Incident Response Playbook Catalogue
40+ UK-specific playbooks covering 6 threat categories. Each playbook includes customised actions, regulatory reporting sections, communication templates, and drill capability — personalised to your organisation's sector, technology stack, and regulatory profile.
Playbooks
Showing 42 of 42 playbooks
Business Email Compromise (BEC)
An attacker gains access to or spoofs a legitimate business email account to deceive internal staff, customers or partners into making unauthorised wire transfers, sharing credentials or altering financial records.
Adversary-in-the-Middle (AiTM) and MFA Bypass
Respond to adversary-in-the-middle attacks that intercept authentication tokens and bypass multi-factor authentication. Covers phishing-resistant MFA deployment, session anomaly detection and conditional access remediation.
General Phishing Attack Response
Respond to widespread phishing campaigns targeting your organisation. Covers credential harvesting, malware delivery, email gateway triage and user awareness actions.
Credential Stuffing Attack
An attacker uses automated tools and botnets to test large volumes of stolen credentials against a login portal in hopes of reusing valid username-password combinations, leading to unauthorised account access.
Cloud Account Compromise
An attacker gains unauthorised access to a user's cloud account through phishing, password spraying, token theft or OAuth abuse. The attacker may access email, storage, admin functions or cloud infrastructure.
Abuse of Stolen Session Tokens in SaaS Platforms
An attacker gains access to a valid session token and uses it to impersonate a legitimate user on a SaaS platform, allowing access without triggering MFA or login anomaly alerts.
Unauthorised Privilege Escalation
An attacker escalates privileges from a low-privilege user to an administrative or root-level account through a vulnerability, misconfiguration or stolen credentials, potentially compromising critical systems.
Abuse of OAuth Integrations
An attacker gains access to a user's cloud or application account by tricking them into authorising a malicious OAuth app, giving persistent access without requiring login credentials and bypassing MFA.
RDP Brute-Force Attack
An attacker launches a brute-force or password spraying attack against internet-exposed or internal RDP services to gain access using weak or reused credentials, potentially leading to lateral movement or malware deployment.
Insider Credential Theft and Misuse
An insider or external actor using stolen insider credentials accesses sensitive systems, extracts data or performs unauthorised activities, often bypassing traditional security detection.
Ransomware Infection
An endpoint or server exhibits signs of ransomware activity such as file encryption, ransom notes or alerts from EDR/XDR tools. Covers NCSC guidance, ICO notification and law enforcement engagement.
Cloud-Native Ransomware in Object Storage
An attacker gains access to cloud object storage and performs malicious actions such as encrypting files, altering permissions or deleting backups, purely using APIs or SDKs without deploying ransomware binaries.
Cryptojacking / Unauthorised Cryptocurrency Mining
Respond to unauthorised cryptocurrency mining on endpoints, servers or cloud instances. Covers CPU/GPU anomaly detection, mining pool blocking, container image hardening and cloud billing anomaly investigation.
Malware via USB Device
Malicious software is introduced into the environment through an infected USB storage device. Covers autorun malware, ransomware, keyloggers and tools used to establish persistence or exfiltrate data.
Mobile Device Compromise
Handle compromise of corporate and BYOD mobile devices. Covers MDM-based containment, app removal, factory reset procedures and data protection considerations.
Advanced Persistent Threat (APT) Detection and Response
Detect and respond to advanced persistent threats involving sophisticated, long-term intrusions. Covers threat hunting, forensic analysis, NCSC engagement and coordinated eradication across the environment.
DDoS Attack
Respond to volumetric, protocol and application-layer DDoS attacks targeting public-facing infrastructure. Covers ISP engagement, CDN configuration, traffic scrubbing and business continuity activation.
Watering Hole Attack
Respond to a watering hole attack where an attacker compromises a website frequently visited by target users to deliver malware or harvest credentials. Covers browser forensics and network indicator analysis.
Cloud Storage Misconfiguration Exposure
Sensitive or confidential data is exposed to the public due to misconfigured permissions on cloud storage services, often discovered via threat intelligence feeds, automated scanners or internal audits.
Lateral Movement Across Cloud Workloads
An attacker gains a foothold in one cloud workload and moves laterally by leveraging over-permissive roles, unsecured credentials, shared storage or misconfigured network rules to reach other workloads or services.
Cloud Identity Misconfiguration
A misconfigured cloud identity or access control is exploited by an internal or external actor to gain elevated access, move laterally or access restricted resources. Covers IAM policy remediation and CSPM tooling.
Unauthorised Cloud Database Snapshot Exports
A cloud database snapshot is created or shared without approval, potentially leading to sensitive data exfiltration if the snapshot is exposed to unauthorised users or shared publicly.
Web Application Exploitation
An attacker exploits a vulnerability in a web application or server to gain unauthorised access, execute commands or extract sensitive data. Covers WAF tuning, forensic analysis and secure code review.
Unauthorised JavaScript Injection on Public Websites
An attacker injects malicious JavaScript code into a public-facing website via compromised CMS, third-party scripts or misconfigured CDN. Covers credential harvesting, skimming and session hijacking response.
Insecure API Endpoint Exploitation
An attacker discovers and exploits insecure API endpoints lacking authentication, rate limiting or proper input validation to perform unauthorised data access, modify business logic or escalate privileges.
Data Breach Notification and Regulatory Response
Full UK GDPR personal data breach response. Covers 72-hour ICO notification, data subject communication, risk assessment, multi-jurisdictional notification requirements and regulatory liaison.
Insider Data Exfiltration
An internal employee, contractor or privileged user attempts to or successfully exfiltrates sensitive data through unauthorised channels such as personal email, cloud storage, removable media or file transfer tools.
Malicious Insider Staging Data in the Cloud
A trusted user abuses their access to sensitive data and begins uploading it to unapproved cloud platforms for exfiltration. This may precede resignation, whistleblowing or corporate espionage.
Data Exfiltration via DNS Tunnelling
An attacker uses DNS as a communication channel to exfiltrate data or maintain command and control. DNS tunnelling disguises malicious payloads or stolen data inside DNS queries, bypassing traditional detection.
Unauthorised Internal Database Access
An insider or compromised system accesses database resources in an unauthorised manner, such as bypassing access controls, querying sensitive tables or using privileged database accounts inappropriately.
Unauthorised Use of Generative AI Tools in Production
An employee or system uses a generative AI tool in a production environment without formal approval or proper security evaluation, risking sensitive data exposure through AI prompts or integrations.
Insider Sabotage and Destructive Actions
Respond to deliberate sabotage or destructive actions by an insider, including mass file deletion, service disruption, configuration wipes and permission changes. Covers HR coordination and evidence handling.
Supply Chain Attack
An organisation is compromised through a trusted third-party service, software update, library, plugin or IT service provider. The attacker uses the trusted relationship to move laterally, deploy malware or exfiltrate data.
Zero-Day Exploitation in Third-Party Libraries
A critical vulnerability is disclosed or actively exploited in a third-party library or framework used within your environment. Covers asset inventory, patching prioritisation and compensating controls.
CI/CD Pipeline Exploitation
An attacker gains access to or exploits weaknesses in a CI/CD pipeline to manipulate build processes, inject malicious code or secrets or use the pipeline to pivot into broader infrastructure.
Unauthorised Access to CI/CD Secrets
Secrets stored in CI/CD tools are accessed by an unauthorised party through misconfiguration, leaked logs, compromised runners or malicious pull requests. Covers credential rotation and vault migration.
API Key Leakage via Public GitHub Repositories
A developer accidentally commits and pushes API keys, cloud credentials or other secrets to a public GitHub repository. These secrets can be harvested by attackers and used to access critical systems.
Container Breakout Attempt
An attacker gains access to a container and attempts to escape the isolated environment to interact with the host operating system, escalate privileges or compromise other containers or underlying infrastructure.
Unauthorised Access to Development Environments
An individual gains access to a development environment without authorisation, potentially resulting in code theft, insertion of malicious code or exposure of credentials and secrets.
Shadow IT SaaS Usage & Data Exposure
An employee or team uses an unapproved SaaS application for work-related purposes, transferring corporate data without security oversight. This can result in unauthorised data exposure or regulatory breaches.
Shadow IT Asset Discovery
A previously unknown or unauthorised IT asset is discovered operating within or connected to the corporate environment, potentially bypassing security controls and increasing risk exposure.
Unauthorised SaaS OAuth Application Integration
An employee or attacker grants a third-party application access to a corporate SaaS account using OAuth scopes. These applications may exfiltrate data, impersonate users or maintain persistent access.