A comprehensive guide for recognizing, managing, and resolving critical incidents across operations, communications, cyber, and security domains.
Every incident begins with recognition. Each team must ask four critical questions to determine if an incident declaration is necessary. If two or more answers are "yes," you must immediately declare an incident and activate the response process.
Is something happening that is unexpected or unsafe?
Are systems, people, or processes behaving in a way that staff cannot explain?
Is normal communication failing or unreliable?
Do you need more information than you currently have to confirm safety?
Once an incident is declared, specific team leads must immediately contact designated personnel. Speed and clarity in these initial communications are essential to effective incident response.
Contacts all operational supervisors
Contacts the Executive Duty Officer
Contacts IT on-call or technical support
Contacts security dispatch or local emergency partners
Alerts all team leads and activates the response process
Before addressing technical or operational problems, the absolute priority is ensuring people are safe. Each team has specific responsibilities to protect staff, passengers, and stakeholders during the critical early moments of an incident.
With people stabilized, teams now act decisively to stop the issue from spreading. Containment prevents escalation and creates the conditions necessary for safe restoration of normal operations.
Restoration focuses on bringing systems, people, and communication back online slowly and safely. Rushing this phase can trigger new problems or reintroduce vulnerabilities. Each team follows a methodical approach to ensure stability.
Confirm the accuracy of operational information before resuming normal workflows. Gradually restore paused services and report any abnormalities immediately.
Release a clear, approved public message once the Incident Commander authorizes it. Resume normal communication channels cautiously and track public or media reactions.
Validate system integrity and ensure no unauthorized access or lingering issues. Restore automated functions one at a time.
Document evidence relevant to the incident and continue monitoring until operations are fully stable.
Once operations are restored, the Incident Commander leads a structured review to capture lessons learned and identify improvements. This critical phase transforms experience into organizational knowledge and strengthens future response capabilities.
What was the first sign something was wrong?
What actions worked well?
What created delays or confusion?
What resources or information were missing?
What improvements should be made for next time?
Each team lead—Operations, Communications, Cyber, and Security—provides a summary to the Incident Commander. The Communications Lead then prepares a short after-action summary for leadership.
The Incident Commander serves as the central authority throughout the response process, coordinating all teams and making critical decisions that affect safety, operations, and public communication.
Alerts all teams at incident declaration and ensures coordinated response across all domains.
Approves containment and restoration steps, ensuring actions align with overall incident strategy.
Authorizes any public messaging to ensure consistency and accuracy in external communications.
Each team lead maintains specific contact paths and focuses on distinct aspects of incident response. Clear delineation of responsibilities ensures comprehensive coverage without duplication of effort.
Contact: Station managers, supervisors, dispatchers
Focus: Safety, crowd/manual control, service continuity
Contact: Executives, city partners, media (when approved)
Focus: Consistent internal and external messaging
Contact: IT support, vendor support, system administrators
Focus: System integrity, technical containment
Contact: Transit security, police liaison, emergency partners
Focus: Physical safety, access issues, investigative support
The STS Incident Response Playbook provides a structured, five-step approach to managing critical incidents. From initial recognition through post-incident review, each phase builds on the previous one to ensure comprehensive incident management.
Recognize and Declare
Stabilize People First
Contain the Problem
Restore Operations
Post-Incident Review
Remember: Effective incident response prioritizes people first, contains problems systematically, and learns from every experience to strengthen future capabilities.
siberX Transit Systems Incident Response Playbook