The first chapter of this section argued that UTIOM starts from management science, not tools. The second showed detection rebuilt as an engineering discipline. This chapter is about what happens after the alert — and why UTIOM refuses to treat it as an "after" at all.

Every security framework has a response chapter. It sits at the end, after detection, the way an ambulance sits at the bottom of a cliff. The org chart agrees: detection engineers over here, incident responders over there, a ticket queue between them, and a plan in a binder for the day something terrible happens.
UTIOM's doctrine takes that entire arrangement and inverts it with one law — the sixth of its seven:
"Operations is continuous response."
In UTIOM, response is not a phase that begins when detection ends. It is the SOC's permanent operating mode — the thing the whole system was built to do. Vision, strategy, crown jewels, visibility, detection: all of them are expressions of incident response at different distances from impact. Choosing what telemetry to collect is response, done years early. Writing a detection is response, done months early. Deciding tonight who may isolate a production server is response, done hours early. The incident is merely the moment all those earlier decisions are graded.
And there is a second model in the UTIOM family that does the grading. TID-CMM, from the previous chapter, asks: would you see it? Its sibling TIR-CMM — the Threat-Informed Response Capability Maturity Model — asks the question that makes CISOs shift in their chairs: could you act on it — inside the adversary's breakout window, with someone permitted to pull the trigger?
Because, in TIR-CMM's words: "A validated detection that fires into an organisation which cannot contain is a very expensive alarm."
Everything the previous chapter built can end exactly there. This chapter is about making sure it doesn't.
The Only Metric the Adversary Respects#
Boyd's OODA loop, from the opening chapter, said the faster decision cycle imposes the terms of the fight. TIR-CMM turns that philosophy into a single, unforgiving number — the containment margin:
breakout time − (time to detect + time to decide + time to contain)
Positive margin: you contained inside the adversary's window, and the incident is a story you tell. Negative margin: the adversary reached the next asset before your containment landed, and the incident is a story someone else tells about you. There is no partial credit, because the adversary gives none — a response slower than adversary tempo fails the model's Level 3 outright, however elegant the process behind it.

Figure — Containment margin turns response speed into an adversary-relative measure.
Inside that margin hides the term almost nobody measures. Aggregate MTTR blends everything into one forgiving average. TIR-CMM splits out MTTDecide — the time from a validated alert to someone authorizing containment — and calls the gap it exposes the most fixable failure in incident response. Organizations spend millions shaving minutes off detection, then lose hours waiting for a decision-maker who is asleep, in a meeting, or unsure they're allowed to say yes.
Which leads to the doctrine's sharpest observation about failed responses: "The playbook was never the constraint." The documents were fine. The permission was missing.
Decisions Move Left of the Incident#
The opening chapter introduced UTIOM's response horizon: leverage falls and cost rises as impact approaches, and the crossing point is the boundary between designing and reacting. Most organizations live to the right of it, making their hardest decisions at the exact moment those decisions are most expensive and least reversible — 3 a.m., adrenaline high, information low.
UTIOM's answer is to move the decisions left, into daylight, where they are cheap and powerful:
Containment authority, decided in advance. Who may isolate which systems, up to what blast radius, without convening anyone. On-call means authority is awake even when executives are not.
Isolation thresholds and business impact tiers, agreed with the business before any incident. Which crown jewels justify stopping revenue to save them — answered once, calmly, instead of debated during the breach.
Escalation paths and SLAs as engineered artifacts with owners and tests, not tribal knowledge.
TIR-CMM enforces the same principle mechanically: automation without pre-granted authorization scores as demonstration, not response. A SOAR platform that can isolate a host but must wait for a human chain of permission has automated the easy part and kept the bottleneck. The doctrine already told us why: decisions that should be made at design time otherwise get made during incidents instead — at maximum cost.
An Unrehearsed Playbook Is an Assumption#
UTIOM demands response as engineered workflow, not improvisation: playbooks aligned to the threat model, containment automated through SOAR, escalation defined, MTTR and MTTC tracked. TIR-CMM adds the constraint that keeps all of that honest — rehearsal. In its bluntest line:
"An unrehearsed playbook is an assumption wearing a document's clothing."
Under TIR-CMM's scoring rules, an untested playbook counts as an assumption, not a capability — its failures will surface exactly once, under maximum cost. This is the previous chapter's testing discipline, carried across the alert boundary: unit tests had effectuality tests; playbooks have exercises. A response capability that has never run against a simulated adversary is in precisely the same epistemic state as a detection that has never fired: unproven, and unprovable from the document alone.
The same evidence discipline applies to the score itself. Like its detection sibling, TIR-CMM caps what self-assessment can claim — a twenty-minute pulse check cannot assert what only evidence-led review can prove. Claimed capability and proven capability stay different numbers, on both sides of the alert.
Respond Like the Threat Model, Not Like the Template#
Generic incident response plans fail for the same reason generic detection fails: they are shaped like a standard, not like your organization. The threat-informed principle that scoped detection to 150–250 techniques in the previous chapter scopes response too.
TIR-CMM structures this as a containment lattice: response options mapped across attack-path stages and asset classes, scoped to your crown jewels — typically a few dozen cells that actually matter, instead of six hundred hypotheticals. For each cell, the question is concrete: at this stage, on this asset class, what can we actually do, who may do it, and how fast? A missing option on a crown jewel is not an acceptable gap; under the model's rules it is a violation of the threat-informed principle itself.

Figure — Response options scoped to the crown jewels, not to six hundred hypotheticals.
And the lattice's highest-leverage row is the one response frameworks usually ignore: prevention and hardening. The reasoning is pure UTIOM — "prevention buys the one thing response cannot manufacture, which is time." Every attack path pre-hardened is minutes added to your containment margin before any alert fires.
Learning Is the Final Deliverable#
The seventh law — "improvement is mandatory" — is where response stops being an ending and becomes an input. The doctrine is explicit: "Learning is the final deliverable of every incident." Not the report. Not the timeline. The learning.
Every incident and every exercise closes with a Kaizen review that feeds the whole chain upstream: the threat model gains a technique it had underweighted; visibility gains the log source whose absence hurt; detection gains the rule that would have fired earlier; a playbook loses the step that wasted eleven minutes; the containment margin gets recomputed against what the adversary actually did. Deming's cycle, from the opening chapter, turning at operational tempo.
This is the loop that separates a SOC that has ten years of experience from a SOC that has one year of experience ten times.
The Family, Complete#
Step back and the architecture of the UTIOM family becomes visible as one thread:

Figure — UTIOM defines the operating model; TID-CMM and TIR-CMM prove it.
UTIOM defines the operating model — how the whole lifecycle should work, from vision to improvement. TID-CMM measures the question would you see it? — and refuses to let visibility gaps or untested rules inflate the answer. TIR-CMM measures could you stop it? — and refuses to let unrehearsed playbooks or absent authority inflate that one. Detection maturity flows into response measurement as a constraint, because undetected threats cannot be countered; response reality flows back into strategy, because that is what continuous improvement means. Strategy and execution, traceable as two ends of the same thread — exactly the operating principle this section started with. All three are publicly available and free to use under their respective licence terms.
What distinguishes UTIOM is that it closes that loop. Most measure fragments; UTIOM connects the fragments and makes each one prove itself.
The quiet standard for the destination is worth repeating: well-designed security operations are not loud. They are deliberate, predictable, and boring. A SOC where the margin is positive, the authority is awake, the playbooks are rehearsed, and every incident makes the system smarter — that SOC has earned its boredom.
That is the third difference: UTIOM treats response not as the emergency at the end of the pipeline, but as the purpose the entire pipeline exists to serve.
Adineh, R. (2026). Response Is the Operating Mode, Not the Emergency. UTIOM Framework
Book, edition 1.2. utiom.de/book/response-is-operating-mode/