Playbook
A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.
A playbook describes how a Security Operations Center reacts to a specific type of incident. It defines the steps, decision points, responsibilities, and permitted actions to be taken.
How it works
Playbooks exist for common scenarios like phishing, compromised accounts, or ransomware attacks. A playbook begins with the triggering alert, guiding analysts through investigation, containment, and closure. Many steps can be automated, such as enriching data with threat intelligence feeds. A human makes decisions at critical points, for example before isolating a production server.
In a phishing playbook, a reported email is analysed, including its links and attachments. If a threat is found, the SOC removes the message from all mailboxes. The SOC then checks who clicked the link and resets those accounts if needed.
What to look out for
- Up-to-date content: A playbook untouched for two years rarely fits the current IT environment.
- Clear authorisations: Document which actions are permitted without needing further approval.
- Correct contacts: Out-of-hours contact information for key personnel must be accurate.
- Regular drills: Test your most important playbooks using tabletop exercises.
- Customisation: Standard playbooks require adapting to your specific systems and processes.
How it differs from a Runbook
A playbook describes the response to an entire incident from start to finish. A runbook details individual technical steps, like blocking an account in Entra ID.
What makes a good playbook
A practical playbook should only be a few pages long. It names the trigger, investigation steps, decision points, and closure criteria. For each decision point, it must define who decides and how to contact them. Long texts without a clear sequence are unhelpful during a stressful situation. Review each playbook after a real incident and adapt whatever did not work.
How we implement it
We coordinate playbooks with you during onboarding and adapt them to your environment. Recurring steps are automated, and all decisions align with your specific mandate.