| Covers malware only, not identity or cloud |
Written when endpoint malware was the primary threat |
Add explicit identity and cloud/SaaS containment branches |
| No backup decision owner |
Assumes the primary owner is always reachable |
Two-deep on-call rotation with clear handoff rules |
| Containment needs change-management approval |
Written by IT operations without incident exceptions |
Pre-negotiate emergency exceptions during preparation |
| Communications plan never rehearsed |
Treated as a document, not an operational exercise |
Tabletop exercises that include legal and communications |
| No evidence step before eradication |
Pressure to restore operations fast |
Make preservation a mandatory, timed checkpoint |
| Automation thresholds undefined |
Fear of automating the wrong thing |
Apply the reversibility and blast-radius test to every action |
| Plan reviewed only after an incident |
No standing review cadence |
Tie reviews to framework updates and every tabletop |