Incident response policies and playbooks, built for your environment.
When an incident hits, nobody has time to figure out who does what. SubRosa develops the incident response policies and playbooks that turn a chaotic event into a set of clear, rehearsed steps your team can follow under pressure.
IR policy · Playbooks · Comms templates · Escalation
What are incident response playbooks?
An incident response policy sets the framework: who is responsible, when the plan activates, and what your obligations are. Incident response playbooks are the step-by-step procedures for specific incident types, ransomware, business email compromise, data breach, so responders know exactly what to do at each stage. Together they turn your response from improvisation into a repeatable, defensible process that also satisfies auditors and regulators.
From policy to step-by-step playbook.
We build the full set of documents your team needs to respond consistently.
IR policy development
A clear incident response policy defining roles, activation criteria, authority, and regulatory obligations.
Detailed playbooks
Step-by-step playbooks for your most likely incident types, mapped to your tools, teams, and environment.
Communication templates
Pre-written internal and external communications so the right message goes out fast, even under pressure.
Escalation procedures
Defined escalation paths and decision criteria, so it is never unclear who to call or when to invoke the plan.
Documents people can actually use at 3am.
Most incident documentation fails because it was written for an auditor rather than for someone under pressure. We write for the second reader.
- 01
Scenario selection
We agree which scenarios warrant a playbook based on what is realistically likely for your sector and estate, rather than producing a folder covering every threat equally.
- 02
Environment mapping
A playbook that says 'isolate the affected host' is useless without knowing how isolation is performed in your environment, by whom, and with which tool. We map that first.
- 03
Playbook drafting
Each playbook gives concrete first steps, decision points, and who makes each call. Written to be followed by someone stressed at an unreasonable hour, not to be admired in a review.
- 04
Communication templates
Pre-drafted holding statements for customers, staff and regulators. Nobody writes well during an incident, and the delay while legal and comms draft from scratch is where reputational damage compounds.
- 05
Escalation and authority
Explicit authority: who can approve downtime, engage external counsel, notify a regulator, or decide on a ransom position — with named deputies for when the primary is unreachable.
- 06
Validation and handover
We walk the team through the documents and, where useful, test them in a tabletop. A playbook nobody has read is a document, not a capability.
Written by former incident responders.
From real incidents
Our playbooks come from people who have run real breaches, so they hold up when it counts, not just on paper.
Tailored, not templated
Everything is built around your environment, tooling, and team, not a generic document you have to adapt yourself.
Audit-ready
Policies and playbooks are mapped to the frameworks and regulations you answer to, so they satisfy auditors too.
Playbooks where your team can reach them.
Your policies and playbooks live in Sable, versioned, assigned, and linked to live incidents, so when something happens your team follows the current procedure from inside the platform, not a document buried on a share drive.
- CurrentRansomware12 steps
- CurrentBusiness email compromise9 steps
- In reviewData breach14 steps
- DraftInsider threat8 steps
Common questions
- What are incident response playbooks?
- Incident response playbooks are step-by-step procedures for specific incident types, such as ransomware, business email compromise, or data breach, so responders know exactly what to do at each stage. An incident response policy sets the surrounding framework: roles, activation criteria, authority, and obligations. Together they turn response from improvisation into a repeatable, defensible process.
- What is the difference between an incident response policy and a playbook?
- An incident response policy is the high-level document that defines who is responsible, when the plan activates, and your regulatory obligations. A playbook is the detailed, step-by-step procedure for handling a specific incident type. SubRosa develops both, plus communication templates and escalation procedures, mapped to your environment and frameworks.
- What is the difference between an IR policy, a plan and a playbook?
- The policy states that the organisation will respond to incidents and who is accountable — it is the governance artefact an auditor asks for. The plan describes the overall process. Playbooks are the specific, step-by-step procedures for particular scenarios. Frameworks generally require the policy; what actually helps during an incident is the playbooks.
- Which scenarios should we have playbooks for?
- The ones realistically likely for your sector and estate, rather than a folder covering every threat equally. For most organisations that means ransomware, business email compromise, a compromised supplier and data exposure. Four good playbooks beat twenty generic ones.
- Why do communication templates matter?
- Because nobody writes well during an incident, and the hours lost while legal and communications draft a customer statement from scratch are hours in which speculation fills the gap. Pre-drafted holding statements for customers, staff and regulators are among the highest-value items in the whole package.
- How often should playbooks be updated?
- At least annually, and whenever your environment, tooling or key personnel change. A playbook naming a tool you no longer run, or a person who left, is worse than none — it costs time at exactly the wrong moment.
Turn chaos into procedure.
Let's develop the incident response policies and playbooks that let your team respond fast, consistently, and defensibly.