> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/security-vetting-and-technical-assurance-playbook/cyber-resilience/incident-response-and-crisis-management.md).

# Incident Response and Crisis Management

### Purpose

Incident response ensures that security events are detected, assessed, contained, eradicated, recovered and learned from.

### Severity Model

| Severity      | Description                                                                                            | Response expectation                                                                               |
| ------------- | ------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------- |
| SEV1 Critical | Confirmed major compromise, material data exposure, loss of critical service or active threat.         | Immediate mobilisation, executive escalation, customer notification assessment and crisis cadence. |
| SEV2 High     | Serious incident affecting sensitive data, privileged access, production service or supplier boundary. | Same day escalation, containment plan and formal incident record.                                  |
| SEV3 Medium   | Limited incident, suspicious activity or contained vulnerability exploitation.                         | Managed through security operations with tracked actions.                                          |
| SEV4 Low      | Minor policy breach, unsuccessful attack or low-impact anomaly.                                        | Record, triage and close with evidence.                                                            |

### Response Phases

1. Detect and report.
2. Triage and classify.
3. Preserve evidence.
4. Contain the threat.
5. Eradicate root cause.
6. Recover service.
7. Validate integrity.
8. Notify stakeholders where required.
9. Conduct post-incident review.
10. Track corrective actions to closure.

### Evidence

* incident record;
* timeline;
* logs and indicators;
* decisions and approvals;
* notifications;
* containment actions;
* recovery validation;
* lessons learned;
* corrective action plan.

### Rule

Never sacrifice evidence preservation, legal notification obligations or customer trust for speed unless there is a clear safety, operational or security reason to act immediately.
