Create and execute safe, authorized incident-response runbooks for owned systems, covering preparation, detection, analysis, containment, eradication, recovery, communications, and lessons learned.