Shared Incident Response Responsibilities
Your IR Plan Works for Your Environment. The Breach Is in Theirs.
6 min read · 22 May 2026 · Security
A financial services firm's information security team had a comprehensive incident response plan , developed by an experienced CISO, tested through annual tabletop exercises, and aligned to NIST SP 800-61. When their core banking platform vendor disclosed a security breach involving customer account data, the firm's IR team activated their plan. Within thirty minutes they had convened the incident response team, initiated the internal communication tree, and begun the regulatory notification assessment. Then the plan's limitations became apparent. Every action item in the first hour of the plan assumed access to the affected systems , forensic image collection, log analysis, network traffic review, and containment actions. All of those systems were in the vendor's environment. The firm had no direct access to any of them. They sent an email to the vendor's account manager requesting access to forensic evidence. They received an out-of-office reply. They called the vendor's support line and were placed in a standard support queue. Forty minutes into their IR plan activation, the firm had executed every action item they were capable of performing and was waiting for a vendor callback. The vendor, meanwhile, was running their own IR plan , which did not include a defined integration point with the customer's response team.
What are Shared Incident Response Responsibilities, Really?
Shared incident response in vendor relationships is the coordination between a customer's security operations team and a vendor's security operations team during a security incident that affects both parties , specifically incidents where the breach occurred in the vendor's environment but affects the customer's data, systems, or customers. Shared IR is not simply the customer following their IR plan and the vendor following theirs in parallel , it requires pre-defined coordination mechanisms that establish who leads which response activities, how evidence is shared, who communicates with external parties including regulators, and how decisions are made when the interests of the two parties may diverge.
The environment control problem is the fundamental challenge. In most security incidents that affect a customer through a vendor, the forensic evidence, affected systems, and response capabilities reside in the vendor's environment. The customer can run their own internal response procedures , convene the team, assess regulatory obligations, prepare customer communications , but cannot directly execute the forensic investigation, containment actions, or eradication activities. These actions require the vendor's IR team to execute them, ideally in coordination with the customer's requirements and timeline rather than solely according to the vendor's own priorities.
Decision authority ambiguity is the specific coordination failure that shared IR planning must address in advance. During an active incident, questions arise that require decisions by specific authority: should the affected systems be taken offline immediately, accepting service disruption to prevent further data access? Should forensic images be preserved before system restoration, delaying recovery in favour of investigation completeness? Should the customer's regulatory team receive raw investigation findings or only vendor-prepared summaries? In the absence of pre-defined decision authority, these questions are resolved through improvised negotiation during the incident , consuming time and creating friction between parties whose interests may not be fully aligned.
- No joint IR plan , customer and vendor IR plans not coordinated before an incident
- Customer IR plan not accounting for vendor environment access limitations
- Evidence access not pre-negotiated , forensic access procedures not defined before incident
- Decision authority ambiguity , who decides on containment, evidence preservation, and communication
- Vendor escalation path not tested , emergency contact during incident not established before needed
Why this matters
Shared incident response matters for TPRM because the quality of the customer's response to a vendor breach is directly constrained by how effectively the vendor's IR team cooperates with the customer's response requirements. An uncoordinated vendor IR team that prioritises its own investigation timeline, delays evidence sharing pending legal review, or makes containment decisions without customer consultation can significantly extend the customer's effective exposure and impair their regulatory compliance.
The forensic evidence access problem is particularly acute. Legal proceedings, regulatory examinations, and insurance claims arising from vendor breaches frequently require forensic evidence from the vendor's environment. Evidence that is not properly preserved, or that the customer cannot obtain access to during the response, may not be available when needed for legal or regulatory purposes. Joint IR planning that defines evidence preservation obligations and customer access rights to forensic artefacts in advance of incidents protects the customer's legal and regulatory position.
Where most teams get this wrong
The most consistent failure is not having a vendor-specific IR plan component that addresses the coordination requirements. Generic IR plans that cover vendor breach scenarios describe the customer's internal response actions without defining the integration points with the vendor's response team.
- No vendor-specific IR component in customer's IR plan
- Emergency escalation contacts not established before incident
- Evidence access rights not contractualised
- Joint IR plan not developed or tested with critical vendors
- Tabletop exercises not including vendor IR coordination
What good looks like
Mature shared IR programmes develop joint incident response plans with critical vendors , specifically defining emergency escalation contacts, evidence access procedures, decision authority allocation, and communication roles before any incident occurs.
- Joint IR plan for critical vendors , coordination procedures established before incidents
- Emergency escalation contact , named individual at vendor reachable outside business hours
- Evidence access rights contractualised , forensic image access, log access, and investigation cooperation defined
- Decision authority allocated , who decides on containment, eradication, and communication
- Annual joint tabletop , coordinated IR exercise with vendor participation
Tooling
IR Management , PagerDuty, Jira Service Management, ServiceNow Security Incident Response
Incident response management platforms provide the workflow structure for coordinating responses across organisational boundaries , shared incident tickets, communication logs, and evidence tracking. For TPRM practitioners, establishing shared IR workspace access with critical vendors before incidents provides the coordination infrastructure that ad-hoc communication cannot match during a live incident.
Joint Playbook Development , NIST SP 800-61 Appendix B
NIST SP 800-61 includes guidance on information sharing and coordination in multi-party incident response scenarios. Joint IR playbooks developed from this framework provide a shared vocabulary and process structure that reduces the friction of real-time coordination during incidents.
Governance challenges
The governance challenge with shared IR is vendor engagement. Developing joint IR plans requires vendor participation , their time, their legal review of coordination procedures, and their willingness to define evidence access rights contractually. Large vendors with many customers may resist bespoke joint IR planning as operationally impractical. The governance resolution is tiered engagement , comprehensive joint IR planning for the most critical vendor relationships, standardised joint procedures for second-tier relationships.
- Develop vendor-specific IR plan component for Tier 1 vendors
- Establish emergency escalation contact , named individual, tested before incident
- Contractualise evidence access rights , forensic image access, log sharing, investigation cooperation
- Conduct annual joint tabletop with critical vendor participation
- Test escalation path , validate emergency contact before an incident requires it
If you are a small team
For your highest-risk vendor, establish one thing before anything else: the emergency escalation contact , the specific individual at the vendor who would answer an urgent call at 9pm on a Tuesday night about a breach affecting your data. That name and number, tested with a quick introductory call, is the most important single element of shared IR preparedness. Without it, your first action in a vendor breach scenario is finding someone at the vendor who can actually help , which may take hours.
- Establish emergency escalation contact at each critical vendor , tested before incident
- Negotiate preliminary evidence access rights in DPA or security addendum
- Develop vendor-specific appendix to IR plan covering coordination procedures
- Conduct annual joint tabletop with at least one critical vendor
What to require
Ask directly:
"If a breach affecting our data were discovered at 9pm on a Friday, who specifically would we call, what is their direct number, and what authority do they have to make decisions about evidence preservation and containment on our behalf?"
Expect as evidence
- Named emergency IR contact with direct contact information
- Authority scope , what decisions they can make without escalation
- Evidence sharing commitment , what forensic access customer has rights to
- Joint IR plan or defined coordination procedure
A vendor with a mature IR plan should be able to answer the 9pm Friday question with a name and a number. The plan is the structure. The contact is the access.
How to evidence it
- Joint IR plan documentation
- Emergency escalation contact records
- Evidence access rights contractual documentation
- Joint tabletop exercise records
Key Takeaway
Your IR plan was designed for your environment. The breach is in theirs. Your first hour of response can be executed from your side of the relationship. Everything that requires vendor cooperation , forensic evidence, system access, containment decisions, investigation findings , requires a coordination mechanism that was either designed before the incident or improvised during it. Design it before. Establish the emergency contact. Contractualise the evidence access. Run the joint tabletop. The plan works for your environment. The coordination makes it work for theirs.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association