secureskies
Cyber Security/Respond/Playbook Development

Who decides,
who isolates, who notifies?

A playbook answers that per incident type — as a tested sequence, from the decision through to communication. We write playbooks for your real systems and responsibilities, with the notification deadlines under NIS2, GDPR and DORA built in, and test them in a tabletop exercise before they go into the binder.

FormatWorkshop plus documentplus tabletop test
TypesRansomware · BEC · data exfiltrationinsider · cloud compromise
ReferenceNIS2 Art. 23GDPR Art. 33 · DORA
OutcomePlaybook settested, versioned
01 · Service

What is included.

So that nobody has to improvise in an incident.

Incident taxonomy

Which incident types are relevant to you, and how they are detected and classified.

Playbook per type

Roles, decision points, technical steps, communication, notification duties with deadlines, evidence preservation.

Interfaces

Providers, insurer, law firm, authorities — contacts, contracts, escalation paths.

Test and maintenance

A tabletop run per playbook; a maintenance process with an owner and a review cadence.

02 · Process

Five steps,
one deliverable.

01

Taxonomy

Define incident types and severity levels.

02

Draft

Write the playbook per type with the people involved.

03

Alignment

With IT, legal, communications and management.

04

Test

Tabletop run and adjustment.

05

Handover

Versioned playbooks, maintenance process, training.

03 · Who it fits

When this service
applies.

Companies with an IR plan on paper but no concrete procedures
NIS2 and DORA entities with notification duties
After an incident in which responsibilities were unclear
More services · Respond

Is your IR plan on paper —
or a tested procedure?