4

Response Playbooks

SL-05

The signal chains that trigger automated containment. Each playbook names the signals that must line up, the response, and — critically — the outcome, because a playbook that ends in 'alert raised' has not actually prevented anything.

DischargesS.8(4)R.6S.6
Playbooks
4
Enabled
4
Total triggers
46
Triggered this month
4

Configured playbooks

Compromised user account7 triggerslast yesterday

An identity suddenly accesses large volumes of classified personal data outside its baseline.

Signal chain

  1. 1Access Assurance flags an anomalous authentication or volume spike
  2. 2Data Discovery confirms the sensitivity and consent scope of what was touched
  3. 3Database Activity Monitoring corroborates with query-level detail

Response

  • Terminate active sessions
  • Suspend the identity
  • Raise a SOC incident
  • Open a breach assessment
Outcome

Extraction is stopped before it becomes a reportable breach, or the reportable scope is materially reduced.

S.8(4)R.6S.8(6)
Insider data misuse14 triggerslast 4 days ago

A legitimate user accesses personal data outside the purpose assigned to their role.

Signal chain

  1. 1Classification indicates a high-risk category
  2. 2Behaviour deviates from the historical baseline
  3. 3No corresponding ticket or case reference exists

Response

  • Flag for investigation
  • Throttle further access
  • Notify the data owner
Outcome

The incident is identified before mass extraction rather than after it.

S.8(4)R.6
Privileged account abuse4 triggerslast 3 months ago

An administrator accesses unstructured repositories containing personal data with no operational reason.

Signal chain

  1. 1Rare behaviour for the privileged identity
  2. 2Data layer confirms regulated data is present
  3. 3Access falls outside any change window

Response

  • Immediate containment
  • Preserve the evidence chain
  • Revoke elevated access
Outcome

Chain of custody is preserved and the department's defensibility is maintained.

S.8(4)R.6
Consent withdrawal enforcement21 triggerslast 2 days ago

Consent is withdrawn, the data has not yet been erased, and an identity attempts to access it.

Signal chain

  1. 1Consent Manager records the withdrawal
  2. 2Discovery marks the affected elements as withdrawn
  3. 3An identity requests those elements

Response

  • Block the access
  • Log the attempt
  • Accelerate the erasure task
Outcome

Processing genuinely stops on withdrawal rather than waiting for the erasure batch — the difference between compliance and a grievance.

S.6S.8(7)

Why these four

They are the four scenarios where identity signals and data classification have to be read together to produce a correct answer. A compromised account looks identical to a busy analyst until you know the data it touched was classified. An insider looks identical to a diligent officer until you know the access fell outside the declared purpose. Consent-withdrawal enforcement in particular has no equivalent in a conventional security stack — it exists only because the Act creates the obligation.