Incident Response

Incident response policies and playbooks, built for your environment.

When an incident hits, nobody has time to figure out who does what. SubRosa develops the incident response policies and playbooks that turn a chaotic event into a set of clear, rehearsed steps your team can follow under pressure.

IR policy · Playbooks · Comms templates · Escalation

Policies and playbooks, defined

What are incident response playbooks?

An incident response policy sets the framework: who is responsible, when the plan activates, and what your obligations are. Incident response playbooks are the step-by-step procedures for specific incident types, ransomware, business email compromise, data breach, so responders know exactly what to do at each stage. Together they turn your response from improvisation into a repeatable, defensible process that also satisfies auditors and regulators.

What we develop

From policy to step-by-step playbook.

We build the full set of documents your team needs to respond consistently.

IR policy development

A clear incident response policy defining roles, activation criteria, authority, and regulatory obligations.

Detailed playbooks

Step-by-step playbooks for your most likely incident types, mapped to your tools, teams, and environment.

Communication templates

Pre-written internal and external communications so the right message goes out fast, even under pressure.

Escalation procedures

Defined escalation paths and decision criteria, so it is never unclear who to call or when to invoke the plan.

How the engagement runs

Documents people can actually use at 3am.

Most incident documentation fails because it was written for an auditor rather than for someone under pressure. We write for the second reader.

  1. 01

    Scenario selection

    We agree which scenarios warrant a playbook based on what is realistically likely for your sector and estate, rather than producing a folder covering every threat equally.

  2. 02

    Environment mapping

    A playbook that says 'isolate the affected host' is useless without knowing how isolation is performed in your environment, by whom, and with which tool. We map that first.

  3. 03

    Playbook drafting

    Each playbook gives concrete first steps, decision points, and who makes each call. Written to be followed by someone stressed at an unreasonable hour, not to be admired in a review.

  4. 04

    Communication templates

    Pre-drafted holding statements for customers, staff and regulators. Nobody writes well during an incident, and the delay while legal and comms draft from scratch is where reputational damage compounds.

  5. 05

    Escalation and authority

    Explicit authority: who can approve downtime, engage external counsel, notify a regulator, or decide on a ransom position — with named deputies for when the primary is unreachable.

  6. 06

    Validation and handover

    We walk the team through the documents and, where useful, test them in a tabletop. A playbook nobody has read is a document, not a capability.

Why SubRosa

Written by former incident responders.

From real incidents

Our playbooks come from people who have run real breaches, so they hold up when it counts, not just on paper.

Tailored, not templated

Everything is built around your environment, tooling, and team, not a generic document you have to adapt yourself.

Audit-ready

Policies and playbooks are mapped to the frameworks and regulations you answer to, so they satisfy auditors too.

Every playbook, one click away.

Playbooks where your team can reach them.

Your policies and playbooks live in Sable, versioned, assigned, and linked to live incidents, so when something happens your team follows the current procedure from inside the platform, not a document buried on a share drive.

Playbooks in Sable
PlaybooksIR policy v3
  • Ransomware
    12 steps
    Current
  • Business email compromise
    9 steps
    Current
  • Data breach
    14 steps
    In review
  • Insider threat
    8 steps
    Draft
Policy · playbooks · commsVersioned · audit-ready

Common questions

What are incident response playbooks?
Incident response playbooks are step-by-step procedures for specific incident types, such as ransomware, business email compromise, or data breach, so responders know exactly what to do at each stage. An incident response policy sets the surrounding framework: roles, activation criteria, authority, and obligations. Together they turn response from improvisation into a repeatable, defensible process.
What is the difference between an incident response policy and a playbook?
An incident response policy is the high-level document that defines who is responsible, when the plan activates, and your regulatory obligations. A playbook is the detailed, step-by-step procedure for handling a specific incident type. SubRosa develops both, plus communication templates and escalation procedures, mapped to your environment and frameworks.
What is the difference between an IR policy, a plan and a playbook?
The policy states that the organisation will respond to incidents and who is accountable — it is the governance artefact an auditor asks for. The plan describes the overall process. Playbooks are the specific, step-by-step procedures for particular scenarios. Frameworks generally require the policy; what actually helps during an incident is the playbooks.
Which scenarios should we have playbooks for?
The ones realistically likely for your sector and estate, rather than a folder covering every threat equally. For most organisations that means ransomware, business email compromise, a compromised supplier and data exposure. Four good playbooks beat twenty generic ones.
Why do communication templates matter?
Because nobody writes well during an incident, and the hours lost while legal and communications draft a customer statement from scratch are hours in which speculation fills the gap. Pre-drafted holding statements for customers, staff and regulators are among the highest-value items in the whole package.
How often should playbooks be updated?
At least annually, and whenever your environment, tooling or key personnel change. A playbook naming a tool you no longer run, or a person who left, is worse than none — it costs time at exactly the wrong moment.

Turn chaos into procedure.

Let's develop the incident response policies and playbooks that let your team respond fast, consistently, and defensibly.