The Cyber Incident Response (IR) Playbook: In-House Preparation Within the NIST SP 800-61 Framework
The 6 phases of NIST SP 800-61 (Preparation/Identification/Containment/Eradication/Recovery/Lessons Learned). USOM 3 hours, KVKK 72 hours. CSIRT/SIRT/SOC structure, RACI matrix, a 10-item preparation checklist, mini-playbooks for 6 incident types (ransomware, phishing, DDoS, insider, leak, supply chain). Tabletop exercise.
The Cyber Incident Response (IR) Playbook: In-House Preparation Within the NIST SP 800-61 Framework
TL;DR: Cyber incidents are no longer a question of "will it happen" but of "when will it happen". NIST SP 800-61 Rev 2 offers a proven six-phase response framework: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. In Turkey there are USOM 3-hour and KVKK 72-hour notification obligations. This guide includes the CSIRT structure, the RACI communication matrix, a 10-item preparation checklist, and a mini-playbook for 6 different incident types. At the end you will find the DSET IR retainer package.
Why is an IR Playbook a Must?
The 2021 Colonial Pipeline attack paralyzed the fuel supply on the U.S. East Coast for days. The 2023 MOVEit Transfer vulnerability leaked the data of thousands of companies. The 2021 HSE Ireland ransomware attack halted the Irish healthcare system for weeks. These three cases all point to a single truth: organizations without pre-incident preparation try to improvise their management during an attack, and most of the time they lose.
Turkey's cyber threat landscape is rapidly worsening. Ransomware now exfiltrates data before encrypting, the difference between EDR and XDR matters but is not sufficient on its own. Coordinated response capability is required just as much as detection capability.
NIST SP 800-61 Rev 2 is the most widely accepted IR framework in the world. In this article we will produce an applicable playbook that combines the framework with Turkish legislation (KVKK + USOM).
Authoritative sources: NIST SP 800-61 Rev 2, NIST CSF, SANS Incident Response, CISA, USOM, KVKK, MITRE ATT&CK.
The Six Phases of NIST SP 800-61
Phase 1: Preparation
Response begins not after the incident but months earlier. The preparation phase is the foundation of the entire IR program. Policy documents, the asset inventory, the log collection infrastructure, contact lists, legal advisor contracts and backup procedures are all established in this phase.
The most critical element here is to make decisions today, with a calm mind, rather than at the moment of the incident. For example, the answer to the question "will the ransom be paid" should be discussed in a tabletop exercise, not while the systems are encrypted.
Phase 2: Detection and Analysis
Realizing that an incident has occurred is often harder than the attack itself. SIEM alerts, EDR alarms, user reports and external tip-offs (USOM, a customer, a researcher) can all be the trigger.
In this phase two fundamental questions are answered: (1) Is this really a security incident or a false positive? (2) How far has it spread? The MITRE ATT&CK framework provides guidance in kill chain analysis.
Phase 3: Containment
Before you put out the fire, you need to stop it from spreading. NIST proposes two strategies: short-term (isolating the affected machine from the network) and long-term (preserving business continuity with temporary solutions while preparing for a permanent fix).
Containment decisions are not always easy. Shutting down the affected server can destroy evidence, while leaving it on allows the spread to continue. This balance must have been discussed in advance.
Phase 4: Eradication
The attacker's presence is completely removed from the system. Backdoors, persistence mechanisms, compromised accounts and malicious scheduled tasks are cleaned out. Even a single remnant is enough for the attacker to return.
Phase 5: Recovery
After the systems have been made clean, they are brought back into production. In this phase the monitoring level is raised and signs of reinfection are watched closely. Recovery must be slow and controlled; the pressure to "get back to normal as soon as possible" usually opens the door to a repeat attack.
Phase 6: Post-Incident Activity
A "lessons learned" meeting is held within 72 hours. What did we do well, what did we notice too late, which control did not work: these questions are examined. The findings are reflected back into the playbook. If this phase is skipped, the same incident happens again.
Playbook Format: Per Threat Category
A good IR playbook is not a single enormous document. There should be separate, short, action-oriented mini-playbooks for each incident type. Each playbook contains the following headings:
- Incident definition and trigger signals
- Initial response team (who is called, who decides)
- First 60 minutes of actions (containment)
- First 4 hours of actions (analysis + start of eradication)
- First 24 hours of actions (recovery + external notifications)
- Evidence collection list
- Legal notification thresholds (USOM, KVKK)
- Closure criteria
Team Structure
| Role | Responsibility |
|---|---|
| CSIRT (Computer Security Incident Response Team) | Owner of the entire IR program, high-level coordination |
| SIRT (Security Incident Response Team) | Operational response, technical eradication |
| SOC (Security Operations Center) | 24/7 monitoring, initial detection, triage |
| Legal | KVKK notification, contractual obligations, chain of custody |
| PR / Corporate Communications | Media, customer and employee communication |
| Senior Management | Strategic decisions (ransom, shutdown, public disclosure) |
| HR | Personnel process in insider incidents |
| External IR firm | Steps in via retainer if there is an expertise gap |
Communication Matrix (RACI)
| Action | SOC | SIRT | CSIRT Lead | Legal | PR | CEO |
|---|---|---|---|---|---|---|
| Initial triage | R | C | I | I | I | I |
| Containment decision | C | R | A | I | I | I |
| KVKK notification | I | C | C | R | I | A |
| USOM notification | C | C | R | C | I | A |
| Media statement | I | I | C | C | R | A |
| Ransom decision | I | C | C | C | C | A/R |
R: Responsible, A: Accountable, C: Consulted, I: Informed.
10-Item Pre-Response Preparation Checklist
- Asset inventory: Are the critical systems, their owners and business-impact levels documented?
- Log infrastructure: Are endpoint, network and identity logs kept centrally for at least 90 days?
- EDR/MDR: Is behavior-based detection active on all endpoints?
- Backup: The 3-2-1 rule, immutable backups, restore tests at least twice a year?
- Contact list: People to reach outside business hours, their alternates, alternative channels (Signal/phone)?
- Legal advisor: Is there a contract with a lawyer who is an expert in cyber incidents, ready to go?
- External IR retainer: Is there a contracted IR firm in place before an incident?
- Tabletop exercises: A scenario-based drill at least once a year?
- Forensic kit: Are disk imaging tools, a write blocker and an evidence bag ready?
- Decision matrices: Are the thresholds for paying a ransom, halting production and public disclosure written down?
Incident Types and Mini-Playbooks
Ransomware
Signals: Mass file extension changes, deletion of shadow copies, suspicious encryption behavior in EDR, ransom notes.
First 60 minutes: Isolate the affected segment at the VLAN level. Revoke the tokens of the accounts on AD that are assumed to be compromised. Verify read-only access to the backup systems.
First 4 hours: Find patient zero (usually not the first encrypted machine, but the first one on which persistence was established). Map the lateral movement paths. Check the traffic logs for whether data was exfiltrated (double extortion).
First 24 hours: USOM notification (it should have been made within 3 hours). If there is a personal data leak, the KVKK 72-hour counter has started. The restore strategy must be clarified.
For a detailed strategy, see our first 24 hours after ransomware guide.
Phishing
Signals: User report, mail gateway warning, anomalous OAuth approval, an unexpected MFA denial.
First 60 minutes: Recall the email from all inboxes, block the sender domain, scan the machines of those who clicked in EDR, terminate the sessions of the affected accounts.
First 4 hours: Determine which credentials were entered, investigate any MFA bypass attempt, check whether there are new inbox rules (auto-forward) in the mailbox.
For detailed indicators, see our how to recognize a phishing email article.
DDoS
Signals: Slowdown in services, an abnormal number of connections, an alarm from the CDN/WAF.
First 60 minutes: Contact the upstream provider + CDN, enable rate limiting, apply geographic blocking if necessary.
First 4 hours: Determine the type of attack (L3/L4 volumetric, L7 application). DDoS is sometimes a distraction for a larger attack, so scan the other logs at the same time.
Insider Threat
Signals: Abnormal data downloads, access outside business hours, the activity of a departing employee, USB copying.
First 60 minutes: Act together with HR and Legal. The chain of evidence is critical. Restrict access quietly (an immediate cut-off can lead to loss of evidence).
First 4 hours: Take a forensic image, place the behavior on a timeline, quantify the unauthorized data exfiltration.
Data Leak
Signals: A data listing on the dark web/Telegram, a customer report, a researcher tip-off.
First 60 minutes: Verify the reality of the leak (compare sample rows against your own DB). Begin to determine which system it came from.
First 4 hours: The counter for the KVKK notification has started, so the number of affected individuals and the data categories must be clarified. For the detailed process, see the KVKK data breach notification article.
Supply Chain
Signals: A supplier announcement, a 0-day in a piece of software you use, abnormal behavior after a SolarWinds-type package update.
First 60 minutes: List all systems on which the affected software is installed, and disable it if necessary.
First 4 hours: Examine the supplier's advisory in detail, scan for the IOCs in your own environment, perform MITRE ATT&CK mapping.
Forensic Evidence Preservation
The digital forensics process should be carried out within the framework of the ISO 27037 standard. The basic principles:
- Do not alter the original. All analysis is performed on a forensic image, and a write blocker is used.
- Chain of custody. Who touched what, and when, is recorded.
- Hash verification. Image integrity is verified at every stage with SHA-256.
- Priority of volatile data. RAM, open connections and running processes are captured before anything is shut down.
- Timestamps. All actions are logged in UTC, and system clocks must be synchronized with NTP.
For evidence that can be used in court, this process is not negotiable. Skipping a single step can invalidate the entire case.
USOM 3 Hours and KVKK 72 Hours
In Turkey there are two critical notification thresholds:
USOM (the Turkish national cyber incident response center): In critical infrastructure and regulated sectors, cyber incidents must be reported within 3 hours. The notification format is via the USOM portal.
KVKK 72 hours: When it is determined that personal data has been leaked or subjected to unauthorized access, notification to the Authority is mandatory within a reasonable period (72 hours, per a KVKK decision). For details, you can refer to our KVKK data breach notification article.
These periods begin "after you understand the incident", but it is hard to prove that detection was delayed. In practice, the counter should be assumed to run from the first abnormal signal.
Annual Tabletop Exercise
A playbook may look perfect on paper, but it may not work in a real incident. A scenario-based tabletop exercise should be carried out at least once a year. A sample scenario: "At 17:45 on Friday, the SOC detected ransomware on the main ERP server. The backup has not been taken for the last 18 hours. The end-of-period closing is on Monday."
During the exercise each role makes its own decision, and the decisions are logged. At the end, the actual decisions are compared with the expected decisions and the playbook is updated.
Post-Incident Review
After every incident, a blameless post-mortem is conducted within 72 hours. Three questions:
- What worked, what should we keep?
- What did we notice too late, what did we miss?
- What will we do next time (a concrete action + owner + date)?
The output is reflected back into the playbook. A lesson that is not reflected back is not a lesson learned.
Frequently Asked Questions (FAQ)
1. Do small companies also need an IR playbook? Yes. Attackers do not distinguish between large and small; small companies are usually targeted as a supply-chain doorway.
2. How often should the playbook be updated? At least once a year, and also after every real incident or tabletop exercise.
3. Should the ransom be paid? As a matter of policy it is not recommended. The decision belongs to senior management, and even paying carries no guarantee. You should make the decision today.
4. External IR firm or internal team? The ideal combination: an internal SIRT + an external retainer. The external firm brings expertise and capacity, while the internal team brings context and speed.
5. Can IR be done without a SIEM? Very difficult. At the very least there should be central log collection and endpoint EDR. You cannot stop what you cannot see.
6. Is a KVKK notification made for every data breach? It depends on the risk assessment. The decision is made together with a legal advisor, but when in doubt the tendency to notify should be preferred.
7. Does cyber insurance replace IR? No. Insurance partially compensates the financial loss; it does not perform the response. Most policies even restrict the choice of IR firm to their own panel.
8. Who should be at the tabletop exercise? Not only the technical team; Legal, PR, senior management, and if necessary HR and Finance. The decision-maker must be at the table.
DSET IR Retainer Package
The panic of "how do I find an IR firm now" at the moment of an incident means lost initial hours. The DSET IR retainer package includes the following:
- 24/7 hotline + remote response starting within 1 hour
- Annual tabletop exercise + playbook preparation
- A guarantee of priority engagement at the moment of an incident
- Forensic imaging + chain of custody management
- USOM and KVKK notification support
- Post-incident review + lessons report
Contact: Hacettepe Teknokent, Beytepe, Ankara · +90 536 662 38 09
To be caught prepared at the next incident, call today.
Sources: NIST SP 800-61 Rev 2, NIST CSF, SANS Incident Response, CISA, USOM, KVKK, MITRE ATT&CK
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.