Incident response plan template: what goes in it
A plan people can follow at 2am: who does what, how serious it is, and what to do first.
The Incident Response & Business Continuity Kit has this plan ready to fill in, 9 playbooks, a BCP/DR plan and 6 tabletop exercises, for $249.
1. Roles
- Incident lead
- Technical lead
- Communications lead
- Legal and privacy
- Executive sponsor
- Scribe
Responsibilities for each role are in the kit.
2. Severity levels
| Level | When | Respond |
|---|---|---|
| SEV1 Critical | Confirmed breach of sensitive or customer data, ransomware, or a core service down for all customers. | Immediately, 24/7. Incident lead and executive sponsor engaged within 30 minutes. |
| SEV2 High | Likely compromise of an account or system, a partial outage, or data exposed to the wrong party. | Within 1 hour, including out of hours. |
| SEV3 Medium | Contained malware, a lost encrypted device, or a phishing email that some people clicked but no credentials entered. | Same business day. |
| SEV4 Low | Suspicious activity with no sign of impact, a reported phishing email nobody acted on, a policy slip. | Within 2 business days. |
3. Response phases
- Prepare: Roles, contacts, tools, logging and backups are in place and tested before anything happens.
- Detect and analyse: Confirm it is an incident, set the severity, open the incident log and start the timeline.
- Contain: Stop it spreading: isolate devices, disable accounts, block senders or addresses, keep evidence.
- Eradicate: Remove the cause: malware, attacker access, the vulnerable setting or the leaked secret.
- Recover: Restore from clean sources, watch closely, and return to normal operation in stages.
- Learn: Hold a blameless review within 10 business days, record actions with owners and dates, and update this plan.
4. Playbooks
- Phishing and business email compromise
- Ransomware
- Lost or stolen device
- Data sent to the wrong person or exposed
- Compromised account or cloud admin access
- Malware on a device
- Major outage or denial of service
- Supplier or third-party breach
- AI tool data leak or misuse
5. Notification, evidence, contacts and testing
Who decides on notifying regulators, customers and insurers; how to keep evidence; a contact sheet; and a testing schedule. All in the kit.