Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
framework

AI Security Operations Runbook.

A conventional breach has a perimeter you can reason about. An injection that succeeded in a retrieval pipeline may have touched one conversation or every conversation that retrieved the same document, and answering that is the investigation rather than the trigger. That asymmetry drives the central rule of this runbook: contain first, scope second. Every playbook is ordered accordingly, and every one carries a do-not column populated mostly with the instinct to establish scope before acting.

In depth

The Reported Incident Is A Sample, Not The Population.

01

What happens by default: the anomaly gets treated as a product bug.

It arrived as a support ticket, so scope is taken from the complaint, because one user noticed. The retrieval corpus gets cleaned to fix the problem, destroying the evidence that establishes reach. The agent gets restored with its original permissions because the immediate cause was a bad input. Legal is told it is probably nothing before the log review is complete. Each of those extends the incident, and several convert an internal fix into a notification obligation discovered late.

In shortEach of those extends the incident, and several conv…
02

What good response does: it declares on suspicion and downgrades on evidence.

The on-call engineer is told explicitly, and more than once, that downgrading two hours in is a good outcome rather than an embarrassment. Evidence is preserved before anything changes. The blast radius envelope, meaning what this system could reach, is established in minutes from the tool registry and credential scopes rather than waiting hours for actual scope. Legal is briefed on the envelope, because notification clocks in several statutes start at discovery rather than confirmation.

In shortLegal is briefed on the envelope, because notificati…
The detail

What Separates This From Your Existing Incident Plan.

Three differences change how the first hour runs. Each one is a place where the AI version of an incident diverges from the conventional one.

Zone · 01

Scope from telemetry

not the complaint

One user noticed, and the retrieval logs will usually show the same injected content reached many more sessions. The difference between those two numbers is the difference between an internal fix and a notification obligation. Every playbook scopes from logs, and the do-not column exists largely to interrupt the instinct to establish scope before containing.

Zone · 02

Three containment options

chosen in advance

Full disable for the highest severity or where you cannot characterise what the system is doing. Scope reduction where the affected path is narrow and identified. And degraded mode, where the model responds with tools and retrieval disabled, which is the option most teams lack and most need because it removes the argument that disabling the product is intolerable.

Zone · 03

The review ends in a control change

Seven post-incident questions, each with what a good answer produces. What architectural property made this possible, meaning a control plane rather than a person. Would the same technique work on another surface right now. What in the response was improvised, because every improvisation becomes a runbook entry or a pre-built capability.

By the numbers

The figures that make it a board-level conversation.

1 day
to build degraded mode, the capability most teams lack and cannot improvise
$6M
average cost of an AI-enabled malicious breach, against $4.99M across all breaches
20%
of shadow AI incidents involved a regulatory fine
Inside the report

What you'll take away.

01

Step 1 - Declare, then preserve before you change anything

Name a commander, open a timeline, and snapshot logs, assembled prompts, model and config versions and the tool registry as it stands, inside five minutes.

02

Step 2 - Contain, revoke and rotate

Disable tools, degrade the surface or pull it. Revoke every credential the system holds and any sharing its scope. Containment comes before scope, every time.

03

Step 3 - Establish the envelope, then brief legal

What could this reach, from the tool registry and credential scopes, in minutes. Brief legal on the envelope, because notification clocks start at discovery rather than confirmation.

04

Step 4 - Close the loop with a control change

Every review ends with a control added, a scope narrowed, a detection created, a runbook entry written or a decision formally made and tested. A write-up alone is not finished.

Questions

Frequently asked.

What do we do in the first hour of an AI security incident?

Declare and name a commander. Preserve evidence before changing anything. Contain by disabling tools, degrading the surface or pulling it. Revoke and rotate any credential the system holds. Establish the blast radius envelope from the tool registry rather than waiting for actual scope. Notify legal if the envelope includes personal or customer data. Then check other surfaces for recurrence.

How do we scope a prompt injection incident?

From the retrieval logs, never the complaint. Search the corpus for instruction-shaped text near the affected retrievals, identify the ingestion path, then enumerate every session that retrieved the affected content. Then examine what those sessions did next: tool calls, fetches, and what was returned to whom.

When do we have to notify customers or a regulator?

Legal owns that decision and that channel, and triggers vary by jurisdiction, sector and contract. What the runbook does is get legal the inputs early: discovery time, data classes, record counts, affected parties and jurisdictions. Notification clocks in several statutes start at discovery rather than confirmation.

An agent did something it should not have. What first?

Stop it, with an emergency stop if you have one and credential revocation if you do not. Do not pause and observe, because an acting agent is an expanding incident. Revoke every credential it holds and any sharing its scope. Snapshot the action audit trail and tool configuration before a deploy overwrites them, then reconstruct forward from the trigger.

What is degraded mode and why does it matter?

The model still responds but with tools disabled, retrieval disabled and a restricted capability set. Without it your only containment options are full disable or nothing, and that argument gets had under pressure with a product manager in the room. It costs roughly a day per surface to build and cannot be improvised.

Our provider changed something and evaluations started failing. Is that an incident?

Treat it as one until characterised. Pin to the previous version if pinning is available, and degrade the surface if it is not. Run your evaluation and security regression suites against the new version immediately rather than relying on release notes. Then identify which controls depended on the previous behaviour, because format changes break validators.

Get the framework

Have it emailed to you.

Drop your details and we'll send AI Security Operations Runbook straight to your inbox - no spam, unsubscribe anytime.

Download framework
Next step

Build degraded mode before you need it.

It costs about a day per surface and cannot be improvised mid-incident. Work through your containment options with our engineering leads. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions

Talk to our engineers