From the SIIRF library
Incident Playbooks
Step-by-step response guides for the incidents organisations face most often. Each playbook covers indicators, triage questions, a severity guide, response steps, communication, evidence to preserve, recovery and prevention. Open one when you need it, or use them as the basis for your own plan.
Phishing & Scams
A staff member received, clicked or acted on a deceptive message designed to steal credentials, money or access.
Account Takeover
An unauthorised person has accessed or taken control of an email, messaging, social media or cloud account.
Lost & Seized Devices
A phone, laptop or storage device has been lost, stolen, or taken by authorities or others.
Ransomware & Malware
Malicious software has infected organisational devices, encrypting files, stealing data or disrupting work.
Harassment & Doxxing
A staff member, or the organisation, is the target of coordinated online abuse, threats or the publication of private information.
Spyware & Surveillance
There are signs that a phone or computer is being secretly monitored by spyware or stalkerware.
Internet Shutdowns
Internet access or specific platforms are deliberately blocked or slowed, cutting staff and communities off.
Data Breaches
Personal or sensitive data has been exposed, shared, accessed or taken without authorisation.
Website Attacks
The organisation's website is unavailable, has been altered, or is being used to spread malware or scams.
Disinformation & Fakes
False information, fake accounts or manipulated media are being spread to discredit the organisation or its people.