SoK CIR-IF Taxonomy: What 417 Papers Say Drives Incident Response
Ask ten CISOs why their last incident spiralled and you get ten answers: stale runbook, missing log source, VP on holiday, procurement blocking the EDR renewal. All plausible, none systematic.
SoK CIR-IF Taxonomy: What 417 Papers Say Drives Incident Response
Ask ten CISOs why their last incident spiralled and you get ten answers: stale runbook, missing log source, VP on holiday, procurement blocking the EDR renewal. All plausible, none systematic. A July 2026 Systematization of Knowledge paper on arXiv, SoK: A Taxonomy for Cybersecurity Incident Response Influence Factors, finally puts a spine to that mess by proposing the CIR-IF Taxonomy — built from 417 academic and 40 non-scientific publications spanning 1999 through mid-2024.
What CIR-IF actually organizes
The taxonomy groups the drivers — technical, organizational, human, regulatory — that determine whether a team detects, contains, and recovers well. The authors benchmark it against seven established frameworks and against the elements in NIST SP 800-61r3, the 2025 revision that aligns incident handling with the NIST Cybersecurity Framework 2.0. The SoK’s conclusion is blunt: existing frameworks describe what to do; they under-specify what makes teams good at doing it.
That gap matters in Europe right now. Directive (EU) 2022/2555 (NIS2) obliges essential and important entities to report significant incidents within 24 hours of awareness, with an update at 72 hours. ENISA’s Threat Landscape 2024 documents a widening gap between reporting duty and reporting capability. A taxonomy of influence factors is the missing scaffold between “we have a plan” and “the plan actually holds under Article 23 pressure.”
Where the taxonomy pays off operationally
Read CIR-IF less as a checklist and more as a diagnostic lens for post-incident review. If your MTTR jumps 4x on a Tuesday, the taxonomy asks: was it detection tooling, decision authority, third-party dependency, or documentation debt? Same question, structured axes.
post_incident_review:
incident_id: INC-2026-0731-14
containment_minutes: 247
cir_if_axes:
technical: [edr_agent_stale_v9.2, siem_ingest_lag_18m]
organizational: [on_call_gap_02:00_04:00_CEST, no_dpo_reachable]
human: [analyst_L1_first_ransomware_case]
regulatory: [nis2_art23_early_warning_missed_by_9h]
frameworks_referenced: [NIST_SP_800-61r3, ENISA_CSIRT_Maturity]
The diagram below sketches how influence factors flow into the response outcome the regulator eventually reads:
Teams working on network intrusion detection without deep packet inspection will recognize the pattern: technical instrumentation is necessary, never sufficient. Regulatory exposure — increasingly the metric boards actually track — collapses when organizational authority is missing at 03:00 CEST. Our Lexnomia work on NIS2 mappings uses CIR-IF-adjacent categories to translate technical incident evidence into the language a national competent authority accepts under Regulation (EU) 2016/679 breach notification obligations.
Our reading
The value of a Systematization of Knowledge paper is not novelty; it is compression. CIR-IF gives buyers of incident response services a vocabulary to interrogate vendors past the “we do IR” pitch. At CAI Technology we already treat the four-axis lens as the scoring rubric in tabletop exercises — a maturity signal is when a client can name their weakest axis without prompting. If you want to see how we translate this into a 90-minute NIS2 tabletop, our AEGIS engagement page has the current format.