A full real-project case study: building a complete incident response plan for a mid-size enterprise, from playbooks through post-incident review.
This third case study takes Module 10's incident-response lifecycle and Module 13's monitoring/detection concepts and builds them into a complete, usable incident response plan for a mid-size enterprise — the kind of deliverable an organization actually needs on file before an incident, not during one. The project works through defining incident severity tiers, writing playbooks for the most likely incident types (ransomware, business email compromise, insider threat), and structuring the post-incident review process so lessons learned actually change the next iteration of the plan.
This project assumes the concepts from Modules 10 and 13 and produces the single most commonly audited cybersecurity-governance artifact in this entire program — most compliance frameworks, including NIST CSF and NERC CIP, explicitly require a documented, tested incident response plan.