Free Tool

Incident Response Runbook Template
one per-scenario package for activation, triage, containment, evidence, eradication, recovery, communication, closure, and post-incident handoff

A free, copy-ready incident response runbook template. Twelve structured sections covering runbook header and version control, activation criteria, scenario-specific role assignment, initial triage in the first ten to thirty minutes, containment options with evidence checkpoints, evidence preservation rules and chain-of-custody discipline, eradication procedure with vulnerability and compensating-control routing, recovery procedure with staged service return, communication script with templated messages and named release authority, closure criteria with signed closure record, post-incident review handoff with five artefact classes, and runbook governance with cadence and revision triggers. Aligned with ISO/IEC 27001 Annex A 5.24, A 5.25, A 5.26, SOC 2 CC7.4 and CC7.5, PCI DSS Requirement 12.10.1, 12.10.5, 12.10.6, NIST SP 800-61 Rev. 2 Section 3.3, NIST SP 800-53 IR-4 through IR-8, NIS2 Article 21, DORA Article 17, HIPAA 164.308(a)(6), and the sector-specific overlays a regulated estate operates against.

No credit card required. Free plan available forever.

Loading tool...

Run the runbook portfolio on the same workspace as the rest of the security record

SecPortal carries the runbook version, the activation event, the timeline, the evidence pack, the closure record, and the after-action report on one workspace so the audit committee read of incident response performance and the operational read are the same record. Free plan available.

No credit card required. Free plan available forever.