Security Incident Identification and Response Framework
Identify. Respond. Recover.
Practical plans, team exercises and playbooks that help civil society respond calmly when digital attacks happen.
Pull a book from the shelf to begin
About SIIRF
SIIRF, the Security Incident Identification and Response Framework, helps civil society organisations, independent media and human rights defenders prepare for, identify and respond to digital security incidents.
It brings together a readiness assessment, tabletop exercises, incident playbooks and practical guides, designed for small teams without IT staff. Everything is free to use, and nothing you enter is tracked or stored.
SIIRF is developed and maintained by BOLTECH.
Our Approach
SIIRF follows the six stages of incident response used by security teams worldwide, adapted for small civil society teams: plain language, practical tools, and practice before the bad day.
- 1PreparationPlans, roles, training and tools in place before anything happens.
- 2IdentificationSpot the signs early, and confirm what is happening and how serious it is.
- 3ContainmentStop the damage spreading, and protect people first.
- 4EradicationRemove the cause: malware, the attacker's access, and the weakness they used.
- 5RecoveryRestore systems and data safely, and return to normal work.
- 6Lessons learnedReview what happened, and improve your plan and practices.
Partner with us
Fund free support for grassroots organisations, or bring SIIRF exercises to your network.