Building an incident response playbook for small teams

The middle of an incident is the worst time to figure out who calls the lawyer. Write the playbook now, while you are calm.
Roles and contacts
Incident commander, communications lead, technical lead. Names, phone numbers, backups.
First-hour checklist
Contain, preserve evidence, notify legal, decide on customer communication. Decisions made in panic are decisions made badly.
Tabletop quarterly
Run a simulated incident every quarter. The first real one will not be the first one your team handles.



