Phishing Incident Response Playbook
Purpose Provides a structured approach for detecting, analyzing, containing, eradicating, and recovering from phishing attacks while minimizing business impact and reducing cyber risk.
Objectives * Detect phishing attempts rapidly * Protect users, credentials, and organizational assets * Reduce the risk of account compromise and malware infection * Ensure timely containment and response * Improve security awareness and organizational resilience
Scope This playbook applies to: * Email phishing * Spear phishing * Business Email Compromise (BEC) * Credential harvesting attacks * Malicious links and attachments * Social engineering campaigns
Roles and Responsibilities SOC Team * Monitor and detect phishing activities * Perform triage and investigation * Execute containment actions
Incident Response Team * Lead incident handling and remediation * Coordinate technical response activities
IT Operations * Implement containment and recovery actions * Support endpoint, email, and identity remediation
Information Security Manager / CISO * Provide governance and oversight * Approve critical response actions * Coordinate stakeholder communication and reporting
Response Process
1. Detection * User-reported suspicious emails * Secure Email Gateway alerts * SIEM correlation rules * Threat intelligence indicators
2. Triage & Analysis * Validate phishing indicators * Identify affected users * Assess business impact * Determine attack type and severity
3. Containment * Block sender, domain, and URLs * Quarantine malicious emails * Disable compromised accounts * Reset affected credentials * Isolate impacted endpoints if required
4. Eradication * Remove malicious artifacts * Revoke unauthorized sessions * Eliminate persistence mechanisms * Update detection controls
5. Recovery * Restore normal business operations * Monitor affected accounts and systems * Verify effectiveness of remediation
6. Lessons Learned * Conduct post-incident review * Identify control gaps * Update detection use cases * Improve awareness training * Enhance phishing prevention controls
Key Metrics * Mean Time to Detect (MTTD) * Mean Time to Respond (MTTR) * Number of affected users * Credential compromise rate * Phishing reporting rate * Recurrence of similar incidents
Continuous Improvement Regular testing, phishing simulations, threat intelligence integration, and user awareness programs shall be conducted to strengthen organizational resilience against phishing threats.
— CISO as a Service — Strategic Cyber Defense & GRC Resilient Through Knowledge 2026.06.05
https://www.linkedin.com/posts/alirezaghahrood_phishing-incident-runbook-2026-activity-7468597554776121344-NsGR