| Incident response plan and playbooks | Define triggers, stages, roles, escalation and required records. | Security, data, privacy, risk and operations |
| Severity and materiality model | Support consistent prioritisation using business and data impact. | Incident leadership and executives |
| Data impact assessment | Document affected data, systems, subjects, jurisdictions and uncertainty. | Privacy, legal, data owners and risk |
| Evidence register and chronology | Maintain a controlled record of facts, sources, assumptions and events. | Responders, counsel, audit and insurers |
| Decision and notification support pack | Present relevant facts for authorised notification and communication decisions. | Legal, privacy, communications and executives |
| Recovery acceptance criteria | Define how integrity, access, availability and residual risk are validated. | Technology, business owners and assurance |
| Lessons-learned and remediation backlog | Assign corrective actions, priorities, owners, evidence and closure criteria. | Executive sponsors, risk and delivery teams |