Guide
What belongs in a practical incident runbook
A short runbook structure that fits a forty-person company and still satisfies POPIA-minded reviewers.
An incident runbook fails when it tries to cover every cyber scenario in a hundred pages. For most South African mid-market teams, a ten-page guide that names people, channels, and decision points outperforms a glossy binder nobody opens.
List the triggers: lost laptop with client files, ransomware on a shared drive, phishing that harvested passwords, or a vendor breach notice. Beside each trigger, name the first responder and the escalation path to a director.
Include contact cards for hosting providers, your insurer if cyber cover exists, and legal counsel you have already briefed. Searching for phone numbers during an outage wastes the hour when containment matters most.
Add a simple decision tree for whether personal information may have been accessed. That single branch drives POPIA-related notifications and should not be improvised under stress.
Review the runbook after every tabletop exercise. Page Willowhub often folds runbook updates into advisory retainers so the document stays aligned with the systems you actually use.