CAI Technology
Menu ☰
aegis · · 3 min read

SoK CIR-IF Taxonomy: What 417 Papers Say Drives Incident Response

Ask ten CISOs why their last incident spiralled and you get ten answers: stale runbook, missing log source, VP on holiday, procurement blocking the EDR renewal. All plausible, none systematic.

CAI Technology · Last reviewed: 7/4/2026
Clean abstract particle-tree visualization on layered translucent sheets with cyan-to-magenta palette, no text, no logos, no anatomy issues. Tree/taxonomy metaphor fits an inc

SoK CIR-IF Taxonomy: What 417 Papers Say Drives Incident Response

Ask ten CISOs why their last incident spiralled and you get ten answers: stale runbook, missing log source, VP on holiday, procurement blocking the EDR renewal. All plausible, none systematic. A July 2026 Systematization of Knowledge paper on arXiv, SoK: A Taxonomy for Cybersecurity Incident Response Influence Factors, finally puts a spine to that mess by proposing the CIR-IF Taxonomy — built from 417 academic and 40 non-scientific publications spanning 1999 through mid-2024.

What CIR-IF actually organizes

The taxonomy groups the drivers — technical, organizational, human, regulatory — that determine whether a team detects, contains, and recovers well. The authors benchmark it against seven established frameworks and against the elements in NIST SP 800-61r3, the 2025 revision that aligns incident handling with the NIST Cybersecurity Framework 2.0. The SoK’s conclusion is blunt: existing frameworks describe what to do; they under-specify what makes teams good at doing it.

That gap matters in Europe right now. Directive (EU) 2022/2555 (NIS2) obliges essential and important entities to report significant incidents within 24 hours of awareness, with an update at 72 hours. ENISA’s Threat Landscape 2024 documents a widening gap between reporting duty and reporting capability. A taxonomy of influence factors is the missing scaffold between “we have a plan” and “the plan actually holds under Article 23 pressure.”

Where the taxonomy pays off operationally

Read CIR-IF less as a checklist and more as a diagnostic lens for post-incident review. If your MTTR jumps 4x on a Tuesday, the taxonomy asks: was it detection tooling, decision authority, third-party dependency, or documentation debt? Same question, structured axes.

post_incident_review:
  incident_id: INC-2026-0731-14
  containment_minutes: 247
  cir_if_axes:
    technical:     [edr_agent_stale_v9.2, siem_ingest_lag_18m]
    organizational: [on_call_gap_02:00_04:00_CEST, no_dpo_reachable]
    human:         [analyst_L1_first_ransomware_case]
    regulatory:    [nis2_art23_early_warning_missed_by_9h]
  frameworks_referenced: [NIST_SP_800-61r3, ENISA_CSIRT_Maturity]

The diagram below sketches how influence factors flow into the response outcome the regulator eventually reads:

flowchart LR A[Alert lands in SIEM] --> B{Technical factors: telemetry complete?} B -->|yes| C{Organizational: on-call authority present?} B -->|no| X[Detection debt — extend MTTD] C -->|yes| D{Human: analyst experience match?} C -->|no| Y[Escalation stall] D -->|yes| E[Contained within NIS2 24h window] D -->|no| Z[Regulatory exposure Art. 23] classDef good fill:#dcfce7,stroke:#10b981 classDef bad fill:#fee2e2,stroke:#ef4444 class E good class X,Y,Z bad

Teams working on network intrusion detection without deep packet inspection will recognize the pattern: technical instrumentation is necessary, never sufficient. Regulatory exposure — increasingly the metric boards actually track — collapses when organizational authority is missing at 03:00 CEST. Our Lexnomia work on NIS2 mappings uses CIR-IF-adjacent categories to translate technical incident evidence into the language a national competent authority accepts under Regulation (EU) 2016/679 breach notification obligations.

Our reading

The value of a Systematization of Knowledge paper is not novelty; it is compression. CIR-IF gives buyers of incident response services a vocabulary to interrogate vendors past the “we do IR” pitch. At CAI Technology we already treat the four-axis lens as the scoring rubric in tabletop exercises — a maturity signal is when a client can name their weakest axis without prompting. If you want to see how we translate this into a 90-minute NIS2 tabletop, our AEGIS engagement page has the current format.

Read further

We start with a 30-minute conversation.

Free AI-readiness audit for companies with 50+ employees. We reply within 24 hours.