← Back to the library

From the SIIRF library

Incident Playbooks

Step-by-step response guides for the incidents organisations face most often. Each playbook covers indicators, triage questions, a severity guide, response steps, communication, evidence to preserve, recovery and prevention. Open one when you need it, or use them as the basis for your own plan.

Phishing & Scams

A staff member received, clicked or acted on a deceptive message designed to steal credentials, money or access.

Accounts and accessMedium to high

Account Takeover

An unauthorised person has accessed or taken control of an email, messaging, social media or cloud account.

Accounts and accessHigh

Lost & Seized Devices

A phone, laptop or storage device has been lost, stolen, or taken by authorities or others.

Devices and malwareHigh

Ransomware & Malware

Malicious software has infected organisational devices, encrypting files, stealing data or disrupting work.

Devices and malwareCritical

Harassment & Doxxing

A staff member, or the organisation, is the target of coordinated online abuse, threats or the publication of private information.

People and safetyHigh to critical

Spyware & Surveillance

There are signs that a phone or computer is being secretly monitored by spyware or stalkerware.

Devices and malwareCritical

Internet Shutdowns

Internet access or specific platforms are deliberately blocked or slowed, cutting staff and communities off.

Infrastructure and connectivityHigh

Data Breaches

Personal or sensitive data has been exposed, shared, accessed or taken without authorisation.

DataHigh to critical

Website Attacks

The organisation's website is unavailable, has been altered, or is being used to spread malware or scams.

Infrastructure and connectivityMedium to high

Disinformation & Fakes

False information, fake accounts or manipulated media are being spread to discredit the organisation or its people.

People and safetyMedium to high