Response design
Turn generic doctrine into playbooks a rail team can run.
Start from the six-phase response model, generate a playbook for the scenario in front of you, then compare it against your own draft to find the gaps.
Response framework
The six phases, in order
- 01Preparation
Define ownership, evidence handling, communications, backups, and OT safety boundaries before an incident happens.
- 02Identification
Verify the incident, scope affected systems, establish severity, and preserve the signals needed for decision-making.
- 03Containment
Limit spread fast while balancing service continuity and safety for rail operations and dependent systems.
- 04Eradication
Remove malicious access, close the exploited weakness, and confirm the environment is no longer hostile.
- 05Recovery
Restore services in controlled phases, validate clean state, and monitor closely for recurrence or hidden impact.
- 06Lessons learned
Capture what worked, where friction appeared, and which policy, tooling, or training gaps need to change.
Playbook builder
Generate a scenario-specific playbook
No playbook loaded
Pick a scenario and generate a guide first. You can then export it, reframe it, or compare it against your own draft.
Draft comparison
Compare your own draft
Generate a guide first so there is a baseline to compare against.
Reporting windows
For a significant incident, send the early warning within 24 hours of becoming aware so the CSIRT or competent authority gets an early signal.
Follow with the incident notification within 72 hours, including severity, impact, and any indicators of compromise available at that stage.
If a personal data breach is likely to create risk for individuals, notify the DPC without undue delay and, where feasible, within 72 hours of awareness.
Under NIS2, expect a final report within one month after the incident notification, then feed the lessons back into controls, comms, and exercises.