← Backup & Recovery

decision guide

Assign Incident Roles Before Everyone Starts Improvising

A preparation-only method for defining small-team incident accountability, authority, coordination, evidence custody, communications, deputies, conflicts, and safe handoffs.

For

An owner or operations lead in a 1–50-person team that lacks agreed incident accountability, authority, coordination, evidence, communications, deputies, and escalation.

Not for

A complete incident-response plan, live investigation or containment, trigger-specific action sequence, legal or notification determination, forensics, recovery, or emergency support.

Failure addressed

Named people are mistaken for available, authorized, competent, independent role coverage, or trigger-specific response is improvised without a general responsibility model.

An incident is a poor time to discover that the person called the owner cannot make the required decision, the coordinator is also the only technical executor, the normal communication route may be unsafe, or nobody knows who holds the record.

This guide helps a 1–50-person team prepare a minimum role-and-communication matrix before a trigger occurs. The title phrase Before Everyone Starts Improvising means preparation before a trigger. It does not authorize assembling a live response team, assigning real people through this article, contacting anyone, or taking incident action.

What the sources support — and what PlainFort adds

NCSC’s small-business incident-preparation guidance supports assigning and documenting responsibilities, shared backup coverage, contactability, trigger points, and exercises. NCSC’s guidance on building an incident-response team supports multiple roles, central coordination, transparent role combination, internal decision oversight, deputies, availability, and exercises. That second source is explicitly written for cyber-security professionals and large organizations, so this article uses only its general role and coordination principles—not its organizational model as a small-team prescription.

NIST SP 800-61 Rev. 3 supports incorporating incident-response recommendations and considerations throughout cybersecurity risk management to improve preparation, detection, response, and recovery. It does not prescribe a PlainFort role matrix or a live incident sequence.

The fifteen concepts, eight stages, nine planning states, role set, combination questions, minimum-deputy rule, handoff model, evidence threshold, 18 fields, tabletop method, completion rule, and review triggers below are PlainFort editorial judgment. They are not NCSC or NIST requirements, a CSIRT standard, legal or notification advice, an incident-response certification, a universal staffing model, or a guarantee.

Keep fifteen role-design concepts separate

  1. Scenario and activation boundary: a category-level situation and reference to a separately owned trigger, not a live incident declaration.
  2. Accountable incident lead: the internally accountable owner, distinct from coordination, execution, advice, and provider support.
  3. Decision authority: who may make bounded business decisions, distinct from the person reporting, coordinating, or executing.
  4. Central coordinator: the role that tracks work, findings, decisions, and handoffs without automatically acquiring business authority or technical competence.
  5. Authorized technical executor: a qualified execution category, not an instruction to perform containment, recovery, account, device, mailbox, or provider action.
  6. Scribe and evidence custodian: ownership of an inert record and evidence boundary, distinct from evidence collection, forensic preservation, inspection, or content copying.
  7. Internal communications owner: responsibility for approved internal coordination categories, not actual messages or contact details.
  8. External communications owner: responsibility for qualified external-communication decisions, distinct from authority to notify, contact, disclose, or make legal statements.
  9. Business-continuity owner: ownership of continuity decisions and handoffs, not backup strategy, restore execution, or proof that a workaround functions.
  10. Qualified escalation categories: legal, privacy, records, insurance, law-enforcement, contractual, regulatory, and specialist questions routed for review rather than answered here.
  11. Deputies, availability, and safe contact categories: genuine coverage and a safe-channel category, not a person’s details, schedule, or promise of reachability.
  12. Role combination, capacity, conflict, and independence: visible tradeoffs when a small team combines roles, without treating combination as automatically acceptable or unacceptable.
  13. Trigger-specific handoff: routing to EP-15, DN-18, AA-09, or another qualified guide without copying its sequence.
  14. Unavailable-role and disputed-authority path: a visible stop when ownership, authority, independence, or safe communication cannot be established.
  15. Tabletop evidence, unresolved gaps, completion evidence, and review: category-level evidence of a non-live review and follow-up, not proof of readiness or a record of a real incident.

Do not collapse these concepts into one Role assigned, Team ready, Incident owner named, Covered, Exercised, Resolved, or Ready checkbox. A named person or provider cannot silently prove authority, competence, availability, capacity, independence, safe communication, legal compliance, trigger coverage, evidence custody, continuity, or incident readiness.

Use an eight-stage preparation process

The sequence below creates an editorial planning record. It does not activate a response or supply live incident steps.

1. Bound the scenario and activation reference

Describe only the category of situation the matrix is intended to support and record an inert reference to a separately owned trigger. Do not declare an incident, copy incident facts, create a timeline, infer impact, or turn uncertainty into an activation decision.

If the applicable trigger, activation authority, or handoff is unknown, use Trigger-specific handoff required or Blocked — authority or safe channel missing. Do not invent a trigger so the matrix can appear complete.

2. Consume existing decisions without reopening them

Use SF-04 for PlainFort’s general responsibility vocabulary. Bring in only inert references from BR-21, BR-25, and BR-22 for continuity, provider-responsibility, restore-test evidence, ownership, and escalation.

Do not copy recovery objectives, provider details, test evidence, contacts, systems, configurations, or live decisions into this matrix. A missing or disputed input remains visible; it is not recreated here.

3. Separate accountability, authority, coordination, and execution

Record the internally accountable lead, decision authority, central coordinator, and authorized technical-executor category separately. One person may cover more than one category in a small team, but the record must show the capacity, availability, backup, conflict, independence, and escalation consequences.

Internal accountability cannot be transferred silently to a contractor, provider, insurer, adviser, or tool. Central coordination does not create authority for privileged, destructive, legal, financial, privacy, records, insurance, notification, or public-communication action. Technical execution always remains subject to separate live authorization and trigger-specific guidance.

4. Assign evidence, communication, continuity, and escalation ownership

Record category-level owners for the scribe/evidence boundary, internal communication, external communication, business continuity, and qualified escalation. A scribe or evidence custodian owns the boundary and inert reference; that role does not gain permission to collect, inspect, copy, preserve, analyze, transfer, or disclose evidence.

A communications owner does not automatically have authority to contact anyone, send a message, notify an affected party, disclose facts, or speak for the organization. Legal, privacy, records, insurance, contractual, regulatory, law-enforcement, and specialist questions are escalation categories, not conclusions supplied by this article.

5. Add genuine deputies, availability, and safe-channel categories

Each essential function needs a genuine deputy or a visible gap. Record only role, availability, and safe-contact categories—never a person’s name, address, phone number, handle, schedule, or route details.

Naming a deputy does not prove the deputy is reachable, unaffected, authorized, competent, independent, or able to use a safe channel. If the only owner or deputy may be affected, the normal communication route may be unsafe, or coverage cannot be established, stop at Availability or safe channel unknown or Blocked — authority or safe channel missing.

6. Surface combinations, conflicts, capacity, and disputed authority

Document why roles are combined, what capacity or independence is lost, which decisions the combination may affect, and who reviews the exception. Do not hide a conflict because the team is small or because a provider offers technical help.

An affected owner, disputed authority, unavailable decision-maker, missing deputy, evidence conflict, or unsafe communication route blocks completion. Combining roles is neither an automatic failure nor proof of coverage; it is a bounded decision with residual risk and escalation.

7. Map trigger-specific handoffs and review tabletop-only

Route suspected mailbox compromise to EP-15, device loss or theft to DN-18, and departure-triggered access work to AA-09. BR-24 supplies the general role and communication model but never copies those guides’ trigger-specific sequences.

Review the matrix only as a tabletop planning exercise with category-level, wholly fictional prompts. Do not use a real account, mailbox, device, provider, person, contact, credential, evidence item, or incident. Do not fabricate a scenario plausible enough to rehearse as live response. Record only which role categories and handoffs were understood, blocked, disputed, or unresolved.

8. Close gaps and set evidence and review triggers

Close the editorial record only when the role categories, evidence references, deputies, availability, safe-channel categories, conflicts, trigger handoffs, unresolved gaps, accountable follow-up, completion evidence, and change-based review trigger are visible.

Reopen it when people or role categories change; authority, availability, communication routes, providers, contracts, trigger guides, recovery inputs, legal context, or evidence expectations materially change; or a tabletop review exposes a gap. Do not mark the matrix complete by hiding Blocked, Deferred, Qualified review required, or a disputed authority path.

Use planning states, not a readiness score

  • Role assigned — evidence referenced
  • Reported assigned — evidence not inspected
  • Deputy required
  • Availability or safe channel unknown
  • Conflict or independence review required
  • Trigger-specific handoff required
  • Blocked — authority or safe channel missing
  • Deferred — owner and review trigger required
  • Qualified review required

These states show planning position, not a security score, maturity level, severity, incident status, readiness grade, staffing sufficiency, legal conclusion, or guarantee. Role assigned — evidence referenced does not mean the person is available, authorized, competent, independent, safe to contact, or prepared for every trigger. Blocked, Deferred, and Qualified review required are visible outcomes and cannot be hidden to mark the matrix complete.

Build the 18-field vertical incident-role matrix

  1. Scenario or incident boundary: category-level scope and explicit exclusions; no incident facts.
  2. Activation or trigger reference: inert reference to a separately owned trigger; no declaration or sequence.
  3. Accountable incident lead: internal role category and evidence state.
  4. Decision authority: bounded authority category, disputed-authority state, and escalation path.
  5. Coordinator: central coordination category kept separate from authority and execution.
  6. Authorized technical executor: qualified category only; no permission or live steps.
  7. Scribe or evidence custodian: inert-reference ownership and evidence boundary.
  8. Internal communications owner: role and approved-channel category without contact details.
  9. External communications owner: qualified decision and escalation category without notification authority.
  10. Business-continuity owner: continuity handoff category and unresolved dependency state.
  11. Legal, privacy, records, and insurance escalation category: questions and qualified route only; no determination.
  12. Deputy for each essential function: genuine coverage or visible gap.
  13. Availability and safe contact category: category and evidence state; details held elsewhere.
  14. Role-combination and independence conflict: combined roles, capacity, conflict, exception, and reviewer.
  15. EP-15, DN-18, or other trigger handoff: dedicated-guide reference without copied sequence.
  16. Unavailable-role or disputed-authority path: stop, escalation category, and accountable follow-up.
  17. Tabletop evidence and unresolved gaps: inert evidence reference, non-live scope, gaps, and owner.
  18. Review trigger with completion evidence: evidence state, residual risk, change trigger, and no universal schedule.

Keep the artifact vertical. Do not convert it into a table, live roster, contact directory, call tree, chat transcript, incident timeline, dashboard, scorecard, RACI diagram, provider runbook, evidence log, legal checklist, notification template, or activation form.

Fictional example — do not copy as a completed backup or recovery record

  1. Scenario or incident boundary: generic preparation category; no incident is declared or described.
  2. Activation or trigger reference: Trigger reference held in approved system — details not copied.
  3. Accountable incident lead: internal leadership role category; availability not assumed.
  4. Decision authority: internal decision-owner category; authority evidence is reported but not inspected.
  5. Coordinator: operations coordination role, separate from technical execution.
  6. Authorized technical executor: qualified support category; no person, provider, permission, or action named.
  7. Scribe or evidence custodian: records role; Role evidence held in approved system — content not copied.
  8. Internal communications owner: operations communication category; no message or contact detail.
  9. External communications owner: leadership and qualified-advice category; no external contact authorized.
  10. Business-continuity owner: operations role; BR-21 handoff recorded without objective values.
  11. Legal, privacy, records, and insurance escalation category: Qualified review required; no conclusion or organization named.
  12. Deputy for each essential function: leadership deputy reported; evidence not inspected; evidence-custody deputy missing.
  13. Availability and safe contact category: Safe contact category recorded — details not copied; one essential function remains unknown.
  14. Role-combination and independence conflict: coordinator and internal-communications categories are combined; capacity review required.
  15. EP-15, DN-18, or other trigger handoff: EP-15 and DN-18 references recorded; sequences not copied.
  16. Unavailable-role or disputed-authority path: Blocked — authority or safe channel missing for the unresolved evidence-custody backup.
  17. Tabletop evidence and unresolved gaps: tabletop-only review reported; evidence reference held elsewhere; backup and availability gaps remain.
  18. Review trigger with completion evidence: reopen after deputy, authority-evidence, safe-channel, and capacity gaps are resolved; no date supplied.

This example does not prove that Example Co. has authorized, competent, available, independent people; safe communications; complete trigger coverage; valid evidence custody; working continuity; legal compliance; or incident readiness. A fabricated incident, person, contact route, authority dispute, outage, evidence item, message, finding, notification, exercise, or response result plausible enough to be mistaken for live material is prohibited even when labelled fictional.

Preserve the dedicated-guide boundaries

  • SF-04 owns the general six-function responsibility vocabulary; BR-24 applies it to incident-specific authority, coordination, evidence, communications, deputies, and escalation without redefining the model.
  • BR-21 owns business recoverability strategy, objectives, dependencies, and restore order; BR-24 consumes inert continuity and ownership references without redesigning it.
  • BR-25 owns provider/customer responsibility and provider-evidence boundaries; BR-24 may record a provider-support category but cannot infer availability, authority, capability, coverage, or contract terms.
  • BR-22 owns a bounded restore-test plan, evidence record, and result; BR-24 consumes authority, evidence, cleanup-handoff, and continuity vocabulary without executing or judging a test.
  • BR-23 owns the later ransomware-readiness synthesis; BR-24 supplies general role-matrix evidence without reproducing preparation or response.
  • EP-15 owns suspected-mailbox-compromise preparation and qualified incident handoff; BR-24 does not copy its trigger sequence.
  • DN-18 owns lost-or-stolen-device preparation and qualified handoff; BR-24 does not copy its trigger sequence.
  • AA-09 owns departure-triggered access offboarding; BR-24 does not turn a departure or access concern into a general incident trigger or repeat that checklist.

Stop before activation, contact, evidence, or live response

Stop and obtain separately authorized qualified help when an active or suspected incident exists; activation authority is unclear; the accountable owner or decision authority is affected, unavailable, disputed, or conflicted; no genuine deputy exists; safe communications are unavailable; privileged, destructive, containment, recovery, device, account, mailbox, provider, or production action may occur; evidence would need to be collected, inspected, copied, preserved, analyzed, disclosed, or transferred; sensitive, regulated, personal, client, employment, health, legal, financial, records, insurance, contractual, regulatory, law-enforcement, or notification matters appear; external contact or public communication is contemplated; or continuity and trigger-specific ownership are unresolved.

This guide creates an editorial role matrix. It does not activate an incident, assign or contact real people, run a tabletop or live exercise, collect or inspect evidence, investigate, perform forensics, contain, eradicate, recover, communicate, notify, disclose, contact a provider, access an account, mailbox, device, or system, invoke continuity, or authorize another person or tool to do so. It does not create, configure, reveal, test, remove, rotate, invoke, or decide break-glass, last-administrator, recovery, privileged-access, evidence-preservation, legal-hold, insurer, law-enforcement, regulator, or notification actions.