Incident Response
Step-by-step runbooks for ransomware, breaches, and outages. Arctic Wolf escalation paths. Break-glass procedure for 18 accounts.
Open runbook
One source of truth for Cirius Group — architecture, runbooks, and compliance, continuously verified against the live environment.
<div class="vp-doc" style="max-width:960px;margin:2rem auto;padding:0 1.5rem">
<SynthesisStats />
Jump straight to what you need. Live system status, current priorities, and the CI/CD pipeline reference live on the Operations & Status page.
| Link | Description |
|---|---|
| Incident Response | Ransomware, breaches, outages — start here |
| Alert Triage | Sources, routing, severity, escalation |
| Break-Glass Procedure | Emergency access for 18 accounts |
| Monthly Threat Hunt | KQL patterns and evidence retention |
| Out-of-Band Comms | When primary channels are compromised |
| Kill Chain Coverage | Detection status per stage |
| Link | Description |
|---|---|
| Compliance Scorecard | Current posture — update weekly |
| HIPAA Controls | Full controls matrix |
| SOC2 PBC Guide | Auditor request mapping |
| Risk Assessment | §164.308 formal assessment |
| Vendor PHI Inventory | BAA status for all PHI vendors |
| Training Log | KnowBe4, HIPAA, tabletop |
| Link | Description |
|---|---|
| Azure Daily Operations | Routine Azure tasks |
| AWS Account Access | SSO, IAM Identity Center |
| Common Tasks | Server, firewall, cert operations |
| Twingate Operations | User/resource/connector management |
| Arctic Wolf Day-to-Day | MDR daily operations |
| Backup Architecture | RSV, Veeam, offline backups |
| Link | Description |
|---|---|
| Threat Model | Canonical — crown jewels, threat actors, STRIDE |
| Palo Alto Overview | 4 × VM-Series, Panorama, DNS Security |
| Patch Management | Cadence, approval, emergency patch |
| Deception Layer | Canary tokens + honeypots |
| SecOps API Reference | Endpoints, incident lifecycle, known-good rules |
| Key Learnings | Hard-won gotchas — read before troubleshooting |
</div>