Incident Command Structure
Configure escalation tiers, roles, and contacts for incident response.
Incident Command Structure
Define how your organisation escalates security incidents. The command structure determines who is responsible at each escalation level and when each tier is activated.
Starting with a Preset
CrownSync provides six preset command models based on common UK frameworks. Choose one as a starting point and customise it to match your organisation.
- Simple — single tier for small organisations
- Silver / Gold — standard UK three-tier model
- Full NCSC Model — five-tier enterprise model
- NHS / Healthcare — clinical and operational tiers
- Financial Services — SOC to crisis committee
- MSP / MSSP — client-facing escalation
Customising Your Structure
After loading a preset, customise it from Admin → Command Structure:
- Add, rename, or remove escalation tiers
- Define roles within each tier with named contacts
- Set activation criteria for each tier (e.g. “High severity or above”)
- Assign deputies and out-of-hours contacts
Best practices
How It Appears in Playbooks
Your command structure is automatically referenced in playbook content via placeholders. When playbooks mention escalation, they include your actual tier names and contacts.
NCSC Guidance
The UK National Cyber Security Centre recommends a structured approach to incident command. Their guidance aligns with the Bronze / Silver / Gold framework used across UK emergency response.
Was this page helpful?