The seven mandatory sections
- Purpose and scope — what the plan covers, what it does not.
- Severity rubric — objective triggers, not vibes.
- CIRT roles and deputies — every named role has a named backup.
- Activation runbook — who calls it, how, and what happens in the first 60 minutes.
- Regulator notification matrix — NDB (OAIC), APRA CPS 234, SOCI Act, ASIC, state regulators.
- Communications plan — internal, customer, media, board, holding statements.
- Post-incident review — blameless review and improvement actions logged.
Severity rubric
Severity levels
- SEV-1 Critical. Material business impact, regulator clock running, board notified within 4 hours.
- SEV-2 High. Significant service or data impact, exec leadership engaged, regulator likely within 24 hours.
- SEV-3 Moderate. Contained operational impact, IT leadership engaged, regulator unlikely.
- SEV-4 Low. Single-user or contained, handled by service desk under standard playbook.
Australian regulator clocks
- OAIC (NDB) — assess within 30 days; notify as soon as practicable once an eligible breach is confirmed.
- APRA CPS 234 — notify within 72 hours of becoming aware of a material information security incident.
- SOCI Act — 12 hours for critical impact, 72 hours for other impact, to ASD.
- ASIC continuous disclosure — for listed entities where the incident is materially price-sensitive.
Treat these as parallel, not sequential. A single major incident commonly triggers three or four obligations on different clocks.
FOR CIRT LEADS
Generate a one-page incident response runbook tonight.
FORTE/CYBERx produces a CIRT-ready runbook — first 60 minutes, RACI, regulator notification drafts and comms templates — anchored to NDB, CPS 234 and SOCI obligations.
Start a free missionThe first 60 minutes
Most plans fall apart in the first hour because no-one knows the activation phone tree or who has the authority to invoke the CIRT. The fix is boring: a single laminated wallet card with three numbers, the activation script and the first three decisions the duty exec needs to take. Test it quarterly.
What good post-incident review looks like
- Timeline reconstructed from logs, not memory
- Decision points labelled with who decided, what they considered, what they chose
- Five whys for at least one root cause
- Improvement actions with owners and due dates, tracked to closure
- Report to the board within 30 days for SEV-1, 90 days for SEV-2
FAQ
What must an Australian incident response plan contain?
At minimum: a severity rubric, CIRT roles with deputies, an activation runbook, a regulator-notification matrix covering NDB / CPS 234 / SOCI, a comms plan and a post-incident review process. The plan must be tested at least annually — most Australian regulators now expect this in writing.
How often should we test the plan?
At least once a year for a full tabletop, with quarterly functional drills for high-risk scenarios (ransomware, supplier compromise, insider). APRA-regulated entities should treat semi-annual as the floor.
Who chairs the CIRT?
A named executive (usually the CISO or CIO) with a documented deputy. The legal owner of regulator notification is typically the General Counsel or Privacy Officer; the CIRT chair owns operational tempo.
Should the plan be public?
No. The plan often contains sensitive contact trees, escalation thresholds and vendor contracts. Maintain a sanitised summary for customers and insurers and the full plan on access-controlled storage.