Create or split a playbook when responders would face materially different declaration criteria, technology, authority, containment tradeoffs, evidence sources, provider dependencies, notification paths, or recovery methods. For example, a supplier-hosted ransomware event may require provider action and contract-specific communications that an internally hosted account compromise does not.
The playbook should tell responders when it starts, who leads, which actions each role may authorize, how the team prioritizes the incident, when to escalate or elevate it, what evidence to preserve, when recovery may begin, and who can declare recovery complete. It should also say when to switch to another playbook or invoke continuity, disaster recovery, crisis communication, or legal procedures.