Back to glossary

Playbook

1 min read

A playbook is a documented and repeatable procedure for handling one specific incident type, written so that responders do not have to improvise under pressure. In security operations it fixes the decisions, the thresholds and the authority to act in advance, when there is time to think about them properly.

July 24, 2026
Compartir:

A useful one is narrow. Ransomware on a file server, business email compromise on a single mailbox, and a confirmed credential leak are three playbooks, not one, because the containment decisions differ. What each needs is the same short set of things: the trigger, the evidence to collect before anything is changed, who is authorised to disconnect or disable, the notification obligations with their clocks, and the criteria for declaring the incident over.

The parts that get skipped are the ones that matter most in the first hour. Who can authorise isolating a production system at three in the morning, and what happens if that person does not answer. Where the contact list lives if the directory is unavailable. Whether a mailbox is preserved before it is reset, since resetting first destroys evidence that incident response will need afterwards.

Automation in a SOAR platform encodes the steps but does not test the assumptions. What tests them is running the procedure against a scenario with the real people, and the observation we most often record is a document that is technically correct and has never been executed by anyone who would have to execute it.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.