Humanitarian Operations
Incident Response
Playbook
Strengthening Cybersecurity Awareness and Incident Response Capacity for Humanitarian Operations.
Immediate Response Protocol
STOP
Stop interacting
PRESERVE
Keep evidence
DISCONNECT
If device is affected
REPORT
Use official channel
Threat Landscape
Humanitarian teams face these common incident categories. Know how to identify and report each.
P
PHISHING
Suspicious links, attachments, impersonation, payment or password requests.
C
CREDENTIALS
Unexpected MFA prompts, unusual sign-ins, password compromise.
M
MALWARE
Pop-ups, system slowdown, antivirus alerts, ransomware symptoms.
D
DATA
Wrong recipient, external sharing, personal cloud uploads.
D
DEVICE
Lost, stolen or unattended laptop, phone or tablet.
N
NETWORK
Fake Wi-Fi, VPN issues, tailgating or unusual questions.
Quick Reference
When in doubt, report. It is better to report a non-incident than ignore a real one.
If this happens
Do this first
Suspicious email
Do not click. Preserve the email. Report it.
Clicked a suspicious link
Disconnect Wi-Fi and call ICT immediately.
Entered password
Report immediately, change password if instructed, ICT revokes sessions.
Unexpected MFA prompt
Do not approve. Capture screenshot if possible. Report immediately.
Malware warning
Disconnect from network. Do not shut down unless instructed. Report to ICT.
Lost device
Report immediately with device type, asset tag, time and location.
Wrong data recipient
Report immediately. Do not delete evidence. Alert Data Protection.
Final reminder: When in doubt, report. It is better to report a non-incident than ignore a real incident.