Skip to main content

Incident Command Structure

Configure escalation tiers, roles, and contacts for incident response.

Incident Command Structure

Define how your organisation escalates security incidents. The command structure determines who is responsible at each escalation level and when each tier is activated.

Starting with a Preset

CrownSync provides six preset command models based on common UK frameworks. Choose one as a starting point and customise it to match your organisation.

  • Simple — single tier for small organisations
  • Silver / Gold — standard UK three-tier model
  • Full NCSC Model — five-tier enterprise model
  • NHS / Healthcare — clinical and operational tiers
  • Financial Services — SOC to crisis committee
  • MSP / MSSP — client-facing escalation

Customising Your Structure

After loading a preset, customise it from Admin → Command Structure:

  • Add, rename, or remove escalation tiers
  • Define roles within each tier with named contacts
  • Set activation criteria for each tier (e.g. “High severity or above”)
  • Assign deputies and out-of-hours contacts

Best practices

Assign at least one named person to every role. Include deputies for key positions. Review your command structure quarterly and after every major incident. Keep out-of-hours contact details up to date.

How It Appears in Playbooks

Your command structure is automatically referenced in playbook content via placeholders. When playbooks mention escalation, they include your actual tier names and contacts.

NCSC Guidance

The UK National Cyber Security Centre recommends a structured approach to incident command. Their guidance aligns with the Bronze / Silver / Gold framework used across UK emergency response.

Was this page helpful?