double extortion is the norm.

Notify. Internal executives and legal; the cyber insurer before engaging vendors; the FBI via IC3 or a field office; CISA; and regulators per Part B3 if personal data is affected.

Pay or don't pay. The US government position is that payment is discouraged, does not guarantee recovery, and funds further crime; 69% of victims did not pay in DBIR 2026. The decisive legal risk is OFAC sanctions: paying a sanctioned actor can violate IEEPA on a strict-liability basis, with penalties applying even where the payer did not know the counterparty was sanctioned. OFAC weighs mitigating factors including strong pre-incident security, prompt reporting to law enforcement, and full cooperation. Any payment decision runs through counsel, the insurer, and a sanctions screen by an experienced negotiation firm. Once CIRCIA's rule is in force, ransom payments must be reported to CISA within 24 hours.

Eradicate and recover. Rebuild from clean images; restore from offline backups after verifying integrity; patch or close the initial vector; rotate all credentials; monitor for re-entry.

Evidence. Preserve one encrypted sample and the ransom note; image representative systems; export logs before they roll; keep the extortion communications.

Common mistakes. Wiping systems before imaging. Restoring onto a still-compromised network. Announcing "no data taken" prematurely. Negotiating without counsel and insurer. Missing that backups were compromised weeks earlier.

C2. Phishing

Triggers. User reports; email security alerts; anomalous logins following delivery; lookalike-domain registrations.

First hour. Obtain the original message with full headers. Determine blast radius by searching and purging the campaign across all mailboxes. Identify who clicked, who entered credentials, and who ran attachments.

Containment. Purge messages; block sender, domain, and URLs. For credential entry, escalate to C4 — reset the password, revoke sessions and tokens, and check mailbox rules. For attachment execution, escalate to C8.

Notify. Affected users, with no blame, because blame kills reporting. Report phishing to CISA and to impersonated brands. IC3 if there were losses.

Eradicate and recover. Hunt for follow-on activity for 30 days; tune mail filters; verify DMARC, SPF, and DKIM enforcement.

Common mistakes. Deleting the reported email, which destroys evidence. Punishing the reporter. Stopping at a password reset without killing sessions and checking mailbox rules. Assuming one recipient means one target.

C3. Business email compromise

Triggers. Payment-redirect requests, "changed bank details," vendor invoice anomalies, executive urgency or gift-card requests, and auto-forwarding rules discovered in mailboxes. BEC cost roughly $3B in reported 2025 US losses.

First hour — if money moved, this is a race. Contact your bank's fraud department immediately to request recall or freeze. File with IC3 and ask about the FBI's Financial Fraud Kill Chain, most effective for wires of $50K or more, international transfers, and reports made within roughly 72 hours. Preserve all emails.

Containment. Determine whether the fraud came from a spoofed lookalike domain, meaning no account compromise, or from a compromised mailbox — in which case reset credentials, revoke sessions, remove forwarding and inbox rules, review OAuth grants, and check delegate access.

Notify. Banks on both ends; IC3 and the FBI; the insurer, under both crime and cyber policies; the counterparty organization if their account was the compromised one; affected vendors and customers.

Eradicate and recover. Enforce MFA, phishing-resistant for finance roles. Implement out-of-band verification for any payment-detail change, calling back a number of record. DMARC at p=reject.

Common mistakes. Waiting even a day to contact banks and IC3. Resetting only the password and missing forwarding rules and OAuth persistence. Failing to determine which side's mailbox was compromised. Not fixing the payment-verification process afterward.

C4. Stolen credentials and account compromise

Triggers. Impossible-travel or anomalous logins; credentials found in infostealer dumps; MFA-fatigue push storms; identity-provider alerts; help-desk social-engineering attempts — voice phishing is now the second-most-common intrusion vector at 11%.

First hour. Reset the password and revoke all active sessions and refresh tokens — a reset alone does not log attackers out. Check MFA method changes and newly registered devices. Review recent activity: mail rules, file access, OAuth consents.

Containment. Disable the account if abuse is active. Block attacker infrastructure cautiously. Scope laterally: one stolen credential often means an infostealer on a device, which must be found and reimaged, or a phishing campaign with other victims.

Notify. The user; internal security; and if a privileged account is involved, treat it as a major incident. Regulators only if data access is confirmed.

Eradicate and recover. Phishing-resistant MFA for administrators first; conditional access blocking legacy authentication; 30 days of heightened monitoring on the account.

Common mistakes. Password reset without session and token revocation. Ignoring the source, such as an infected personal device syncing browser passwords. Treating infostealer hits as low priority — they are the raw material of the access-broker economy.

C5. Cloud compromise

Triggers. Unusual API calls; new IAM users or keys; resource spin-up suggesting cryptomining; disabled logging; anomalous console logins; malicious OAuth app consents; billing spikes.

First hour. Identify the compromised principal — user, role, key, or application — and disable or rotate it. Do not delete anything, since it is evidence. Snapshot affected instances. Verify that audit logging is still enabled and preserved.

Containment. Rotate exposed keys and secrets; restrict permissive roles; quarantine workloads via security groups; revoke suspicious OAuth grants and app registrations; check for persistence such as new admin accounts, modified conditional access, and federation or trust changes — attackers add their own identity provider.

Notify. The cloud provider through its abuse or incident process; insurer and counsel; customers if their data was in scope; regulators per Part B3.

Eradicate and recover. Rebuild workloads from known-good infrastructure-as-code; audit the entire identity plane including federation settings, service principals, and keys; enable org-level guardrails. For Microsoft 365 and Google Workspace hardening, CISA's SCuBA secure configuration baselines are the free reference.

Common mistakes. Rotating one leaked key but missing the persistence it created. Deleting attacker resources before forensics. Assuming provider-side logging defaults are sufficient — retention is often short unless configured. Overlooking third-party app integrations as the entry point.

C6. Data breach

Triggers. Extortion emails with data samples; data found on leak sites; DLP or egress alerts; researcher or customer notification; discovery during another incident.

First hour. Engage counsel first, to establish privilege over the investigation. Validate the claim — is the sample real, current, and yours? Begin scoping what data, whose, how many records, and which jurisdictions.

Containment. Close the exposure — a misconfigured bucket, a vulnerable application, a compromised account — and preserve access logs, because they determine who actually accessed what, which in turn drives notification scope.

Notify. Insurer; then a counsel-driven regulatory matrix: state attorneys general, GDPR's 72 hours, HIPAA, SEC materiality analysis for public companies, affected individuals per statute, and credit-monitoring decisions.

Eradicate and recover. Fix the root cause; verify no other similar exposures by configuration-scanning everything; harden and monitor.

Evidence. Access logs proving or limiting scope are the most valuable artifact — preserve them immediately and document the scoping methodology, because regulators ask.

Common mistakes. Notifying too early with the wrong scope, since forced re-notification destroys trust, or too late, which violates statute. Letting IT "fix" the system before logs are preserved. Conducting the investigation outside privilege. Forgetting data held by vendors.

C7. Insider threat

Triggers. Mass downloads or USB copies before a resignation; access outside role or hours; DLP alerts; exfiltration to personal cloud or email; disgruntlement reported by managers; a departing employee taking "their" work. DBIR 2026 flags unsanctioned shadow AI use as the third-most-common non-malicious insider action.

First hour. Loop in HR and legal before any confrontation. Quietly preserve evidence — mailbox hold, endpoint logs, badge and VPN records. Avoid alerting the person prematurely.

Containment. For active exfiltration, suspend access in a coordinated action with HR and legal. For departing employees, standard offboarding with immediate access revocation and return-of-property attestation.

Notify. HR, legal, management chain; law enforcement for trade-secret theft where warranted; customers or regulators only if personal data left the organization.

Eradicate and recover. Access reviews and least-privilege cleanup; DLP tuning; sanctioned AI tooling with guardrails, since the fix for shadow AI is a safe alternative rather than a ban.

Evidence. Chain of custody matters most here, because litigation or prosecution is likely. Use forensically sound collection.

Common mistakes. Confronting the employee before evidence is preserved. Treating it purely as a security problem without HR and legal. Monitoring in ways that violate employment or privacy law. Hunting rare malicious insiders while ignoring the negligent majority.

C8. Malware infection (non-ransomware)

Triggers. EDR or AV detections; command-and-control beaconing; cryptominer resource spikes; user reports of odd behavior; threat-intelligence hits on your addresses.

First hour. Network-isolate the host via EDR, keeping it powered on. Identify the malware family and its capabilities — stealer, loader, or remote-access tool. Check whether it is a precursor: loaders and infostealers routinely front-run ransomware.

Containment. Isolate all hosts sharing the same indicators; block command-and-control; and if credentials were on the box — browser-stored, SSH keys, tokens — treat every one as stolen and escalate to C4.

Eradicate and recover. Reimage rather than clean for anything beyond commodity adware. Verify persistence removal. Patch the delivery vector.

Evidence. Memory capture where feasible before isolation changes state; sample the binary with a hash and a quarantined copy; export the EDR timeline.

Common mistakes. "AV cleaned it, we're done," with no investigation of what executed or what it accessed. Powering off, which loses memory. Not resetting credentials cached on the machine. Ignoring a single infostealer detection that later becomes the ransomware entry point.

C9. Lost or stolen device

Triggers. User report; MDM check-in anomalies; police report.

First hour. Confirm encryption status — this single fact determines whether the event is a breach or a hardware loss. Trigger remote lock and locate via MDM. Revoke device tokens, sessions, and Wi-Fi and VPN certificates.

Containment. Remote wipe when recovery is unlikely, documenting the decision and timing. Reset credentials cached or saved on the device. Monitor the user's accounts.

Notify. IT and security; a police report for theft, which insurers require; and if the device was unencrypted and held personal data, a breach analysis under Part B3. Many state laws exempt encrypted data — this encryption safe harbor is the core lesson for readers.

Evidence. MDM logs showing last check-in and wipe confirmation, the police report, and the encryption attestation.

Common mistakes. Having no proof of encryption at the time of loss, which forfeits the safe harbor. Wiping before considering evidentiary needs in theft cases with a suspect. Forgetting synced accounts, saved passwords, and cached email. BYOD devices with no MDM at all.

C10. Third-party or vendor compromise

Triggers. Vendor breach notification; news or regulatory filings about a supplier; anomalous activity from vendor accounts or integrations; a software update behaving oddly; alerts about components you consume, such as CISA's September 2025 npm ecosystem alert. DBIR 2026 put third-party involvement in breaches up 60% year over year, to nearly half of all breaches.

First hour. Identify every integration point — accounts, API keys, VPN tunnels, data shared, software deployed. Disable or restrict vendor access pending scoping. Demand specifics from the vendor: indicators, timeframe, affected services.

Containment. Rotate all credentials and keys the vendor held or could access. Review logs of vendor account activity across the compromise window. Suspend automated data feeds if exposure is suspected.

Notify. Insurer and counsel; customers if your data at the vendor was affected, since you likely retain notification obligations for your data even when the breach was theirs; regulators per Part B3; and the contracts team, for breach-notification SLAs and indemnification.

Eradicate and recover. Re-enable access only after vendor attestation of remediation, with compensating monitoring on reconnection. Reassess vendor tiering and least privilege across all third parties. CISA's CPG 2.0 added goals for third parties with deep access — use them as a vendor questionnaire baseline.

Common mistakes. Waiting for the vendor's full report before rotating credentials. Not knowing what access a vendor actually has — do that inventory now, not mid-incident. Treating SaaS vendors as out of scope for your IR plan. Having no contractual breach-notification SLA.

C11. Denial-of-service attack

Triggers. Unavailability with traffic spikes; upstream provider alerts; extortion emails threatening or claiming attacks.

First hour. Confirm it is actually a DDoS, ruling out failed deploys, certificate expiry, and upstream outages. Activate mitigation through your CDN or scrubbing provider. Notify stakeholders of degraded service.

Containment. Rate-limit, geo-filter, or challenge suspicious traffic per provider guidance; scale critical services; and protect origin IPs, because attackers bypass CDNs by finding them.

Notify. ISP, hosting, or CDN provider, since they perform the mitigation. The FBI and IC3, especially for extortion-driven attacks — do not pay, since payment invites repeats and rarely stops attacks. CISA. The joint CISA/FBI/MS-ISAC guidance on understanding and responding to DDoS attacks is the free reference.

Eradicate and recover. There is nothing to eradicate on your systems, since this is traffic rather than intrusion — but check whether the DDoS was a smokescreen for intrusion attempts during the outage window. Afterward, formalize a runbook with provider contacts.

Evidence. Flow logs and provider reports, extortion emails, and a timeline of impact for business-interruption insurance claims.

Common mistakes. Having no pre-existing mitigation contract, since procurement mid-attack is slow and expensive. Exposing origin IPs. Paying extortion. Ignoring concurrent intrusion attempts. Failing to communicate with customers during the outage.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval