ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Runbook · Post-incident
RB-POST-003

DDoS Resilience Improvement

1. Prerequisites

Before starting this runbook, ensure the following:

  • DDoS incident has been resolved
  • Service restoration activities have been completed
  • Incident timeline has been documented
  • Relevant stakeholders are available
  • Technical evidence has been preserved
  • Incident ticket remains active
  • Post-incident review has been scheduled

2. Step-by-Step Instructions

  1. Conduct Post-Incident Review

    Review:

    • Incident timeline
    • Detection timeline
    • Escalation timeline
    • Mitigation timeline
    • Recovery timeline
    • Communications timeline

    Identify:

    • What worked well
    • What did not work well
    • Areas for improvement

    Document findings.

  2. Assess Detection Effectiveness

    Review:

    • Alert generation
    • Alert quality
    • Alert timing
    • Monitoring coverage
    • Escalation effectiveness

    Determine:

    • Detection gaps
    • Visibility gaps
    • Alert tuning opportunities

    Document findings.

  3. Assess Mitigation Effectiveness

    Review:

    • CDN protections
    • WAF protections
    • DDoS mitigation services
    • ISP support
    • Traffic filtering controls
    • Rate limiting controls

    Determine:

    • Controls that were effective
    • Controls that were ineffective
    • Additional controls required

    Document findings.

  4. Review Infrastructure Resilience

    Assess:

    • Network capacity
    • Load balancer capacity
    • Cloud scaling effectiveness
    • CDN performance
    • Application resilience
    • Service redundancy
    • Geographic resilience

    Identify infrastructure improvements.

    Document findings.

  5. Review Provider Performance

    Assess:

    • CDN provider response
    • Cloud provider response
    • ISP support effectiveness
    • DDoS provider effectiveness
    • Third-party response times

    Identify:

    • Vendor strengths
    • Vendor weaknesses
    • Contractual improvement opportunities

    Document findings.

  6. Review Business Impact

    Assess:

    • Customer impact
    • Revenue impact
    • Operational disruption
    • SLA impact
    • Reputational impact
    • Executive impact

    Document business consequences.

    Identify opportunities to reduce future impact.

  7. Identify Security Improvements

    Review opportunities to improve:

    • DDoS detection
    • Traffic visibility
    • Threat intelligence integration
    • Network segmentation
    • WAF protections
    • Bot management
    • Incident response procedures

    Document recommendations.

  8. Update Documentation

    Review and update:

    • Playbooks
    • Runbooks
    • SOPs
    • Escalation procedures
    • Contact lists
    • Architecture documentation

    Ensure documentation reflects lessons learned.

    Document updates performed.

  9. Create Improvement Plan

    Develop an action plan containing:

    • Improvement activities
    • Owners
    • Priority levels
    • Due dates
    • Success criteria

    Track actions through completion.

    Document the plan.

  10. Update Incident Record

    Record:

    • Review findings
    • Detection improvements
    • Mitigation improvements
    • Infrastructure improvements
    • Vendor observations
    • Documentation updates
    • Improvement plan

    Attach supporting evidence.

3. Post-Action

Upon completion:

  • Ensure post-incident review findings are documented
  • Ensure improvement opportunities are identified
  • Ensure documentation updates are completed
  • Ensure action items have owners assigned
  • Ensure supporting evidence is attached
  • Ensure incident ticket is updated or formally closed

Contributor

Vishal Thakur GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.