UNCLASSIFIED Roles and Accountabilities 23. In a cyber security emergency, the following roles need to be fulfilled. These roles reflect established best practice in cyber security incident management. It is often desirable for a single agency to have responsibility for all roles, but roles may be delegated. Most critical in an emergency is that a lead agency is quickly identified. Lead agency 24. The lead agency has overall responsibility for managing a cyber security emergency and is accountable to their Minister for overall performance. It is required to manage response and recovery; need to have overall situational awareness of all work streams; and will likely be required to provide regular briefings to Ministers, senior officials and other supporting entities. 25. The NSS Handbook (2016) prescribes NCSC as the lead agency for cyber emergencies. 26. The lead agency can be reassigned by the Cyber Emergency Coordination Group. Instances where a cyber security emergency may be led by other agencies include: • Where the primary victim of a cyber security emergency is a government agency or industry organisation that has the capability to respond appropriately. • The most significant impacts of the emergency are more appropriately dealt with by another organisation, such as the National Emergency Management Agency. A Cyber Security Emergency Controller 27. This role, if not performed by the lead agency, supports the lead agency coordinating the cyber security response and recovery activities. The cyber security emergency controller draws on access to technical specialists, partners resources and service provider relationships and involves oversight of all the aspects of the cyber security components of the emergency, including technical aspects of detection and analysis of malicious activity, as well as recommendations on containment and eradication. Service Owners 28. Service owners affected by a cyber security emergency will be involved in the response and will need to understand the impact of the cyber security emergency and make decisions regarding impact on service delivery. Technical Specialists 29. Experts play a critical role in understanding and responding to the cyber security components of the emergency. They will be required to restore and protect infrastructure that supports services impacted in a cyber security emergency. These may be public or private experts with the skills and capabilities to perform detection, disruption of cyber security threats as well as response; which includes the capability to deploy detection capabilities, perform analysis, that supports recommendations and measurement of the efficacy of containment, eradication and recovery of systems. Page 8 of 12 UNCLASSIFIED 8

Select target paragraph3