NEW · AI-DETECTED TECHNICAL IR RUNBOOK

A technical incident response playbook, when the AI says you need one.

During council processing, the AI evaluates whether your mission involves a live or imminent cyber incident. If it does, you're prompted on Tactical Plan open to accept — and a SOC/IR playbook anchored to NIST 800-61r2 and ACSC guidance is attached as a dedicated tab. Sits alongside the Crisis Response Plan (executive comms) when both apply.

Open the War RoomTalk to usTwo free missions · No credit card
NIST SP 800-61r2 alignedACSC Essential Eight mappedOAIC NDB & APRA CPS 234 notificationsSits alongside Crisis Response Plan

WHAT IT IS

The technical first hour, pre-drafted for your responders.

Cyber incidents often stall on the technical side — unclear scope, unsure containment moves, ad-hoc evidence handling and notification deadlines no one is tracking. The IR Playbook removes that cold start for your SOC and IR responders.

When a mission involves ransomware, account compromise, exfiltration, CVE exploitation, supply-chain compromise or similar technical scenarios, the AI Council flags it during processing. If you accept on Tactical Plan open, the playbook is generated and attached as its own tab. If the AI does not flag the mission, no manual playbook can be added.

Every section is a structured starting point — to be adapted to your environment, runbooks and your DFIR / insurer panel arrangements before execution.

WHAT'S INSIDE

Six sections. One responder runbook.

Every playbook is tailored to the specific scenario described in your mission — severity, suspected vector and assumed affected systems flow into every section.

Scenario snapshot

Severity, suspected vector, assumed affected systems and business impact — so responders triage in seconds.

First 60 minutes

Minute-by-minute actions with owners — SOC, IR lead, platform owner, comms — for the critical first hour.

Containment & eradication

Short and long-term containment, eradication and recovery steps with success criteria.

Evidence & threat hunting

What to preserve, what not to touch, chain of custody, log sources to pull and hunt questions to answer.

Regulator notifications

OAIC NDB, APRA CPS 234, ASD ReportCyber and SOCI obligations with deadlines, channel and what to include.

Essential Eight uplift

Targeted ACSC Essential Eight mitigations relevant to the incident plus a printable responder checklist.

TRY IT NOW

Bring one technical scenario. Get a responder runbook.

Free to use. Run a mission and, when the AI flags it, accept the IR Playbook prompt.

Run your first mission free

WHEN IT TRIGGERS

Suggested when technical response is required. Never added manually.

Auto-detected technical scenarios

Ransomware, account/identity compromise, exfiltration, malware/C2, CVE exploitation, supply-chain compromise, ICS/OT incidents and AI agent compromise. The AI prompts you to accept or decline on Tactical Plan open.

AI-only — no manual override

IR Playbooks cannot be added manually. The AI Council decides eligibility based on mission context, so playbooks stay focused on missions that genuinely warrant a SOC/IR response.

Included in print and email exports

When you print or email a Tactical Plan, the IR Playbook goes with it — so the SOC and IR responders who need it on the day already have it offline.

QUESTIONS

FAQ

What is the Cyber Incident Response Playbook?

A technical responder runbook the AI Council attaches to a Tactical Plan when a mission warrants hands-on incident response. It gives your SOC/IR team a structured playbook: first 60 minutes by minute window and owner, short and long-term containment, eradication, recovery, evidence preservation, threat-hunting questions, regulator notifications and Essential Eight uplift steps.

How is this different from the Crisis Response Plan?

The Crisis Response Plan covers executive comms, RACI, regulator drafts and board-ready statements. The IR Playbook covers the technical response — what the SOC, IR analyst and platform owners actually do on the keyboard. A mission can trigger one, both, or neither depending on context.

Which frameworks does it reference?

NIST SP 800-61r2 (Computer Security Incident Handling Guide), ACSC Cyber Incident Response Plan guidance, ACSC Essential Eight, ASD ReportCyber obligations, OAIC Notifiable Data Breaches scheme, APRA CPS 234 (72-hour material incident notification) and the Security of Critical Infrastructure (SOCI) Act where applicable.

When does the AI add an IR Playbook automatically?

During council processing the AI evaluates whether a mission involves a live or imminent technical incident — ransomware/extortion, account compromise (M365, Entra, Okta, AWS/GCP/Azure), email compromise, exfiltration, malware/C2, CVE exploitation, supply-chain compromise, ICS/OT incidents or AI agent compromise. If flagged, you are prompted on Tactical Plan open to accept or decline.

Can I use it during a real incident?

It is a drafting aid for your IR team. Treat outputs as a structured starting point to be tailored to your environment, runbooks and DFIR/insurer panel arrangements. The playbook accelerates the first hour and gives technical responders a checklist; it does not replace your incident response retainer.

Is it included in every mission?

No. The IR Playbook only appears when the AI Council flags the mission as requiring technical incident response. It cannot be added manually.

Run your first mission free.

Two free missions. No credit card. If the AI flags a technical incident, the IR Playbook prompt appears inside your Tactical Plan.