Home Services About Blog Contact 📞 1-800-890-6133
Free Resource

The Pro Link Systems Incident Response Playbook

The plan we actually run when something goes wrong — written down, and published, because the moment to find out how your IT partner handles a crisis is before the crisis.

Download the Playbook (PDF) Get a free 15-minute readiness review

No form, no email required — read it before you need it.

Most IT providers keep their incident process in their heads. We wrote ours down and published it, because the moment to find out how your IT partner handles a crisis is before the crisis, not at 2 a.m. during one.

This is the playbook our team follows when a client is under attack, down, or unsure. It is deliberately calm. Panic skips steps, destroys evidence, and turns a bad hour into a bad week — our job is to already know the next move so you don’t have to.

It is built on the incident-response lifecycle from NIST SP 800-61 — Prepare, Detect & Analyze, Contain, Eradicate & Recover, and Learn — adapted for the real conditions of a small or mid-sized business. Four pages, free, and no email address required.

How we classify severity

An incident is any event that threatens the confidentiality, integrity, or availability of your systems or data — something broken, exposed, or under attack that needs a coordinated response, not just a help-desk ticket. We classify every one so the response matches the stakes.

SeverityWhat it looks likeOur response
SEV-1 — Critical Active ransomware, confirmed breach, full outage of a critical system, funds at risk Immediate all-hands. Incident Commander assigned. Owner called, not emailed.
SEV-2 — High One compromised account, malware contained to a machine, a key system degraded, targeted phishing Rapid response, senior engineer engaged, client notified within the hour
SEV-3 — Moderate Suspicious activity, isolated outage, a failed backup, a lost device Same-day investigation, monitored to resolution
SEV-4 — Low A blocked threat, a single reported phishing email, a minor anomaly Logged, reviewed, used to tune defenses

Severity can move in either direction as we learn more. We would rather over-classify for the first thirty minutes than under-react.

Who does what, and in what order

In an incident, unclear roles cost time. The playbook assigns them immediately — an Incident Commander who owns the response and keeps the timeline, the Technical Lead(s) doing containment and recovery, a Communications Lead so your team gets one clear voice instead of five fragments, and your decision-maker, looped in from the start for anything touching operations, money, or legal exposure.

The first 60 minutes

The opening hour sets the tone. This is the checklist, in order:

  1. Confirm and classify — is it real, and how bad? Assign severity and an Incident Commander.
  2. Open the timeline — every action and finding, timestamped, from minute one.
  3. Contain, don’t erase — isolate what’s spreading; preserve the evidence.
  4. Communicate out-of-band — if email or accounts may be compromised, we reach you by phone or a channel the attacker can’t see. We never discuss a live incident on a system that may be listening.
  5. Protect what matters next — verify backups are intact and reachable before anything else touches them.
  6. Bring in the right people — senior engineers, and where warranted, guidance on cyber-insurance and legal notification obligations.

Runbooks for the incidents that actually happen

Six specific playbooks, each with the moves that matter and the mistakes that cost the most:

Ransomware

Isolate immediately but do not power machines down — it destroys evidence. Assess recovery options before any thought of payment; with tested backups, paying is usually avoidable.

Business email compromise

Reset credentials and revoke sessions, then hunt for attacker-created mailbox rules — auto-forward and auto-delete are the classic hidden footholds. Every payment change is verified by voice.

Account or credential compromise

Disable, revoke tokens, reset, re-enroll MFA. Review what the account could reach and whether it was used to move laterally. Assume the credential is public and rotate what it shared.

Data breach or exfiltration

Contain the access path first, then determine what data, whose, and how much — that drives the legal and notification obligations. Breach notification has deadlines, not just technical steps.

Major outage or infrastructure failure

Establish what’s down and the business impact, then work the restore in priority order — decided in advance, not during. Steady status cadence, so silence never reads as “still broken.”

Lost or stolen device

Remotely lock or wipe, revoke access and sessions, rotate any credentials it held. Assess what data it could reach and whether encryption was enabled — it should have been.

This playbook is a general framework, adapted to each client’s systems, obligations, and risk. It is guidance, not a substitute for a response plan built for your specific environment.

Want the printable version?

The full playbook — 4 pages, print-ready, no form and no email required.

Download the Playbook (PDF)
Free 15-Minute Readiness Review

Want us to pressure-test your incident readiness?

A straight read on where you’re exposed and what to shore up first — no pitch. Because the best time to meet the team that answers at 2 a.m. is long before you need them.

Book your free 15-minute review 1-800-890-6133