Public Sector & Local Government
Updated
A small town may have only a few people available when email is untrusted, a vendor is unreachable, and department leaders need answers. The first-24-hour playbook should help that team coordinate facts, protect essential services, preserve decision quality, and reach the right outside parties. It should not pretend the town can diagnose every event or prescribe notification duties without legal and factual review.
Define the playbook boundary before the incident
This guide covers the operating period from initial report through the first day. Its job is to establish control: open an incident record, identify an incident lead, protect people and essential services, limit further harm, preserve relevant information, maintain alternate communications, and place decisions with authorized leaders. It does not replace the town's continuity, emergency-management, legal, insurance, law-enforcement, or technical-recovery procedures.
NIST's current SP 800-61 Revision 3 integrates incident response across cybersecurity risk management rather than treating it as a standalone technical phase. The NIST Cybersecurity Framework 2.0 likewise places response and recovery within a lifecycle that also includes governance, identification, protection, and detection. That matters for a small municipality: response decisions can affect safety, privacy, operations, finances, public communications, evidence, and recovery at the same time.
Keep the printed playbook and critical contacts somewhere available without the normal network. Assign a primary and alternate for each role. Test whether those people can reach the record, conference method, vendor contacts, and approved communication templates when municipal email, identity, or a building is unavailable.
Use a small role structure with explicit authority
- Incident lead: coordinates the operating period, maintains objectives, assigns actions, and ensures decisions are recorded. This person need not be the most technical responder.
- Technical lead: validates observable facts, proposes containment and evidence-preservation actions, tracks affected assets, and states the operational risk of each proposed change.
- Service owners: explain resident and staff impact, validate minimum service needs, and approve workarounds within their authority.
- Executive decision owner: resolves priority conflicts and approves consequential operational choices according to the town's established authority.
- Communications lead: coordinates internal, partner, public, and media messages using confirmed facts and approved channels.
- Recorder: keeps the action, decision, contact, and evidence logs. Combine this role with another only when workload permits.
Legal counsel, insurer or broker, emergency management, law enforcement, regulators, records staff, and specialized responders may need to join. The correct parties and timing depend on the event, contracts, coverage, applicable requirements, and counsel. The playbook should store vetted contact paths and decision prompts, not invent universal reporting deadlines.
First hour: establish command and protect options
- Open the record. Assign an incident identifier, start time, recorder, incident lead, and alternate coordination channel. Record who reported what, using their words and separating observations from assumptions.
- Check immediate safety and service impact. Ask whether emergency response, water, communications, finance, facilities, or other essential services are impaired or at risk. Escalate life-safety issues through established emergency procedures.
- Control communications. If normal identity or email may be affected, move to the approved alternate. Do not spread sensitive screenshots, credentials, personal information, or attacker content through uncontrolled channels.
- Preserve options. Technical responders should document state and obtain appropriate authorization before destructive actions. Turning systems off, deleting files, restoring backups, or broadly blocking access can change evidence and service availability.
- Engage known support paths. Use independently verified numbers for internal support, managed providers, cyber insurer contacts, counsel, and essential vendors. Treat new contact instructions received during the event as untrusted until verified.
Hours one through four: bound the event
Create a working scope from evidence: affected users, devices, accounts, locations, applications, data, and services; observed indicators; first known activity; and confidence in each statement. Mark unknowns clearly. Do not let an unverified label such as “ransomware” or “data breach” substitute for facts.
Set short operating objectives, such as protecting dispatch communications, preventing use of a compromised administrator account, or determining whether a shared service remains trustworthy. For every containment proposal, document expected benefit, affected service, rollback or alternate, evidence impact, authority required, and validation step. NIST SP 800-61r3 emphasizes considering broader organizational risks during incident decisions, which supports this deliberate approach. CISA's voluntary Cross-Sector Cybersecurity Performance Goals prioritize a limited set of high-impact practices and can help a resource-constrained team decide which prepared capabilities to strengthen after the immediate event; they are guidance, not a complete response plan or mandate.
FEMA's cyber incident planning considerations connect cyber response with continuity and degraded communications. If a public service is affected, activate the relevant continuity arrangements and track the service state separately from the technical investigation. The municipal disaster-recovery blueprint provides the next layer for restoration planning.
Hours four through 12: stabilize decisions and handoffs
Run brief status meetings on a cadence set by the incident lead. Each update should cover verified changes, essential-service state, actions completed, current objectives, decisions required, information gaps, and next update time. Avoid long speculative briefings. A stable common operating picture is more useful than a stream of unprioritized technical detail.
Coordinate external reporting through authorized leadership and appropriate advisors. CISA maintains a central cyber incident reporting page, while the FBI's Internet Crime Complaint Center accepts cybercrime complaints. CISA's StopRansomware Guide also identifies federal assistance and reporting paths. These resources do not determine every town's contractual, legal, regulatory, insurance, or records obligations; confirm those for the actual facts.
Prepare handoffs. Document temporary access, emergency changes, isolated systems, evidence locations, vendor case numbers, staff coverage, pending decisions, and the next operational objectives. A handoff should allow a fresh responder to understand why actions were taken, not merely what buttons were pressed.
Hours 12 through 24: plan the next operating period
Reassess scope and confidence. Confirm that containment remains effective, alternate services are sustainable, monitoring covers the suspected paths, and no essential dependency has been overlooked. Decide which systems may be restored only after responsible owners agree on validation, trust, sequencing, and rollback. Restoration pressure should not erase unresolved questions about identity, persistence, or data integrity.
Approve a written next-period plan with service priorities, technical objectives, communications, staffing, decision points, and evidence needs. Schedule an after-action process, but do not conduct it while active response still needs the same people. The related local-government tabletop guide is for exercising this playbook before an event, not for substituting a discussion exercise for live incident management.
Copy this incident action and decision log
Use one chronological record with controlled access and retention determined by the town. Give every entry the same common fields: time, recorder, entry type, source, observed fact or clearly labeled assumption or question, and confidence. Then complete only the fields relevant to that entry type:
- Service-state entry: affected department, public or internal impact, workaround, owner, and next validation time.
- Action entry: assigned owner, authorization, start and completion time, expected result, actual result, and evidence reference.
- Decision entry: question, options considered, operational and evidence implications, decision maker, rationale, approval time, and reconsideration trigger.
- External-contact entry: verified organization and person, contact method, case number, information shared, commitments, and follow-up owner.
- Communication entry: audience, approved facts, approver, channel, issue time, and any correction required.
Keep alternate communication instructions in the emergency communications continuity playbook. Review this incident playbook after exercises, material system or provider changes, and actual events. A usable first-day record is measured by the quality of coordination and decisions it preserves, not by how many pages it contains.
Official sources
- NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations
- FEMA: Planning Considerations for Cyber Incidents
- CISA: Reporting a Cyber Incident
- FBI: Internet Crime Complaint Center
- CISA: StopRansomware Guide
- NIST: Cybersecurity Framework
- CISA: Cross-Sector Cybersecurity Performance Goals