Skip to content

RESPOND

Objective

Contain, eradicate, and communicate during incidents, including meeting EU statutory reporting deadlines, which are among the strictest in the world.

Core capabilities

StandardOCDFFunction from NIST CSF 2.0; the capability breakdown and IDs are this framework's.

ID Capability Description
RS-1 Incident response plan Approved IR plan: definitions, severity classification, roles, escalation, decision authority including who may disconnect production, out-of-band communications.
RS-2 Playbooks Scenario-specific runbooks for the most likely incident types: phishing/BEC, ransomware, credential compromise, data breach, DDoS and supplier compromise.
RS-3 Incident analysis & forensics Evidence collection and preservation with chain of custody, forensic imaging capability in-house or retained, root-cause analysis per CSF 2.0 RS.AN.
RS-4 Containment & eradication Technical ability to isolate hosts, disable accounts, block indicators, and revoke sessions, all with pre-agreed authority.
RS-5 Incident reporting & communication Internal escalation matrix plus external statutory reporting: national CSIRT or competent authority under NIS2, data protection authority under GDPR, sector regulators under DORA, affected data subjects, law enforcement.
RS-6 Crisis management interface Escalation path from security incident to organisational crisis; link to business continuity structures.
RS-7 Exercises Tabletop and technical exercises at least annually, including management under the NIS2 training obligation, and statutory-reporting drills.

The first hour of a major incident

PractitionerLessons from major incidents; agree them in the charter before you need them.

Playbooks handle the specific scenario. These are the estate-wide moves that apply to almost any major compromise, and the ones most often skipped under pressure. Pre-agree them in charter §4 so they are decisions to execute, not decisions to have.

  • Do not shut systems down. Powering off destroys memory evidence, and on a compromised host nobody knows what is configured to run at boot. Isolate instead: network containment preserves both the machine and the evidence inside it.
  • Cut external connectivity for affected sites. A deny-all rule at the top of the perimeter ruleset, and remote access disabled with it: client VPN, site-to-site tunnels, remote desktop and VDI gateways, vendor and out-of-band management paths. Partial isolation that leaves one tunnel up is not isolation. The Availability impact is severe, which is exactly why the authority has to exist before the night it is needed.
  • Protect the backups before anything else touches them. Confirm recent restore points exist and are readable, then isolate the backup infrastructure. Backup systems are a primary target in ransomware operations, and the credentials to reach them are often already held.
  • Freeze anything that expires. SAN, hypervisor and filesystem snapshots roll off on default retention schedules, frequently within days, taking recovery points and evidence with them. Extend retention or export copies in the first hour, not the first week.
  • If there is no central logging, start collecting now. Firewall, directory, hypervisor, endpoint, mail and remote-access logs, pulled somewhere the adversary cannot reach. A log not collected on day one is not available on day five.
  • Engage counsel, and the insurer if there is a policy — see below, and do it before the technical picture is complete rather than after.

Counsel and insurance

Involve legal counsel when an incident looks material, not when it looks notifiable. Two practical traps, both hard to fix retrospectively:

  • Insurance conditions bind early. Cyber policies commonly require notification within a short window and mandate pre-approved DFIR, negotiation and legal panels. Bringing in your own responder first can reduce or void cover. Establish before the incident whether a policy exists, who notifies the carrier, within what window, and which vendors it permits, then record it in the IR plan alongside the DFIR retainer.
  • Privilege is not uniform across the EU. Some jurisdictions extend legal professional privilege to material prepared for or by external counsel; several member states do not extend it to in-house lawyers at all, and the treatment of technical investigation reports differs again. Do not assume a report is protected because counsel commissioned it. Settle the position per jurisdiction before the first report is written.

Firms specialising in incident response can coordinate carriers, responders and notifications while the CDC keeps working the incident. Identify one alongside the DFIR retainer, not during a P1.

EU statutory reporting timelines — build these into playbooks

LawFrom the legal texts; national transpositions may add detail. Not legal advice.

Regime Trigger Deadline Recipient
NIS2 Art. 23 Significant incident Early warning ≤ 24 h; incident notification ≤ 72 h; final report ≤ 1 month National CSIRT / competent authority
GDPR Art. 33 Personal data breach posing a risk to individuals ≤ 72 h from awareness Data protection authority
GDPR Art. 34 High risk to individuals Without undue delay Affected data subjects
DORA Art. 19 Major ICT-related incident at financial entities Initial ≤ 4 h from classification / ≤ 24 h from awareness; intermediate ≤ 72 h; final ≤ 1 month Competent financial authority

Member-state transpositions of NIS2 may add national specifics, so maintain a country annex for each jurisdiction you operate in. Community contributions of national annexes are welcome; see CONTRIBUTING.

Case closure taxonomy

OCDF

Standardise how every case closes. It is the foundation of honest metrics, tuning feedback and comparable statistics: true positive with impact, where a CIA attribute was breached, making it an incident whose reporting duties must be assessed; true positive without impact, where there was malicious intent but no harm done; indeterminate; or false positive, which feeds the tuning loop in Running the CDC. For incident-type classification, the open VERIS vocabulary of malware, hacking, social, misuse, error, physical and environmental keeps year-over-year and peer statistics comparable.

CIA mapping

OCDFThis framework's mapping of each capability to confidentiality, integrity and availability.

Capability C I A Rationale
RS-2 Playbooks ● ● ● Ransomware playbooks defend A/I; breach playbooks defend C.
RS-3 Forensics ○ ● ○ Evidence integrity through hashing and chain of custody is an Integrity discipline.
RS-4 Containment ● ● ● Containment trades short-term Availability for protection of C and I, so the decision authority for that trade-off must be pre-agreed at GOVERN level.

Roles & staffing

PractitionerStaffing figures are practitioner estimates; the arithmetic is under staffing and cost in Operating models.

  • Incident manager/commander — coordinates; distinct from technical lead in larger incidents.
  • Technical responders — often the same analysts as DETECT.
  • Legal/DPO and communications — mandatory members of the extended IR team.
  • Retainers — consider an external DFIR retainer at Level 2+ if in-house forensics is not viable, and identify external counsel on the same basis.

Maturity criteria

OCDFThis framework's criteria, informed by the NIST CSF tiers. Not a certification standard.

Level Criteria
1 — Initial Ad-hoc response by IT; no approved plan; reporting duties not mapped.
2 — Managed Approved IR plan; playbooks for top 3–5 scenarios; statutory reporting contacts and templates prepared; annual tabletop.
3 — Established Containment actions pre-authorised and technically automatable; forensic capability in-house or retained; exercises include management and reporting drills; post-incident reviews feed improvements.
4 — Optimising Response metrics MTTC and MTTR trended; cross-functional crisis exercises with suppliers; automation of enrichment and containment with human approval gates; lessons systematically drive PROTECT/DETECT changes.

EU regulatory hooks

LawParaphrased from the legal texts. Check the article itself and your national law; not legal advice.

  • NIS2 Art. 21(2)(b) incident handling; Art. 23 reporting; see the table above.
  • GDPR Art. 33/34 — breach notification; document all breaches internally, even those not notified, per Art. 33(5).
  • DORA Art. 17–19 — ICT incident management, classification and reporting for financial entities.
  • ENISA / national CSIRT good practice — align severity taxonomies with your national CSIRT's scheme where one exists to ease reporting.

External dependencies

PractitionerTypical dependencies from experience; yours will differ.

Dependency Party Type Agree up front
Containment beyond pre-mandated scope, the crown jewels Service owner / executive per charter §4 [GATE] Decision criteria plus deputy; drill it, because this gate at 03:00 is the whole point of the charter
Execution of containment and restoration actions IT operations [HARD] 24/7 reachability; actions from the containment catalogue rehearsed
Notification decisions for GDPR, NIS2 and press Legal / DPO / communications [GATE] Draft templates pre-approved; who can be woken
External statements and customer communication Communications [HARD] Holding statements ready; single spokesperson rule
Insider-related cases HR + legal [GATE] Process agreed before the first case, incl. evidence handling
Forensics beyond in-house capability External DFIR retainer [HARD] Retainer signed, response time, onboarding pack ready
Cyber insurance notification and approved vendors Insurer via risk/finance [GATE] Whether a policy exists, who notifies, within what window, which responder and counsel panels it permits; engaging outside the panel can reduce cover
Legal privilege position and external counsel Legal, external where required [GATE] Settled per jurisdiction before the first investigation report is written
Estate-wide network containment: perimeter deny-all, remote access off Network/IT operations + executive per charter §4 [GATE] Who may order it, who executes it out of hours, and how long it can stand
Backup isolation and snapshot retention extension Backup/storage owner [HARD] Reachable 24/7; defaults roll off in days

Sources

Open CDC Framework, licensed CC BY 4.0. Credits: References & credits.