Hello,
I found great that you share your incident response docs. Thanks for it.
I use it as a base to detail more on security incident response and a few typical cases.
https://github.com/juju4/incident-response-docs/tree/devel
I decide to keep it simple so not with overload of details and more with good references set.
If it's something you would be interested in, I can push a PR