Governance, risk and compliance

SmartSuite for the Incident Response Manager

The Incident Response Manager coordinates major security incident and breach response: playbooks, activation, cross-functional actions, evidence preservation, regulatory and customer notification decisions and the post-incident review. They keep execution consistent and communication timely when a breach is live.

What you own

  • Maintain the incident response plan and playbooks for high-priority incidents and breaches
  • Lead response activation, coordination and cross-functional task tracking
  • Preserve evidence and maintain the incident timeline and decision log
  • Coordinate breach notification decisions with privacy, legal and communications
  • Run post-incident reviews and own root cause and improvement actions
  • Exercise the response team and report readiness and incident metrics

Where the role sits

Each name opens that role's page.

Reports to

Chief Information Security Officer

Chief Information Security Officer

See the role

Direct reports

Works closely with

Security Operations Manager

Security Operations Manager

See the role
Crisis Management Lead

Crisis Management Lead

See the role
Data Protection Officer

Data Protection Officer

See the role
Communications Director

Communications Director

See the role
Incident and Problem Manager

Incident and Problem Manager

See the role
IT Risk Manager

IT Risk Manager

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

resilience

Touches

contributes or approves

privacy, risk, third-party, issues-actions, reporting

Depends on

consumes its output

compliance, policy

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

How they use the Cyber & IT Risk suite

Response playbooks

Launches structured workflows for high-priority incidents and breaches.

Real-time collaboration

Tracks cross-functional actions during active investigations.

Post-incident reviews

Documents lessons learned, root causes, and improvement actions.

Suites that serve this role

How SmartSuite supports this role

Operational resilience. Launches structured response workflows for high-priority incidents and breaches and tracks cross-functional actions in real time.

Privacy. Links security incidents to privacy impact assessments and breach notification workflows so the privacy clock is visible.

Risk management. Connects incidents to the IT and cyber risks they realise and updates exposure after the event.

Third-party risk. Records vendor-originated incidents against the vendor and triggers reassessment.

Issues and actions. Documents lessons learned, root causes and improvement actions from post-incident reviews and tracks them to closure.

Reporting. Reports incident volumes, time to contain and open actions to the CISO and committees.

Industry reference

NIST SP 800-61 Rev. 3 (2025), ISO/IEC 27035 and NIST CSF 2.0's Respond and Recover functions define the response lifecycle: preparation, detection, containment, eradication, recovery and lessons learned. PCI DSS Requirement 12.10 requires a tested plan where card data is involved.

Notification law sets the deadlines. GDPR requires supervisory authority notification within 72 hours; HIPAA's Breach Notification Rule allows 60 days; SEC registrants disclose material incidents within four business days; US banks notify regulators within 36 hours; NYDFS requires notice within 72 hours; DORA and NIS2 impose staged reporting from 24 hours; US federal agencies report to CISA within one hour.

In their words

Related roles

Chief Information Security Officer

Chief Information Security Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.