Incident Response
Playbook v1.0 · August 2026
Humanitarian Operations

Incident Response
Playbook

Strengthening Cybersecurity Awareness and Incident Response Capacity for Humanitarian Operations.

Immediate Response Protocol

STOP
Stop interacting
PRESERVE
Keep evidence
DISCONNECT
If device is affected
REPORT
Use official channel

Threat Landscape

Humanitarian teams face these common incident categories. Know how to identify and report each.

P
PHISHING
Suspicious links, attachments, impersonation, payment or password requests.
C
CREDENTIALS
Unexpected MFA prompts, unusual sign-ins, password compromise.
M
MALWARE
Pop-ups, system slowdown, antivirus alerts, ransomware symptoms.
D
DATA
Wrong recipient, external sharing, personal cloud uploads.
D
DEVICE
Lost, stolen or unattended laptop, phone or tablet.
N
NETWORK
Fake Wi-Fi, VPN issues, tailgating or unusual questions.

Quick Reference

When in doubt, report. It is better to report a non-incident than ignore a real one.

If this happens
Do this first
Suspicious email
Do not click. Preserve the email. Report it.
Clicked a suspicious link
Disconnect Wi-Fi and call ICT immediately.
Entered password
Report immediately, change password if instructed, ICT revokes sessions.
Unexpected MFA prompt
Do not approve. Capture screenshot if possible. Report immediately.
Malware warning
Disconnect from network. Do not shut down unless instructed. Report to ICT.
Lost device
Report immediately with device type, asset tag, time and location.
Wrong data recipient
Report immediately. Do not delete evidence. Alert Data Protection.
Final reminder: When in doubt, report. It is better to report a non-incident than ignore a real incident.

Explore the Playbook

Strengthening Cybersecurity Awareness and Incident Response Capacity for Humanitarian Operations · Version 1.0 · August 2026