Tactic-to-Response Playbook¶
Response protocol — instantiates Attenuated Threat Inoculation
An if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing "this is manufactured urgency" comes pre-linked to a rehearsed response.
A Tactic-to-Response Playbook pairs, for each tactic in a threat family, the recognition cue — how you spot manufactured urgency, borrowed authority, phantom scarcity — with a specific, pre-decided counter-move: so you slow down, verify on a known channel, escalate. The one idea that makes it this mechanism: it welds recognition to response, so its unit is the tactic → counter-move pair. Spotting the tactic already carries the reaction, instead of leaving a defender to invent one under pressure. That separates it from the Manipulation Tactic Labeling Card, which names the tactic but stops at recognition, and from the Refutation Script Library, which stores argument content ("why the claim is false") rather than behavioral moves ("what to do when you see the tactic").
Example¶
A bank equips its fraud-line agents with a tactic-to-response playbook for scam calls. Each entry is a pair. Cue: the caller manufactures urgency ("your account will be frozen in ten minutes") → Response: state the standard hold policy, never act on inbound-caller pressure, offer to call back on the number printed on the card. Cue: the caller already "knows" the last four digits → Response: treat shared data as non-authenticating; re-verify independently. An agent who recognizes the tactic does not have to reason out a reply mid-call; the move is pre-linked and already rehearsed. The playbook's value is precisely that the decision was made in advance, when there was time to make it well.
How it works¶
What distinguishes it from a glossary or a policy memo:
- Cue → response pairs, not prose. The atomic unit binds a concrete tell to a concrete move; neither half stands alone.
- Responses target the tactic, not the script. Each counter-move is chosen to work across variants of the tactic, so a reworded lure still meets the same defense.
- Built for retrieval under pressure. Entries are short and rehearsable, because the point is a fast reflex, not a reference to study mid-attack.
- A default for the unrecognized. A good playbook includes the catch-all "tactic you can't place → slow down and escalate."
Tuning parameters¶
- Cue specificity — broad tactic categories versus fine-grained tells; finer cues are easier to spot but multiply entries and can miss novel blends.
- Response rigidity — a single mandated move versus a small menu; rigid is fast and consistent but brittle on edge cases, a menu is flexible but slower.
- Coverage versus memorability — how many tactics to include; a short playbook is learnable, a long one is comprehensive but goes unused.
- Escalation thresholds — when the response is "handle it" versus "escalate to a human or authority."
- Grouping — mapping tactic-by-tactic versus by families that share a single response, trading precision against a smaller set to learn.
When it helps, and when it misleads¶
Its strength is removing in-the-moment invention — exactly what fails under pressure. Pre-deciding "if I see X, then I do Y" is the logic of implementation intentions, which reliably beat good intentions for follow-through because the response is already linked to a trigger.[1] A shared playbook also makes a team's responses consistent.
It misleads when it hardens into a rulebook. A rigid playbook misfires on a novel tactic it has no entry for, and can breed false confidence that every attack is covered. Over-drilled responses can even be reverse-engineered by an adversary who then designs around them. The classic misuse is applying it mechanically to justify heavy-handed or dismissive treatment ("policy says X") regardless of context, or to shut down legitimate interactions merely flagged as "tactics." The discipline is to map responses to the tactic's underlying leverage so they generalize, keep an explicit "unrecognized → slow down and escalate" default, and revise as tactics mutate.
How it implements the components¶
The playbook realizes the archetype's recognize-and-respond components — the two halves it deliberately binds together:
recognition_cue_map— each entry's left side is a concrete cue for spotting one tactic; collectively they map tells to tactics.resistance_response_repertoire— each entry's right side is a pre-decided, rehearsable counter-move; the set of them is the response repertoire.
It does not hold the argument-level rebuttals (Refutation Script Library), stage a live drill to install the moves under pressure (Social Engineering Simulation with Debrief), or measure whether they stuck (Resistance Probe Quiz).
Related¶
- Instantiates: Attenuated Threat Inoculation — binds recognition to a pre-decided response so spotting a tactic carries its counter.
- Consumes: Manipulation Tactic Labeling Card — the recognition labels the playbook builds its responses onto.
- Sibling mechanisms: Manipulation Tactic Labeling Card · Social Engineering Simulation with Debrief · Refutation Script Library · Resistance Probe Quiz · Counterargument Rehearsal · Weakened Adversarial Example Set · Rumor Prebuttal Brief · Prebunking Message · Adversarial Message Sandbox · Inoculation Dose Ladder · Inoculation Refresh Drill
Editorial Notes¶
Form Classification¶
Form family: Protocol, Workflow & Routine
Rationale: Tactic To Response Playbook is defined in the frozen evidence as: An if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing 'this is manufactured urgency' comes pre-linked to a rehearsed response. Its operative deployed or enacted form is therefore Protocol, Workflow & Routine.
Nearest alternative: Interface, Display & Cue — Interface, Display & Cue can support this mechanism, but the evidence centers the concrete operation described above rather than the alternative family's defining operation.
Review outcome: Adjudicated after independent review; high confidence.
Origin Attribution¶
Primary origin: Security Studies & Intelligence Analysis
Origin pattern: Convergent development
Present-day reach: Multi-domain
Rationale: The defining operation is: An if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing 'this is manufactured urgency' comes pre-linked to a rehearsed response. In the security_intelligence lineage, that operation is specifically evidenced by authoritative or primary work that pairs recognized incident conditions with predefined, rehearsable response actions. This makes security_intelligence the best historical origin, while the retained alternates document contributing methods and later applications rather than being mistaken for coequal origins.
Related originating lineages:
- Computer Science & Software Engineering — Computer science and software-engineering practice supplies a parallel or contributing lineage for the mechanism's defining operation: an if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing 'this is manufactured urgency' comes pre-linked to a….
- Education & Pedagogy — Education, assessment, and instructional practice supplies a parallel or contributing lineage for the mechanism's defining operation: an if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing 'this is manufactured urgency' comes pre-linked to a….
- Military & Strategic Studies — military_strategic_studies supplies a historically relevant parallel or contributing practice for the defining operation—An if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing 'this is manufactured urgency' comes pre-linked to a rehearsed response—but the evidence does not make it the best primary lineage.
- Psychology — Experimental, clinical, and behavioral psychology supplies a parallel or contributing lineage for the mechanism's defining operation: an if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing 'this is manufactured urgency' comes pre-linked to a….
Review resolution: The blind reviewers disagree on primary lineage (military_strategic_studies versus security_intelligence), so I adjudicated the mechanism rather than inheriting either label. The defining operation is: An if-this-then-that reference that pairs each manipulation tactic with the specific counter-move it calls for, so recognizing 'this is manufactured urgency' comes pre-linked to a rehearsed response. In the security_intelligence lineage, that operation is specifically evidenced by authoritative or primary work that pairs recognized incident conditions with predefined, rehearsable response actions. This makes security_intelligence the best historical origin, while the retained alternates document contributing methods and later applications rather than being mistaken for coequal origins. The cited CISA Cybersecurity Incident and Vulnerability Response Playbooks directly supports the mechanism-specific operation and its disciplinary lineage. I retain all independently explained historical alternates without a numeric cap. origin_mode=convergent records how the mechanism arose; domain_reach=multi_domain separately records how broadly it can now be applied.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
Notes¶
A playbook decides responses in advance but does not by itself install them. On paper it is a reference — consulted too slowly to help mid-attack. Pairing it with a live drill (the Social Engineering Simulation with Debrief) is what turns the mapping from a document into a reflex; the plan and the practice are different things.
References¶
[1] Gollwitzer, P. M. "Implementation Intentions: Strong Effects of Simple Plans". American Psychologist 54(7), 493–503 (1999). Defines implementation intentions as if-then plans that link anticipated cues to responses and improve follow-through. registry ↩