RACF-CC • Domain 7

Incident Response and Automation

Give a small, generalist team clear authority, practical playbooks and safe containment actions when cyber events threaten people, information or continuity of care.

Purpose

Respond consistently under pressure

Incident response coordinates technical containment with service continuity, safeguarding, privacy, communications and leadership decisions. RACF-CC prioritises short playbooks, a central record and pre-agreed escalation over a large enterprise response function.

What good looks like

Staff know how to report concerns; incidents receive an owner and severity; priority scenarios have one-page playbooks; evidence and decisions are recorded; legal and care-service consequences are considered; and lessons lead to tracked improvements.

Risk picture

Why informal response fails

Unclear authority

Responders hesitate over disabling accounts, isolating devices or interrupting a service.

Scattered records

Evidence, decisions and communications are lost across chats and inboxes.

No severity model

Technical alerts are not consistently translated into organisational impact.

Missing playbooks

Critical actions depend on memory during a stressful and unfamiliar event.

Unsafe automation

Automated containment can disrupt care if context, approval and rollback are absent.

No learning loop

Recurring weaknesses persist when post-incident actions lack owners and dates.

Prioritised action

The RACF-CC response control set

PriorityControl directionOutcomeEvidence
FirstCreate a central incident register with severity, owner, timeline and outcome.Establishes accountability and organisational memory.Complete incident records.
FirstDefine reporting, triage, escalation and decision authority.Reduces delay and uncertainty.Contact matrix and exercises.
FirstWrite one-page playbooks for identity compromise, malware, data loss and service disruption.Makes high-value actions repeatable.Approved and tested playbooks.
NextDefine containment actions across identity, endpoint, network and data platforms.Links monitoring signals to practical control.Action matrix and permissions.
NextIntegrate continuity, privacy, safeguarding, insurers, suppliers and communications.Addresses the whole organisational impact.Escalation and notification records.
NextRun proportionate tabletop exercises and capture improvement actions.Tests readiness without waiting for a real incident.Exercise report and action log.
DevelopAutomate only high-confidence, reversible tasks with human oversight.Improves speed without uncontrolled disruption.Approval, execution and rollback logs.

Implementation

A four-phase roadmap

Phase 1

Prepare

  • Name roles and deputies
  • Create the incident register
  • Define severity and escalation
  • Confirm contact routes

Phase 2

Standardise

  • Create priority playbooks
  • Map alerts to containment
  • Include privacy and continuity
  • Define evidence handling

Phase 3

Exercise

  • Run tabletop scenarios
  • Test out-of-band communication
  • Validate supplier escalation
  • Track lessons to closure

Phase 4

Automate carefully

  • Select reversible repetitive actions
  • Require appropriate approval
  • Monitor unintended effects
  • Review after every use

Care continuity changes containment decisions

Disconnecting a device or service may introduce immediate safety or continuity risks. Playbooks should identify who can make that decision, what fallback exists and how to preserve evidence. Automation should never outrun this context.

Stage automated containment before trusting it

Observe → pilot → validate → enable → monitor → review

Begin with reversible, high-confidence actions, test care-continuity decisions and require suitable approval where isolation, account disablement or blocking could interrupt essential services. Use the Safe Enforcement Pattern →

Include critical suppliers before an incident

Agree notification, escalation, containment authority, evidence sharing and continuity contacts while the service is operating normally. Use the Supplier and Third-Party Risk guide →

Evidence

Measure readiness and learning

OwnershipIncidents assigned and acknowledged within target.
Containment timeTime from confirmation to proportionate containment.
Record qualityTimeline, decisions, evidence, notifications and outcome completed.
Playbook coveragePriority scenarios with current, tested instructions.
Exercise performanceRoles, decisions and communications demonstrated in practice.
ImprovementPost-incident actions completed by agreed dates.

Residual risk and escalation

Record response limitations that remain

What may remain unresolved?

Untested playbooks, single-person dependencies, limited out-of-hours cover, supplier-controlled containment, unavailable forensic evidence and automation that cannot yet be enabled safely may remain.

Why might it remain?

Small teams, supplier boundaries, unavailable test environments, care-continuity constraints, limited tooling and infrequent exercise opportunities may restrict readiness.

Compensating safeguards

Maintain clear contacts and deputies, use manual containment steps, preserve out-of-band communications, pre-agree supplier escalation and rehearse priority decisions.

Risk owner

The accountable service and organisational incident owner share the consequence, supported by technical responders, privacy and continuity roles.

Review requirement

Review after every incident or exercise, material supplier or service change, role change and at the agreed readiness interval.

Escalation triggers

Critical incident outside available cover, failed containment, unavailable decision-maker, supplier non-response, evidence loss or immediate threat to care continuity.

Recording does not equal acceptance. Response gaps require leadership visibility because they affect the organisation’s ability to limit harm after preventative controls fail.

References

Standards alignment

Continue

Make improvement sustainable

Domain 8 connects policy, organisational risk, technical evidence, exceptions and leadership review.