Security Incident Identification and Response Framework

Identify. Respond. Recover.

Practical plans, team exercises and playbooks that help civil society respond calmly when digital attacks happen.

About SIIRF

SIIRF, the Security Incident Identification and Response Framework, helps civil society organisations, independent media and human rights defenders prepare for, identify and respond to digital security incidents.

It brings together a readiness assessment, tabletop exercises, incident playbooks and practical guides, designed for small teams without IT staff. Everything is free to use, and nothing you enter is tracked or stored.

SIIRF is developed and maintained by BOLTECH.

1Preparation2Identification3Containment4Eradication5Recovery6Lessonslearned

Our Approach

SIIRF follows the six stages of incident response used by security teams worldwide, adapted for small civil society teams: plain language, practical tools, and practice before the bad day.

  1. 1
    PreparationPlans, roles, training and tools in place before anything happens.
  2. 2
    IdentificationSpot the signs early, and confirm what is happening and how serious it is.
  3. 3
    ContainmentStop the damage spreading, and protect people first.
  4. 4
    EradicationRemove the cause: malware, the attacker's access, and the weakness they used.
  5. 5
    RecoveryRestore systems and data safely, and return to normal work.
  6. 6
    Lessons learnedReview what happened, and improve your plan and practices.

Partner with us

Fund free support for grassroots organisations, or bring SIIRF exercises to your network.