6. Incident Playbooks

6.1 How to Use These Playbooks

When you discover a security incident:

  1. Don't panic - Take a breath; most incidents are recoverable if you act systematically

  2. Find the right playbook - Match your situation to one of the scenarios below

  3. Follow the steps in order - Steps are prioritized by urgency and importance

  4. Document everything - Keep notes on what happened, when, what you did, who you spoke to

  5. Ask for help - If you're overwhelmed, ask a tech-savvy friend or professional

6.1 Account Compromise

Compromised Email Account

Signs your email might be compromised:

Step 1: Regain Control if Locked Out (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage control (Within Hours)

Step 4: Additional Actions

Compromised Password Manager

This is the worst-case scenario. Act fast!

Signs your password manager is compromised:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Reset All Passwords In Your Vault (IMMEDIATELY – this takes time)

Assume every account in your vault is compromised. Work through tiers in order. For EACH account changed:

  1. Change password to new unique password

  2. Remove all authorized devices

  3. Enable or verify MFA

  4. Check recent activity

  5. Verify security questions and recovery settings

  6. Check for account-specific issues (email forwarding, rofile changes, etc)

Tier 1 – Immediately

Tier 2 – Within 1 Hour

Tier 3 – Within 4 Hours

Tier 4 – Within 12 Hours

Tier 5 – Within 24 Hours

Step 3: Additional Actions

Compromised Financial Account

(Bank, credit union, credit card, investment account, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Additional steps:

Compromised Social Media Account

(Facebook, Twitter/X, Instagram, LinkedIn, forums, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

Compromised Cloud Storage Account

(Google Drive, OneDrive, iCloud, Dropbox, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

Compromised Shopping Account

(Amazon, eBay, Etsy, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

If Any Other Account is Compromised

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

6.3 Personal Data Incidents

Identity Theft

Signs of identity theft:

Step 1: Contain the Damage (IMMEDIATELY)

Step 2: Close Fraudulent Accounts (Within 24-48 Hours)

Step 3: Secure Your Legitimate Accounts (Within 48 Hours)

Step 4: Additional Actions

Lost or Stolen Wallet or Purse

What's at risk:

Step 1: Immediate Containment (IMMEDIATELY)

Step 2: Replace Documents (Within 24-48 Hours)

Step 3: Monitoring

Sent Money to a Scammer

Common scenarios:

Step 1: Try to Stop the Payment (IMMEDIATELY)

Document everything:

For wire transfers:

For credit/debit card charges:

For payment apps (Venmo, PayPal, Zelle):

For gift cards:

For cryptocurrency:

Step 2: Report the Fraud (Within 24 Hours)

Step 3: Protect Against Further Loss (Within 24 Hours)

Gave Out Personal Information

Follow this playbook if you gave out high risk, personal information via email or to a caller in a conversation you did not initiate.

High Risk Personal Information:

Step 1: Immediate Actions (Based on What You Shared)

Step 2: Monitor accounts daily for 2 weeks

If you see anything unusual, follow the appropriate playbook

Clicked a Phishing Link or Opened Suspicious Attachment

Your next steps are based on what you did, based on risk.

Low Risk

High Risk

Received Notice of Data Breach

This is when a company notifies you your data was exposed.

Common notification sources:

Step 1: Verify Notification is Legitimate (IMMEDIATELY)

Beware of phishing! Don't click links in breach notification emails, instead, verify using one of the following:

Step 2: Understand What Was Exposed (Within 24 Hours)

Read the notification carefully:

Step 3: Take Action Based on Data Exposed (Within 48 Hours)

If passwords were exposed: Follow the playbook for the type of compromised account above

If email address only: Not much you can do here, just understand you will likely start receiving a lot of spam and potentially phishing attempts, so be extra vigilant in the coming weeks and months.

If Social Security number or financial data:

If medical information:

Step 4: Accept Company's Offer (If Valuable)

Many companies offer:

Evaluate the offer:

Step 5: Additional Actions

Document the breach:

Monitor relevant accounts based on exposure and consider legal action if negligence was involved.

Ongoing monitoring:

SIM Swap Attack

Signs of SIM swap:

Step 1: Regain Control of Phone Number (IMMEDIATELY)

Contact your mobile carrier:

Step 2: Secure Accounts That Use Phone for 2FA (Within 1 Hour)

Attackers may have targeted accounts using SMS for two-factor authentication. Verify recent logins to new devices in the following priority:

If there was an unauthorized login, for each account:

6.4 Device Incidents

Ransomware Infection

Signs of ransomware

Step 1: Isolate the Infection (IMMEDIATELY)

Step 2: Assess and Report (Within 1 Hour)

Do NOT pay the ransom, there is no guarantee of file recovery and this funds criminal activity

Step 3: Recovery Options

If decryption is available from your assessment, follow the instructions. This differs by type of ransomware and who is providing instruction, so I cannot be more specific than that.

If no decryption is available AND you have backups then performing a clean reinstall of your operating system is the way to go. Again, I cannot be more specific as there are too many variables. If you aren’t sure how to do this, ask a technical friend or visit somewhere that services computers (Microcenter, Best Buy, Apple Store, etc).

If no decryption is available and you DON’T have backups, I’m sorry, you’re pretty screwed. From a clean computer, go through all your accounts and remove that computer as an authorized device. Under no circumstances should you boot this computer and connect to anything until it is clean. Keep an eye on the decryption assistance sites above, there may be something in the future that can help, or seek assistance from a professional service.

Malware or Virus Infection (Not Ransomware)

Signs of malware infection:

Step 1: Isolate The Infection (IMMEDIATELY)

Step 2: Scan and Remove (Within 1 Hour)

Step 3: Check for Damage (Within 24 Hours)

Step 4: Additional Actions

If infection cannot be cleaned, contact your antivirus provider. Even if you don’t pay for the service they may still offer help.

The worst-case scenario, make sure your backups are working and perform a clean reinstall of your operating system. If unsure how to do this, talk to a technical friend or seek professional services.

Gave Remote Access to Your Computer

Common scenarios:

Step 1: Cut Off Access (IMMEDIATELY)

Step 2: Scan for Malware (Within 30 minutes)

Step 3: Additional Actions

What To Do If Your Phone or Computer Is Lost or Stolen

Act quickly, the sooner you respond, the better your chances of recovery or protecting your data.

Step 1: Protect Your Data (IMMEDIATELY)

Use Find My Device (see Mobile Device Hardening or Physical Security section) to:

Suspend services and force logouts:

If you had an authenticator app on your phone, you may lose MFA access, so you may need to use another device where the authenticator app is install or the recovery codes form your password manager.

Step 2: Erase and File Reports (Within 12 Hours)

If stolen or otherwise not recoverable:

Step 3: Recovery

If device is recovered, before using:

If suspicious changes found, factory reset the device and proceed as if setting up a new device.