When something goes wrong, a written plan beats improvisation. Here's a template you can adopt today.
Roles (name someone for each)
- Incident lead — coordinates the response
- IT/Managed Service Provider — technical containment
- Comms — customer/regulator notifications
Containment steps
Isolate affected systems, reset credentials, enable MFA, preserve logs. Detail lives in our first-24-hours breach checklist.
Notification timelines
Know your obligations: contractual (customers), regulatory (HIPAA/state breach laws), and insurer (often 24–72h). Document them here.
Post-incident review
Within two weeks, write down what happened, what worked, and the one change to prevent recurrence. Tie it to your security checklist.
Frequently Asked Questions
What should be in my incident response plan?
Key components: (1) Contact list (IT, legal, PR, law enforcement), (2) Detection and analysis procedures, (3) Containment strategies, (4) Eradication steps, (5) Recovery procedures, (6) Post-incident review process, (7) Communication templates. Include specific procedures for ransomware, data breaches, and insider threats. Test the plan annually.
Who should be on my incident response team?
At minimum: IT manager or tech-savvy employee, business owner/manager, legal counsel, PR/communications lead. For larger businesses, add: CISO/security manager, HR director, finance director. Document roles and responsibilities clearly. Ensure team members know their roles during an incident and have contact information.