A guide to preparing an incident response plan that defines in advance what to do when a security incident occurs.
Why you need a plan
In an incident, time is the most expensive thing. If who decides, who acts and who is informed is debated in the moment, losses grow. A good plan lowers the thinking load in a crisis and keeps everyone on the same page.
Phases of incident response
Roles and responsibilities
Runs the process, decides and reports status.
Carries out analysis, containment and recovery.
Assesses notification duties and evidence integrity.
Keeps internal and external messaging consistent.
Decides on resources and priorities.
Forensic or response specialists, if needed.
Classifying incidents
Not every incident is handled the same way. A predefined scale gets the right people involved at the right speed:
- Low: limited impact, solved with routine team capacity
- Medium: affects a business process or several users, management informed
- High: a critical system or personal data is affected, the crisis team convenes and notification duties are assessed
First 60 minutes checklist
- Record the incident: when, who noticed, what was seen
- Isolate affected systems from the network without destroying evidence (do not power off unless necessary)
- Assemble the incident manager and crisis team
- Preserve logs and related evidence
- Communicate over a secure channel (e-mail may be compromised)
- Inform legal / data protection
- Classify the incident and brief management
Playbooks and exercises
Prepare step-by-step playbooks for common scenarios: ransomware, account takeover, data leak and denial of service. Test them with a tabletop exercise at least once a year; an exercise shows gaps in the plan before a real incident does.
Important: Do not write the plan and shelve it. Update contacts, roles and tools as they change.
Let’s build your incident response readiness together
We will create your plan, roles and exercises together.