Intro:
In April 2025, NIST updated its primary guidance for cyber incident response plans (CIRPs), Special Publication 800-61 Revision 3. In 2023, the SEC also issued guidance on board cybersecurity oversight. Together, these developments significantly affect your current CIRP and your role as CISO.
Public companies are now required to disclose their cyber risks and their Board of Director (BOD) cybersecurity risk oversight in their Annual Reports (SEC 10-K). These Cybersecurity disclosures incur fiduciary / due diligence obligations. Should any of these efforts be deemed insufficient by regulators or private litigants, the organization could face significant consequences (e.g. litigation).[1]


The US NIST 800-61r3 requires your CIRP to be in alignment with these “strategic” (i.e. “material”) cyber risks amongst other changes discussed in the link below.[2]
- You have a “Tactical & Technical” CIRP
A quick Google search revealed the following: “The NIST [800-61] Revision 3 integrates incident response into broader cybersecurity risk management, emphasizing a strategic, ongoing, and business-aligned approach rather than a standalone technical lifecycle.”
If your current CIRP looks like either of the next 2 diagrams:


It now needs to look like this:

A far more detailed narrative is available at the link below[3].
- Your CIRP isn’t aligned with your Cyber Risks
Your BOD has told your shareholders that you are addressing cyber risks. Where does that manifest within your CIRP/InfoSec program? Your CIRP should have an explicit narrative that identifies and aligns with these disclosed risks and any other cyber risks listed in your Enterprise Risk Management (ERM) program. More information on this topic is available at the link below[4]. Below is an example Table of Contents of a CIRP with a Cyber Risk narrative:

- Your CIRP isn’t Actionable.
Imagine your 13 year old daughter asking you “Daddy, what goes into having a wedding?”. You are going to talk about the need for a church, a preacher, a venue for the party etc. Comprehensive and accurate. But when your now 23 year old daughter approaches you with fiancé in hand and says “Dad, it’s time for us to plan for a wedding”, you are going to have an “actionable” plan. You will have a date, the address of the exact location. Who will be in attendance, etc., Obviously CIRPs don’t have the luxury of knowing when their next incident will occur, but this is the level of detail we should strive for in a CIRP. At a minimum, every member of your Cyber Incident Response Team (CIRT) should be able to search the CIRP and read which requirements they are assigned to during an incident.
- Does your CIRP prepare you to stand at the head of the table and lead your organization through a cyber crisis?
Too many CISOs view their CIRP as merely an audit requirement that you can open during a crisis and be sufficiently informed of what to do. Or worse, they hope the CIRP will be a “checklist” of sorts. (I had a client ask for just a diagram…) A good CIRP is an artifact of the detailed process of reviewing/understanding everything necessary for you and your organization to be successful during a crisis. “If you can think it, you should write it.” The image below provides some idea of the scope that your CIRP should address. And don’t worry if it is too big. It’s like the User’s Manual of your car. You don’t read the whole thing to change a tire or a fuse. InfoSec and cars are complex. Your CIRP should be representative of this complexity.

- Your CIRP is not fully integrated with your Cyber Insurance
Today, Cyber Insurance is the 80% solution for most companies. Your BOD understands insurance and is expecting it to address some of the organization’s cybersecurity risks.
Cyber Insurance is a significant risk mitigation tool, but if it is executed improperly during a crisis, it can lead to denied claims which in turn exposes your organization to significant financial risk. It does your BOD no good to have a great insurance policy, only for you to “fumble” it during your Incident Response (IR) execution.
Cyber Insurance integration was a significant part of my “coaching” based approach over my last decade at Dell Secureworks where I focused solely on management level CIRPs & TTX’s. I would facilitate a conference call with the client (typically the CISO), their internal insurance manager, general counsel, their broker(s), and on very few occasions, the underwriter(s) would attend. The goal was for everyone on the call to make sure all the “dots were connected”. Don’t wait until a crisis emerges to figure this stuff out. It’s too late at that point.
I am not an insurance broker, nor a lawyer; I ask the same questions of every client as part of their CIRP development process. Here are just a few highlights from almost a DECADE of these cyber insurance integration conference calls:
- The one that has been mentioned the most of late is the application you give your customers for their phones. You didn’t develop it, but you put your name/brand on it. What is your exposure if your application gets infected and becomes a threat vector that negatively impacts your customers? Most clients with a customer app agree to discuss Tech E&O coverage after this call.
- I have had a handful of clients who ON THIS CALL discovered from their insurance broker that their upcoming cyber insurance renewal was predicated on them installing new technology (e.g. MFA, EDR, etc.).
- Make sure your internal insurance manager/risk management/CFO person knows they are “on the hook” for managing the insurance component (division of labor) during an incident. This task may extend beyond just the cyber policy (e.g. eCrime, bond, Tech E&O, etc.) This should be documented in your CIRP.
- Do you approve of the IR related vendors being provided/allowed by the policy? Don’t wait until you have an incident to figure this out.
- Are there any “other” vendors that will be invoicing you after an incident?
- Additional outside counsel may not be covered by the policy (e.g. Privacy, Industry / company expertise, the other “IR” – Investor Relations). AXA offers an endorsement for SEC (i.e. Materiality) support.
- Any Third party IT support that you will rely on during a crisis should be included in your coverage (in addition to the ‘typical’ support provided by these policies). You will need to pay their invoice(s) and if they are working 7×24, it will not be cheap. Insurance is primarily a financial risk mitigant. Make sure you understand the full scope of this exposure and ensure the insurance policy will cover it.
- Who will speak Japanese, in Japan, to the Japanese regulator/media, when you are most likely asleep, with the authority of the company? Many clients are expecting their cyber insurance to cover this (e.g. legal, PR). Make sure to talk this through. Especially if you already have established working relationships in country that understand your business.
- I developed containment plans for many of my clients. These were developed to be BOTH Proactive and Reactive (i.e. “Chasing Electrons”). For these clients, it was imperative that they had a “Voluntary Shut Down” endorsement within their policy.
- Other insurance topics your CIRP should include:
- Notification: calling the 800 number may not be enough.
- Expense Management: record keeping, invoices, etc.
- Payments: Bitcoin, Reimbursement policy implications, failure to obtain approvals is the leading cause of non-reimbursement, OFAC restrictions, etc.
- Betterment, Bricking, etc.
- Litigation: recent Attorney Client Privilege developments/application to IR, Common Interest Agreement/JDA, vicarious liability, etc.
- Decision Making: when you are an expense to the carrier(s) who is worried about their bottom line – Remember the Sting song: “when you find your servant is your master…”? A common TTX epiphany.
- Tabletop Exercise (TTX) with your carrier(s). You don’t want to be discussing this topic for the first time during an incident. Make sure you’ve TTX-ed your team prior. Should your performance be sub-par, it may impact your premiums. They may also want to look over your CIRP to get a better idea of your maturity/risk profile.
- Zywave offers a free newsletter “Cyber Digest – Front Page News” which covers cyber insurance. It provides CISO’s a more quantitative/financial perspective. I strongly recommend it for your Situational Awareness. It may also help you when you speak to your BOD. I’ve used it repeatedly with my BOD clients.
Additional information on this topic is available at the website below[5]
- The NIST 800-61r3 now requires “Detect” & Protect” narratives in the CIRP.
I believe this is an effort to drive additional transparency and accountability. The CIRP is an established (i.e. tangible) document that is required by every InfoSec framework out there. By incorporating these requirements into this primarily “Corrective” document (i.e. CIRP), NIST is now directing organizations to document their Preventative and Detective controls.


Let’s start with “Protect”. It is included in the “Preparation” section of the CIRP. I interpret this as a ‘high level’ narrative (especially for your BOD and ELT). I now include it with the Cyber Risk Narrative. Organizations should have a more detailed breakout (e.g. against the PCI DSS) referenced by the CIRP but maintained in a document that is specifically focused on the organization’s Preventative controls. Additionally, the logs provided by many of these Preventative controls should enable the organization to Detect an incident.
“Detect”:
As Illustrated above, Detect is in the “Incident Response” section of the CIRP and has a “higher priority with respect to incident response than “Protect”. The 800-61 r3, starting at Section 3.2 on page 23 requires detailed “DETECT” narratives to include:
“Anomalies” & “deviations from expected activity”
“Indicators of Compromise”
“Other potentially adverse events”
Detailed assignments/narratives for:
“Networks & network services”
“Physical environment”
“Personnel activity & technology usage”
“External Service Provider”
“Computing hardware and software, runtime environments, and their data”
“Information is correlated from multiple sources.”
Additional information is available at the link listed below[6].
If you have a “standalone technical lifecycle” CIRP, you will need to update if you intend to meet industry best practice/standards. I can help you.
I provide a FREE CIRP analysis. This is a “no brainer”.
[1] https://mccarthycyberreadiness.com/your-annual-report-may-be-your-biggest-cybersecurity-risk/
[2] https://mccarthycyberreadiness.com/why-the-us-nist-says-your-technical-tactical-cyber-incident-response-plan-cirp-is-now-insufficient/
[3] https://mccarthycyberreadiness.com/why-the-us-nist-says-your-technical-tactical-cyber-incident-response-plan-cirp-is-now-insufficient/
[4] https://mccarthycyberreadiness.com/your-annual-report-may-be-your-biggest-cybersecurity-risk/
[5] https://mccarthycyberreadiness.com/is-cyber-insurance-your-blind-spot/
[6] The Other Significant NIST change for CIRPs: Detect – McCarthy Cyber Readiness